Access rules policies in Cisco Security Manager

Hello!
We've started to deploy CSM 3.01 on our network (currently we have about 20 ASA's and this list is going to have about a 100 devices). The point is that we haven't used CSM's Policy View tab to develop our security policy - we've deployed our policy on each device through ASDM (or CLI). So now we have independent policy on each device (they are very similar but they are local to each device). CSM has an policy inheritance mechanism but the question is - how can we deploy one shared policy thorugh policy tab and retain local individual rules that were added later?
The problem is that CSM offers to deploy policy and then to add local rules but how can we make it reverse - i mean automatically add global policy to local rules and to delete rules that match in both policies?
I think that is rather "unclear" explanation of problem, but i'll try to answer any additional questions.
Regards, Amir

Yes that could be done but only for certain Objects as an example Text objects can be overriden by Induvidul apolicies. Refer URL
http://cisco.com/en/US/products/ps6498/products_user_guide_chapter09186a00805ac23c.html#wp1199068

Similar Messages

  • Import Network host objects to Cisco Security Manager

    Is it possible to import complete lists of Network Hosts objects to Cisco Security Manager?
    Exporting the hosts already defined in the ASAs is easy but how to import them in CSM??
    Thanks

    No hostnames discovered go the Policy Object Manager (nor to the Access rules), only group-names (there's a bug in ASAs related to single host names too). The way CSM handles single hosts is previously creating them, so when we later discover devices, the single hosts names set in the discovered device are not considered, only their IP addresses; then you can see that in the discovered access rules CSM shows the hostname as the previously defined ones in the Policy Object Manager. If you dont define those hostnames before the device discovery, you will only see IP addresses, no hostnames, no matter they are set in your firewalls.
    Imagine discovering a couple FWSM modules with 500 access rules, and you only get to see the IP addresses of the 2,500 hosts on your network. And you have all those hosts already defined in your FWSM firewalls, when you log via ASDM you view your hard created rules with hostnames, and when you log to CSM you only view IP addresses. The clients get very disappointed with CSM after that, and discard it. The bigger the network, the faster they reject CSM.
    The only way to add hosts in the Policy Object Manager is 1 by 1. But as this may have happened to more than one company and considering how easy it is to code a feature like that, I assume that it's possible to import a complete list of single hosts to CSM.
    is that really possible? it should be.
    thanks for the replies so far

  • Cisco Security Manager evaluation

    How to download CSM software for evaluation ? CSM Q&A state -
    Anybody with a valid cisco.com account can download Cisco Security Manager and use the software for up to
    90 days in evaluation mode. Visit  http://www.cisco.com/go/csmanager  and select the “Download Software”
    But when I click "Download" I get "To Download this software, you must have a valid service contract associated to your Cisco.com user ID."
    Help, plz.
    BR, Oleg.

    You can contact your local AM to get an evaluations version, this is related to the new 'restricted' downloaded access on CCO. You need to have a service contract assocaited for that 'specific' product to download software (I know it does not make sense in case of an evaluation).
    And you also have the following alternate:
    Note:
    This download does not include  CiscoWorks Resource Manager Essentials (RME). For customers that wish to  also evaluate CiscoWorks RME or that prefer a media format rather than a  large download, an evaluation DVD can be ordered from Cisco  Marketplace. At http://www.cisco.com/pcgi-bin/marketplace/welcome.pl,  navigate to the Collateral and Subscriptions Store and search for part  number EVAL-CSMGR-4.0.
    Regards
    Farrukh

  • Cisco Security Manager CLI change

    Hi Guys,
    IS there any way to detect a CLI change in Cisco Security Manager without having to manually rediscover policies from CSM
    Can it be automatic?
    Regards

    Following link may help you
    http://www.cisco.com/en/US/docs/security/security_management/cisco_security_manager/security_manager/3.1/user/guide/defapset.html

  • Audit Reports on Cisco Security Manager

    Is there a way to schedule audit reports from Cisco Security Manager and distribute those reports via email or some other method?
    My auditors want a daily report of firewall configuration changes. They do not want to login into CS-Mgr every day to manually generate the report.

