Lumu Defender provides a framework to help you leverage Lumu's integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems, and more.
The Lumu Defender Watchguard FW Out-of-the-box integration enables you to configure Watchguard Firewalls to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization. See more at: Lumu docs.
Check this section first if you have a running Watchguard FW Out-of-the-box integration component and the Lumu team indicated you to update it.
You must check if you already have a version with an external control database. To check this, run the following command on the host where you deployed the integration.
docker inspect lumu-watchguard-fw-threat-feeder --format '{{ .Mounts }}'
If you obtain a result with a single bind record as shown below, go to the next step to extract your control database.
[{bind REDACTED_PATH_TO_YOUR_PRIVATE_KEY /tmp/p.key true rprivate}]
If you obtain a result with two bind records as follows. You can proceed with the update process.
[{bind REDACTED_PATH_TO_YOUR_PRIVATE_KEY /tmp/p.key true rprivate} {bind REDACTED_PATH_TO_YOUR_DATABASE/indicators.db /app/indicators.db true rprivate}]
Run the following command to extract the database from the container to the integration host.
docker cp lumu-watchguard-fw-threat-feeder:/app/indicators.db .
You will have a new file named indicators.db in your current host folder. Now, you can proceed with the update process.
To run this integration, you must configure it in your Lumu portal and set up the on-premises component. This guide shows you how to install and run the on-premises component to feed your WatchGuard Firewall with Lumu's confirmed compromises.
Before proceeding, ensure you have:
Ensure you extracted your control database to your host as indicated in the Important: Review control database configuration section.
You must stop and delete your current integration container before continuing. Run the following block of commands to do so:
docker stop lumu-watchguard-fw-threat-feeder
docker rm lumu-watchguard-fw-threat-feeder
You can proceed with your selected deployment mode after running these commands, either the Single Integration Mode or the Multiple Integration Mode.
The on-premises component can run in two modes:
Note: If you have not yet generated an RSA key pair, you can create one using OpenSSL. Follow the steps in Generating an RSA Key Pair before continuing. This key pair is used to secure communication between the on-premises component and the Lumu platform.
If you are setting up a single integration, follow the steps below.
Prepare the Required Parameters
Replace with the appropriate values:
True to enable debug logging; otherwise, omit or set to False.Create the Docker Container
docker create \
-v ./indicators.db:/app/indicators.db \
-v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
--name "lumu-watchguard-fw-threat-feeder" \
--env "COMPANY_ID=<COMPANY_ID>" \
--env "INTEGRATION_ID=<INTEGRATION_ID>" \
--restart unless-stopped \
--log-opt max-size=20m \
--log-opt max-file=3 \
lumutools/watchguard-fw-threat-feeder:latest
If you want to run your component in DEBUG mode, use the following command:
docker create \
-v ./indicators.db:/app/indicators.db \
-v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
--name "lumu-watchguard-fw-threat-feeder" \
--env "COMPANY_ID=<COMPANY_ID>" \
--env "INTEGRATION_ID=<INTEGRATION_ID>" \
--env "APP_DEBUG=True" \
--restart unless-stopped \
--log-opt max-size=20m \
--log-opt max-file=3 \
lumutools/watchguard-fw-threat-feeder:latest
Create a blank indicators database
touch indicators.db
Run the Docker Container
docker start lumu-watchguard-fw-threat-feeder
If you need to deploy multiple integrations in a single container, use the multiple integration mode by creating a config.yaml file.
True to enable debug logging; otherwise, omit or set to False.Prepare the Configuration File config.yaml
Create a config.yaml file with the following structure:
integrations:
-
company_id: <COMPANY_ID> # UUID from Lumu portal
id: <INTEGRATION_ID> # UUID from Lumu portal
-
# Integration 2
-
# Integration N
Replace <COMPANY_ID> and <INTEGRATION_ID> with the appropriate values for each integration.
Create the Docker Container
Replace <PRIVATE_KEY_FILE_PATH> with the path to your RSA private key file (private_key.pem):
docker create -v $PWD/config.yaml:/app/config.yaml \
-v ./indicators.db:/app/indicators.db \
-v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
--name "lumu-watchguard-fw-threat-feeder" \
--restart unless-stopped \
--log-opt max-size=20m \
--log-opt max-file=3 \
lumutools/watchguard-fw-threat-feeder:latest
If you want to run your component in DEBUG mode, use the following command:
docker create -v $PWD/config.yaml:/app/config.yaml \
-v ./indicators.db:/app/indicators.db \
-v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
--name "lumu-watchguard-fw-threat-feeder" \
--env "APP_DEBUG=True" \
--restart unless-stopped \
--log-opt max-size=20m \
--log-opt max-file=3 \
lumutools/watchguard-fw-threat-feeder:latest
Create a blank indicators database
touch indicators.db
Run the Docker Container
docker start lumu-watchguard-fw-threat-feeder
If you have not yet generated an RSA key pair, you can create one using OpenSSL. This key pair is used to secure communication between the on-premises component and the Lumu platform.
Note: If you have already generated a key pair during the integration setup in the Lumu portal, skip this section and ensure you use the matching private key during the on-premises component setup.
Generate a Private Key
Run the following command to generate a 2048-bit RSA private key:
openssl genrsa -out private_key.pem 2048
Extract the Public Key
Run the following command to extract the public key from the private key:
openssl rsa -in private_key.pem -pubout -out public_key.pem
Keep the Public Key to use it in the Lumu Portal
When configuring the integration, you will be asked to provide a public key to encrypt your credentials. Be sure to provide the file you just created.
Securely Store Your Private Key
Keep the private_key.pem file in a secure location. This is the only artifact that can be used to decrypt the credentials you provide during integration setup. Also, you will need this private key file (private_key.pem) during the on-premises component setup.
For the proper functioning of the integration, please follow these recommendations:
Content type
Image
Digest
sha256:5d7fb2c87…
Size
92.7 MB
Last updated
about 1 year ago
docker pull lumutools/watchguard-fw-threat-feeder