Cisco ASA IPS Monitoring

SecurityTheatre

Senior member
Aug 14, 2011
672
0
0
I may be inheriting a number of Cisco ASA firewalls to manage. I know ASA well enough, but one of their major concerns is the IPS functionality and doing security monitoring. In the past I've just dumped the stuff to Syslog and into a SIEM device.

Currently, I have some staff who are monitoring a bunch of Palo Alto firewalls using Panorama, which is a great tool to do reporting, drill down on sessions, threats, etc.

What exists for Cisco devices to monitor the IPS? How do I know when there are critical threats found by IPS? Can I drill down into sessions in a similar way to Palo Alto?

I don't know what they have installed. Is there a built-in console that lets you look at IPS log data? Is there one for session/traffic data? Is there a central manager that lets you do this for all devices at several remote sites, or do I need to spend $50k getting a SIEM device in place?

Any thoughts?

Thanks!
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
Kind of surprised you got no responses. I haven't used Cisco's IPS products, but I would think they're paired up with some good software/dashboards/consoles (whatever you want to call them) seeing as Sourcefire is part of Cisco now. (I also haven't used Soucefire's products, but have heard good things.)