    Security Audit operates in one of two modes-the Security Audit wizard, which lets you choose which potential security-related configuration changes to implement on your router, and One-Step Lockdown, which automatically makes all recommended security-related configuration changes.
    On routers that do not support the command scheduler interval, Security Audit configures the scheduler allocate command whenever possible. When a router is fast-switching a large number of packets, it is possible for the router to spend so much time responding to interrupts from the network interfaces that no other work gets done. Some very fast packet floods can cause this condition. It may stop administrative access to the router, which is very dangerous when the device is under attack. The scheduler allocate command guarantees a percentage of the router CPU processes for activities other than network switching, such as management processes.
    The configuration that will be delivered to the router to set the scheduler allocate percentage is as follows:
    scheduler allocate 4000 1000

  • Installing Cisco Security Manager

    I would like to uninstall and reinstall my Cisco Security Manager 3.0 since 3.1 has been taken off the market for the time being.
    Is there a step by step process that I would have to take to install this with standard install, Service packs and patches?
    In a nutshell, I would like to do a complete reinstall and be fully operational when completed.
    Thanks

    Cisco Security Manager (Security Manager) enables you to configure, deploy, and manage services and policies on Cisco security devices. With Security Manager, you can provision VPN and firewall services across multiple, different device types, including IOS routers, firewall devices (PIX and ASA), Catalyst 6500/7600 devices, and Catalyst security services modules (VPN, FWSM, and so on). On some device types, you can also provision platform-specific settings such as QoS, SNMP, and routing, even though these settings are not necessarily security settings.

  • Cisco Security Manager IOPS for Storage (VM Deployent)

    Hi,
    I've been asked by a client about the Cisco Security Manager requirement to have 1TB of storage for events and another for archiving.
    They wish to know the IOPS requirement for this storage. Please could anyone assist in this ?
    Many thanks,
    Mark                 

    Hi,
    I'm not sure that I can really help you, but I can verify that on my CSM 4.5 server which is running normally, that service has a starup type of automatic and is in the "Started" state.
    You may want to check your system and application event logs to see if there are any messages that could explain why it stopped.
    Regards,
    Matt

  • Unable to Install Cisco Security Manager

    Hi,
    I facing issue when trying to install Cisco Security Manager in my Windows Server 2008.
    I had attach the print screen of my server version and error message.
    The error message had mention that it was due to unsupport OS or terminal service.
    But, i check and it show that my Window Server was the recommend version and no terminal service been enable.

    Hi Vincent,
    Please understand that Window Server 2008 R2 Enterprise Server is not same as Windows Server 2008 Enterprise Server. I had faced the same problem earlier. The R2 version is supported only CSM 4.1 onwards.
    Regards,
    Chetan

  • Cisco security Manager Backup error

    i  am getting  the below  error  after the backup in Cisco Security  Manager 3.2
    [Sun Dec 20 00:00:05 2009]  ERROR(313): D:/backup.LOCK file exists
    Most probably another backup process is running
    [Sun Dec 20 00:00:05 2009]  Backup failed: 2009/12/20 00:00:05
    i have deleted the backup.LOCK file and tried  it is giving the same error.
    any one help me in this.
    thanks in advance.

    Update:
    WHen performing the same action through the client interface, rather than from the server interface the backup has appeared to work.
    Is this a feature?
    Needless to say I was able to run a backup.
    Steve

  • Cisco Security Manager Local RBAC Authentication Radius assign user role

    Is it possible to use Cisco Security Manager with local RBAC, authenticate the user to Radius and retrieve it's role from Radius. Getting the authentication to work isn't the problem, but is it also possible to return the role the user has (i.e. Super Admin) via Radius, without having to create all the users one-by-one in the local CSM database with the correct role.
    Can i use a certain Cisco-AV-Pair attribute to return the user role via Radius?

    I just got asked to look at the same situation by one of our security people.
    We have exactly the same problem but it reports a username of "*****" and we are running CSM 4.7 (upgraded last week)

  • Cisco Security Manager logging

    Hello Experts,
    Can anyone help me, how can i configure CSM 4.0 to capture its logs.
    I want to read logs of Cisco Security Manager itself, so how can i do that & in which location it captures it log file.

    There are multiple server logs (47 of them on my CSM 4.4 setup) all stored on the server itself and accessible from Windows Explorer.
    You will need to RDP to the server and look at the log directory under the path where you installed CSM.

  • Cisco Security Manager (CSM) License Problem

    Hi All,
    We have CSM V3.2 with Professional license edition and support 50 devices. It's installed properly in the Cisco Security Manager client as appeared in the attachement but the problem is in the server administration- license management which doesn't include any records for license (see attachment).
    I tried to upload the .lic file by clicking the Update button in server administration but an error message appeared stated that the license file is corrupted although it's installed properly in CSM client!!!
    Could you please advise what's the problem and what should I do?
    Thanks in Advance!

