IP Correlation is the method by which the SMS looks up the IP addresses of hosts under inspection, learns the associated MAC address of an IP from a source, and then resolves which switch this MAC is connected to. The SMS can then engage switch actions to begin acting on hosts. This setup is required for SMS Active Response to work with non-IPS infrastructure equipment, such as switches and other network access points.
Configuring IP Correlation
The IP Correlation Network Mapping Table is used to create a static map of IP address to MAC address one entry at a time. Mapping of the end-station to its IP address is a requirement for the SMS Active Response application to properly control access on a host. When configured for IP Correlation, the SMS:
- Watches events from an IPS
- Finds the end-station responsible for those events
- Uses the information to initiate a response
How To: Common Task
- Log in to the SMS from a client.
- On the SMS toolbar, navigate to the Responder > IP Correlation. The IP Correlation screen displays.
How To: Add/Edit Network Mapping
- In the IP Correlation Network Mapping area, click New, or select an existing entry in the list and click Edit. The IP Correlation dialog displays.
- Specify the following information:
- IP Address
- MAC Address (in::::: format)
- Click OK to finish.
How To: Add/Edit Web Services
- In the IP Correlation Web Services area, click New or select an existing entry in the in the list and click Edit. The IP Correlation Web Services dialog displays.
- Specify the Web Services URL. If you are using basic authentication, enter the Username and Password.
- Click OK to finish.
How To: Control Web Service Precedence
- From the IP Correlation Web Services area, select the Web Service URL entry.
- Use the Up and Down arrow buttons to move the entry up or down in the list.
How To: Perform a Test of IP Correlation
- On the SMS toolbar, navigate to the Responder > IP Correlation. The IP Correlation screen displays.
- Click Test (located at the bottom of the screen). The IP Correlation Test dialog box opens.
- Select the appropriate Correlation Method (IPLOOKUP or MACLOOKUP)
- Enter an address for the type of method selected: IP or MAC.
- Click Query. The results of the query display in the results section.
- Click Close to close the dialog and return to the IP Correlation screen.
Reference: SMS User Guide