Sign inSign up

lumutools/barracuda-fw-threat-feeder

By lumutools

•Updated almost 2 years ago

Image
0

1.6K

lumutools/barracuda-fw-threat-feeder repository overview

⁠Lumu - Barracuda CloudGen FW Integration

Lumu Defender offers a framework to help you leverage Lumu's integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems; and more.

The Lumu Defender Barracuda CloudGen FW Out-of-the-box integration allows you to configure Barracuda CloudGen Firewalls to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization. See more at: Lumu docs⁠

⁠Getting Started

To run this integration, you must configure it in your Lumu portal and set up the on-premises component. This guide shows you how to install and run the on-premises component to feed your Barracuda CloudGen Firewall with Lumu's confirmed compromises.

⁠Requirements

Before proceeding, ensure you have:

  • Configured the Lumu Defender Barracuda CloudGen Firewall Out-of-the-box Integration in your Lumu portal. See more at: Lumu docs⁠.
  • Installed Docker on the machine where you intend to run the on-premises component. Refer to Docker official installation guide.

⁠Setting Up the On-Premises Component

The on-premises component can run in two modes:

  • Single Integration Mode: For setting up a single integration.
  • Multiple Integration Mode: For setting up multiple integrations simultaneously.

Note: If you have not yet generated an RSA key pair, you can create one using OpenSSL. Follow the steps in Generating an RSA Key Pair⁠ before continue. This key pair is used to secure communication between the on-premises component and the Lumu platform.

⁠Single Integration Mode

If you are setting up a single integration, follow the steps below.

⁠Steps
  1. Prepare the Required Parameters

    Replace with the appropriate values:

    • <COMPANY_ID>: Your Lumu Company UUID.
    • <INTEGRATION_ID>: Your Lumu Integration UUID.
    • <PRIVATE_KEY_FILE_PATH>: Path to your RSA private key file (private_key.pem). This should be the private key matching the public key you provided during the integration configuration in the Lumu portal.
  2. Create the Docker Container

    docker create \
      -v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
      --name "lumu-barracuda-fw-threat-feeder" \
      --env "COMPANY_ID=<COMPANY_ID>" \
      --env "INTEGRATION_ID=<INTEGRATION_ID>" \
      --restart unless-stopped \
      --log-opt max-size=20m \
      --log-opt max-file=3 \
      lumutools/barracuda-fw-threat-feeder:latest
    
  3. Run the Docker Container

    docker start lumu-barracuda-fw-threat-feeder
    
⁠Multiple Integration Mode

If you need to deploy multiple integrations in a single container, use the multiple integration mode by creating a config.yaml file.

⁠Parameters
  • <COMPANY_ID>: Lumu Company UUID.
  • <INTEGRATION_ID>: Lumu Integration UUID.
  • <PRIVATE_KEY_FILE_PATH>: Path to the RSA private key file (private_key.pem). This should be the private key matching the public key you provided during the integration configuration in the Lumu portal.
⁠Steps:
  1. Prepare the Configuration File config.yaml

    Create a config.yaml file with the following structure:

    integrations:
      -  
        company_id: <COMPANY_ID>  # UUID from Lumu portal
        id: <INTEGRATION_ID>      # UUID from Lumu portal
      -  
        # Integration 2
      -
        # Integration N
    

    Replace <COMPANY_ID> and <INTEGRATION_ID> with the appropriate values for each integration.

  2. Create the Docker Container

    Replace <PRIVATE_KEY_FILE_PATH> with the path to your RSA private key file (private_key.pem):

    docker create -v $PWD/config.yaml:/app/config.yaml \
      -v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
      --name "lumu-barracuda-fw-threat-feeder" \
      --restart unless-stopped \
      --log-opt max-size=20m \
      --log-opt max-file=3 \
      lumutools/barracuda-fw-threat-feeder:latest
    
  3. Run the Docker Container

    docker start lumu-barracuda-fw-threat-feeder
    
⁠Generating an RSA Key Pair

If you have not yet generated an RSA key pair, you can create one using OpenSSL. This key pair is used to secure communication between the on-premises component and the Lumu platform.

Note: If you have already generated a key pair during the integration setup in the Lumu portal, skip this section and ensure you use the matching private key during the on-premises component setup.

⁠Steps to Generate an RSA Key Pair
  1. Generate a Private Key

    Run the following command to generate a 2048-bit RSA private key:

    openssl genrsa -out private_key.pem 2048
    
  2. Extract the Public Key

    Run the following command to extract the public key from the private key:

    openssl rsa -in private_key.pem -pubout -out public_key.pem
    
  3. Keep the Public Key to use it in the Lumu Portal

    When configuring the integration, you will be asked to provide a public key to encrypt your credentials. Be sure to provide the file you just created.

  4. Securely Store Your Private Key

    Keep the private_key.pem file in a secure location, this is the only artifact that can be used to decrypt the credentials you provide during integration setup. Also, you will need this private key file (private_key.pem) during the on-premises component setup.

⁠General Recommendations

For the proper functioning of the integration, please follow these recommendations:

  • The integration between Lumu and your firewall is carried out using the Custom External Network Objects feature.
  • These objects are actively used and updated by this integration; therefore, they must not be modified manually.
  • When using the Docker image, do not stop the container. Stopping the container will cause the synchronization process to restart from scratch.

⁠Find more about us

Tag summary

Content type

Image

Digest

sha256:3acaa904d…

Size

84.8 MB

Last updated

almost 2 years ago

docker pull lumutools/barracuda-fw-threat-feeder