Lumu Defender offers a framework to help you leverage Lumu's integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems; and more.
The Lumu Defender Fortinet FortiGate FW Out-of-the-box integration allows you to configure Fortinet FortiGate Firewalls to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization. See more at: Lumu docs
To run this integration, you must configure it in your Lumu portal and set up the on-premises component. This guide shows you how to install and run the on-premises component to feed your Fortinet FortiGate Firewall with Lumu's confirmed compromises.
Before proceeding, ensure you have:
The on-premises component can run in two modes:
Note: If you have not yet generated an RSA key pair, you can create one using OpenSSL. Follow the steps in Generating an RSA Key Pair before continue. This key pair is used to secure communication between the on-premises component and the Lumu platform.
If you are setting up a single integration, follow the steps below.
Prepare the Required Parameters
Replace with the appropriate values:
INTEGRATION_ID1:VDOM1,VDOM2,VDOM3, max 3 VDOM per integrationCreate the Docker Container
docker create \
-v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
--name "lumu-fortinet-fw-threat-feeder" \
--env "COMPANY_ID=<COMPANY_ID>" \
--env "INTEGRATION_ID=<INTEGRATION_ID>" \
[--env "VDOMS=<VDOMS>" \]
--restart unless-stopped \
--log-opt max-size=20m \
--log-opt max-file=3 \
lumutools/fortinet-fw-threat-feeder:latest
Run the Docker Container
docker start lumu-fortinet-fw-threat-feeder
If you need to deploy multiple integrations in a single container, use the multiple integration mode by creating a config.yaml file.
INTEGRATION_ID1:VDOM1,VDOM2,VDOM3,INTEGRATION_ID2:VDOM2,..., max 3 VDOM per integrationPrepare the Configuration File config.yaml
Create a config.yaml file with the following structure:
integrations:
-
company_id: <COMPANY_ID> # UUID from Lumu portal
id: <INTEGRATION_ID> # UUID from Lumu portal
-
# Integration 2
-
# Integration N
Replace <COMPANY_ID> and <INTEGRATION_ID> with the appropriate values for each integration.
Create the Docker Container
Replace <PRIVATE_KEY_FILE_PATH> with the path to your RSA private key file (private_key.pem):
docker create -v $PWD/config.yaml:/app/config.yaml \
-v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
--name "lumu-fortinet-fw-threat-feeder" \
[--env "VDOMS=<VDOMS>" \]
--restart unless-stopped \
--log-opt max-size=20m \
--log-opt max-file=3 \
lumutools/fortinet-fw-threat-feeder:latest
Run the Docker Container
docker start lumu-fortinet-fw-threat-feeder
If you have not yet generated an RSA key pair, you can create one using OpenSSL. This key pair is used to secure communication between the on-premises component and the Lumu platform.
Note: If you have already generated a key pair during the integration setup in the Lumu portal, skip this section and ensure you use the matching private key during the on-premises component setup.
Generate a Private Key
Run the following command to generate a 2048-bit RSA private key:
openssl genrsa -out private_key.pem 2048
Extract the Public Key
Run the following command to extract the public key from the private key:
openssl rsa -in private_key.pem -pubout -out public_key.pem
Keep the Public Key to use it in the Lumu Portal
When configuring the integration, you will be asked to provide a public key to encrypt your credentials. Be sure to provide the file you just created.
Securely Store Your Private Key
Keep the private_key.pem file in a secure location, this is the only artifact that can be used to decrypt the credentials you provide during integration setup. Also, you will need this private key file (private_key.pem) during the on-premises component setup.
For the proper functioning of the integration, please follow these recommendations:
Content type
Image
Digest
sha256:ec450e719…
Size
91.3 MB
Last updated
about 1 year ago
docker pull lumutools/fortigate-fw-threat-feeder