Sign inSign up

lumutools/sonicwall-fw-threat-feeder

By lumutools

•Updated about 4 years ago

SonicWall Next-Gen FW Integration

Image
1

1.7K

lumutools/sonicwall-fw-threat-feeder repository overview

⁠Lumu - SonicWall Next-Gen FW Integration

Lumu Defender offers a framework to help you leverage Lumu's integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems; and more.

The Lumu Defender SonicWall Next-Gen FW Out-of-the-box integration allows you to configure SonicWall Firewalls to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization. See more at: Lumu docs⁠

⁠Getting Started

This guide shows you how to use this project to feed your SonicWall Firewall with Lumu's confirmed compromises.

A python script version of this project is also available at LumuTools in Bitbucket⁠

⁠Requirements

Before trying to run this project, be sure to familiarize yourself and properly set up the Lumu Defender SonicWall Next-Gen FW Out-of-the-box integration in your Lumu portal.
See more at: Lumu docs⁠

In order to run this project you'll need docker installed in the machine where you intend to run it.

⁠Usage
  1. Prepare the container (replace VALUE with proper values):
 docker create \
 -e HOST=VALUE \
 -e PORT=VALUE \
 -e USERNAME=VALUE \
 -e PASSWORD=VALUE \
 -e INTEGRATION_ID=VALUE \
 -e NUMBER_OF_EVENTS=VALUE \
 -e MAX_REQUEST_ATTEMPTS=VALUE \
 -e VERSION=VALUE \
 -e LOG_LEVEL=VALUE \
 -e VERIFY_SSL=VALUE \
 -e FREQUENCY=VALUE \
 --restart unless-stopped \
 --name lumu-sonicwall-fw-threat-feeder \
 --log-opt tag=lumu-sonicwall-fw-threat-feeder \
 --log-opt max-size=100m \
 --log-opt max-file=1 \
 lumutools/sonicwall-fw-threat-feeder:latest
  1. Run it:
docker start lumu-sonicwall-fw-threat-feeder
⁠Parameters
  • HOST - Host SonicWall
  • PORT - Port SonicWall
  • USERNAME - Username to login in SonicWall
  • PASSWORD - Password to login in SonicWall
  • INTEGRATION_ID - Integration ID
  • NUMBER_OF_EVENTS - Number of events to bring from Lumu, the recommendation is 50
  • MAX_REQUEST_ATTEMPTS - Max attempts of request to Lumu in case of failed, the recommendation is 5
  • VERSION - SonicOS version, if you have SonicOS version 6.5 the value should be --version-6. This parameters is not required and default is for SonicOS version 7
  • LOG_LEVEL - Level of logs to be displayed. For error the value should be --error, for debug the value should be --debug. This parameter is not required and default is for level log info
  • VERIFY_SSL - -V if your SonicWall is provisioned with an SSL certificate emitted by Certification Authority (do not use with self-signed certificates)
  • FREQUENCY - Polling frequency in minutes (1-30). How often to check for updates.
⁠General Recommendations

For the proper functioning of the integration, follow these recommendations:

  • Integration between Lumu and your firewall is carried out using Uri List Group and Uri List Objects named as follows:
    • Uri List Group: Lumu-Uri-List-Group
    • Uri List Object: Lumu-Uri-List-Object-n where n is a number
  • Each of these objects is actively used and updated by this integration; therefore, they must not be modified.
  • Additional threats must not be added to elements created by this integration. Create or use other elements instead.
  • When using the Docker image, do not stop the container. This will cause the synchronization process to restart from scratch.
  • When using the Docker image, a frequency between 20 and 30 minutes is recommended.

⁠Find more about us

Tag summary

Content type

Image

Digest

sha256:4e4d8b356…

Size

21.8 MB

Last updated

about 4 years ago

docker pull lumutools/sonicwall-fw-threat-feeder