11-2
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter11 Configuring External Product Interfaces
Understanding the CSA MC
Understanding the CSA MC
The CSA MC enforces a security policy on network hosts. It has two components:
Agents that reside on and protect network hosts.
Management Console (MC)—An application that manages agents. It downloads security policy
updates to agents and uploads operational information from agents.
The CSA MC receives host posture information from the CSA agents it manages. It also maintains a
watch list of IP addresses that it has determined should be quarantined from the network. The CSA MC
sends two types of events to the sensor—host posture events and quarantined IP address events.
Host posture events (called imported OS identifications in IPS) contain the following i nformation:
Unique host ID assigned by the CSA MC
CSA agent status
Host system hostname
Set of IP addresses enabled on the host
CSA software version
CSA polling status
CSA test mode status
NAC posture
For example, when an OS-specific signature fires whose target is running that OS, the attack is highly
relevant and the response should be greater. If the target OS is different, then the attack is less relevant
and the response may be less critical. The signat ure attack relevance rating is adjusted for this host.
The quarantined host events (called the watch list in IPS) contain the following information:
IP address
Reason for the quarantine
Protocol associated with a rule violation (TCP, UDP, or ICMP)
Indicator of whether a rule-based violation was associated with an established session or a UDP
packet.
For example, if a signature fires that lists one of these hosts as the attacker, it is presumed to be that much
more serious. The risk rating is increased for this host. The magnitude of the increase depends on what
caused the host to be quarantined.
The sensor uses the information from these events to determine the risk rating increase based on the
information in the event and the risk rating configuration settings for host postures and quarantined IP
addresses.
Note
The host posture and watch list IP address information is not associated with a virtual sensor, but is
treated as global information.
Secure communications between the CSA MC an d the IPS sensor are maintained through SSL/TLS. The
sensor initiates SSL/TLS communications with the CSA MC. This communication is mutually
authenticated. The CSA MC authenticates by providing X.509 certificates. The sensor uses
username/password authentication.