Thursday, November 20, 2008

Cool Cisco Icons for Visio


One thing i absolutely hate is all the crappy looking icons for doing Visio diagrams.
Microsoft has made some pretty cool diagrams, but most of the Cisco ones look crappy.
Anyway, I downloaded the Cisco WMF files off of Cisco's site. and modified the colors and shading, to make them look a little cooler, then I imported them into visio and created a .vss you can use.
Hopefully, I am not breaking any copyright laws or anything by doing this, I am really just trying to give back to the community, and all the Cisco admins who only have crappy icons to work with.
Here they are, (you will need to right click and download) you can download them and use them, unless I get in trouble of course. They are a little nicer than the blase onse you will get off of Cisco's site. Unfortunately since I deal mostly with Security, I did mostly the ASA's, IPS, MARS and some Switch stuff.
Let me know if you find them useful.

Wednesday, October 22, 2008

Adding AIP-SSM (IPS) modlue reporting in CS-MARS

This one has been driving me nuts for a long time, and I finally found the answer.
I have two ASA firewalls in active/standby failover, both firewalls have an IPS module in them. I actually have them plugged into MARS as two modules, sitting in a single firewall. Obviously MARS can only speak with one of them at a time, because the Standby IPS is physically sitting in a different hardware device, untill failover occours.
It works, but I have always wondered what is the actual "CISCO" way for configuring this device reporting in MARS. Today, I actually found the CISCO documentation that indicates the correct method for adding these devices in MARS.

While this is true for the actual firewalls, it is not true for AIP-SSM modules. AIP-SSM modules do not swap IP addresses in the event of a failover. Therefore, to ensure that MARS receives uninterrupted IPS event data, you must configure both the primary and secondary AIP-SSM modules as child modules of the same ASA device that represents the Active/Standby pair. In this configuration, MARS will likely generate "Inactive Reporting Device" messages on the hour for the non-active AIP-SSM module. view here