    Sorry but Cisco seems to have removed that product bulletin from cisco.com.
    Your reseller can use Cisco Commerce Workspace (CCW) to order the correct part number for your CSM installation. There is a unique number for each licensing level and/or upgrade.
    For instance, for a 10-device standard license, the support would be part number CON-SAS-CSMST10K.
    For the 100-device Pro license, the support would be CON-SAS-CSMPR4K9.
    The reseller needs to adjust the support term (12-60 months) to suit when ordering.

  • Cisco Security Manager, need global search, i.e. filters are not good at all

    Does anybody know how to work effectively with security manager and filtering?
    It is extremely time consuming and frustrating to work with Cisco Security Manager in regards to search for entries or filter. I have not been able to find some kind of global search, is there?
    How do other people cope with this?

    It appears to have been a temporary issue as the backup is running fine again now... closing the thread.

  • Catalyst 3750x and 4510R and Cisco Security Manager

    Hi,
    I just downloaded and install trial (evaluation) version of Cisco Security Manager 4.3. In supported devices list I saw Cisco Catalyst 3750 and 4510R but when I try to add it I got for 3750:
    Invalid device: Device is a switch and cannot be mapped to a Generic Router model.
    Please verify the selected device type, OS version and device configuration
    For 4510R:
    Invalid device: Version 03.03.00.SG (N/A) is not supported for the device type of Cisco Catalyst 4510R Switch Please verify the selected device type, OS version and device configuration
    We need to make a purchase decision but for it we need to import all of our devices and perform some tests.
    Thanks in advance for your replies!
    BR, Vasily.

    I figured this out on my own -- change Compatibility mode of the installer to be Windows 8 (which is same OS version as Windows 2012) and it installs just fine.

  • Cisco Security Manager Advice

    Hi,
    I'm looking into Cisco Security Manager. From what I understand you can monitor and manage Cisco security appliances. I'm interested in the monitoring of our Cisco ASAs - specifically, monitoring VPN sessions and their  trending over months at a time and I would like to monitor other Cisco devices on the network for link problems/performance and such - I don't want to use Cisco Security Manager as a management point. Would Cisco Security Manager not be the right tool for this?
    We have SolarWinds and I've heard that you can assign UnDPs(Device Pollers) to devices you want to monitor, including ASAs and these pollers can give you trending for VPN sessions with graphing. I just want to make the most of our budget dollars.
    Any advice?
    Thanks, Pat.

    CSM 4.3 and above can be used to monitor VPN sessions on Cisco ASAs. You can definitely use CSM as a monitoring only solution for ASAs (without using it for management). You can also explicitly disable policy change privileges for all admins so they do not modify stuff by mistake. Note however that CSM is primarily focused on end-to-end management scenarios (including policy change, troubleshooting, reporting, etc). So you may not find all the bells and whistles in CSM for monitoring scenarios that you may find with some of the pure monitoring only solutions.

Maybe you are looking for

  • Apple TV no longer connects to Samsung Smart TV

    My ATV (newest version) worked just fine for many months connected to my Samsung Smart TV.  Recently, I updated the Samsung  Smart TV software.  The last update was 6 months back.  Now ATV does not  work.  ATV has been connected to HDMI4 and worked j

  • Issue account assignment at item level.

    Hi Experts, I have an issue, because I have created a new order type that has to work the same that the one I have used as model however this new order type doesnu2019t work the same at item level in the view Account assignment. The new has the field

  • DNG Converter install problem

    Hi all- I didnt know what forum to post this in but since I run elements, I figured I'd post it here. I have a new camera and was looking to get DNG converter to bridge the gap until I get Lightroom-3 Current set up: iMac 24 os 10.4.1.1 Photoshop Ele

  • Missing CMS DataSource

    Hi Experts, I have recently installed Business Contents 3.5.3 to utilise CMS infoProviders for reporting. However, I cannot seem to locate relevant DataSources to populate ODS Objects in R/3 whilst all the CMS master DataSource are found using RSA5 (

  • Mac Pro shuts down instead of sleeps.

    I run a  2008 Mac with OSX10.5.8, with 2GB memory and 2x2.8Ghz Quad core processors It works great! however recently it has started acting strangely. What i mean is it normally goes into sleep mode after 15 mins of inactivity or so. However recently