SonicWall Next-Gen FW Integration
1.7K
Lumu Defender offers a framework to help you leverage Lumu's integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems; and more.
The Lumu Defender SonicWall Next-Gen FW Out-of-the-box integration allows you to configure SonicWall Firewalls to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization. See more at: Lumu docs
This guide shows you how to use this project to feed your SonicWall Firewall with Lumu's confirmed compromises.
A python script version of this project is also available at LumuTools in Bitbucket
Before trying to run this project, be sure to familiarize yourself and properly set up the Lumu Defender
SonicWall Next-Gen FW Out-of-the-box integration in your Lumu portal.
See more at: Lumu docs
In order to run this project you'll need docker installed in the machine where you intend to run it.
docker create \
-e HOST=VALUE \
-e PORT=VALUE \
-e USERNAME=VALUE \
-e PASSWORD=VALUE \
-e INTEGRATION_ID=VALUE \
-e NUMBER_OF_EVENTS=VALUE \
-e MAX_REQUEST_ATTEMPTS=VALUE \
-e VERSION=VALUE \
-e LOG_LEVEL=VALUE \
-e VERIFY_SSL=VALUE \
-e FREQUENCY=VALUE \
--restart unless-stopped \
--name lumu-sonicwall-fw-threat-feeder \
--log-opt tag=lumu-sonicwall-fw-threat-feeder \
--log-opt max-size=100m \
--log-opt max-file=1 \
lumutools/sonicwall-fw-threat-feeder:latest
docker start lumu-sonicwall-fw-threat-feeder
HOST - Host SonicWallPORT - Port SonicWallUSERNAME - Username to login in SonicWallPASSWORD - Password to login in SonicWallINTEGRATION_ID - Integration IDNUMBER_OF_EVENTS - Number of events to bring from Lumu, the recommendation is 50MAX_REQUEST_ATTEMPTS - Max attempts of request to Lumu in case of failed, the recommendation is 5VERSION - SonicOS version, if you have SonicOS version 6.5 the value should be --version-6. This parameters is not required and default is for SonicOS version 7LOG_LEVEL - Level of logs to be displayed. For error the value should be --error, for debug the value should be --debug. This parameter is not required and default is for level log infoVERIFY_SSL - -V if your SonicWall is provisioned with an SSL certificate emitted by Certification Authority (do not use with self-signed certificates)FREQUENCY - Polling frequency in minutes (1-30). How often to check for updates.For the proper functioning of the integration, follow these recommendations:
Content type
Image
Digest
sha256:4e4d8b356…
Size
21.8 MB
Last updated
about 4 years ago
docker pull lumutools/sonicwall-fw-threat-feeder