Sign inSign up

lumutools/watchguard-fw-threat-feeder

By lumutools

•Updated about 1 year ago

Image
0

4.3K

lumutools/watchguard-fw-threat-feeder repository overview

⁠Lumu - Watchguard FW Integration

Lumu Defender provides a framework to help you leverage Lumu's integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems, and more.

The Lumu Defender Watchguard FW Out-of-the-box integration enables you to configure Watchguard Firewalls to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization. See more at: Lumu docs⁠.

⁠Important: Review control database configuration

Check this section first if you have a running Watchguard FW Out-of-the-box integration component and the Lumu team indicated you to update it.

⁠Check if your control database is mounted as an external volume

You must check if you already have a version with an external control database. To check this, run the following command on the host where you deployed the integration.

docker inspect lumu-watchguard-fw-threat-feeder --format '{{ .Mounts }}'

If you obtain a result with a single bind record as shown below, go to the next step to extract your control database.

[{bind  REDACTED_PATH_TO_YOUR_PRIVATE_KEY /tmp/p.key   true rprivate}]

If you obtain a result with two bind records as follows. You can proceed with the update process⁠.

[{bind  REDACTED_PATH_TO_YOUR_PRIVATE_KEY /tmp/p.key   true rprivate} {bind  REDACTED_PATH_TO_YOUR_DATABASE/indicators.db /app/indicators.db   true rprivate}]
⁠Extract the control database to the integration host

Run the following command to extract the database from the container to the integration host.

docker cp lumu-watchguard-fw-threat-feeder:/app/indicators.db .

You will have a new file named indicators.db in your current host folder. Now, you can proceed with the update process.

⁠Getting Started

To run this integration, you must configure it in your Lumu portal and set up the on-premises component. This guide shows you how to install and run the on-premises component to feed your WatchGuard Firewall with Lumu's confirmed compromises.

⁠Requirements

Before proceeding, ensure you have:

  • Configured the Lumu Defender WatchGuard Firewall Out-of-the-box Integration in your Lumu portal. See more at: Lumu docs⁠.
  • Installed Docker on the machine where you intend to run the on-premises component. Refer to the Docker official installation guide.

⁠If you are updating an existing integration

Ensure you extracted your control database to your host as indicated in the Important: Review control database configuration⁠ section.

You must stop and delete your current integration container before continuing. Run the following block of commands to do so:

docker stop lumu-watchguard-fw-threat-feeder
docker rm lumu-watchguard-fw-threat-feeder

You can proceed with your selected deployment mode after running these commands, either the Single Integration Mode⁠ or the Multiple Integration Mode⁠.

⁠Setting Up the On-Premises Component

The on-premises component can run in two modes:

  • Single Integration Mode: For setting up a single integration.
  • Multiple Integration Mode: For setting up multiple integrations simultaneously.

Note: If you have not yet generated an RSA key pair, you can create one using OpenSSL. Follow the steps in Generating an RSA Key Pair⁠ before continuing. This key pair is used to secure communication between the on-premises component and the Lumu platform.

⁠Single Integration Mode

If you are setting up a single integration, follow the steps below.

⁠Steps
  1. Prepare the Required Parameters

    Replace with the appropriate values:

    • <COMPANY_ID>: Your Lumu Company UUID.
    • <INTEGRATION_ID>: Your Lumu Integration UUID.
    • <PRIVATE_KEY_FILE_PATH>: Path to your RSA private key file (private_key.pem). This should be the private key matching the public key you provided during the integration configuration in the Lumu portal.
    • [Optional] APP_DEBUG: Set to True to enable debug logging; otherwise, omit or set to False.
  2. Create the Docker Container

    docker create \
      -v ./indicators.db:/app/indicators.db \
      -v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
      --name "lumu-watchguard-fw-threat-feeder" \
      --env "COMPANY_ID=<COMPANY_ID>" \
      --env "INTEGRATION_ID=<INTEGRATION_ID>" \
      --restart unless-stopped \
      --log-opt max-size=20m \
      --log-opt max-file=3 \
      lumutools/watchguard-fw-threat-feeder:latest
    

    If you want to run your component in DEBUG mode, use the following command:

    docker create \
      -v ./indicators.db:/app/indicators.db \
      -v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
      --name "lumu-watchguard-fw-threat-feeder" \
      --env "COMPANY_ID=<COMPANY_ID>" \
      --env "INTEGRATION_ID=<INTEGRATION_ID>" \
      --env "APP_DEBUG=True" \
      --restart unless-stopped \
      --log-opt max-size=20m \
      --log-opt max-file=3 \
      lumutools/watchguard-fw-threat-feeder:latest
    
  3. Create a blank indicators database

    touch indicators.db
    
  4. Run the Docker Container

    docker start lumu-watchguard-fw-threat-feeder
    
⁠Multiple Integration Mode

If you need to deploy multiple integrations in a single container, use the multiple integration mode by creating a config.yaml file.

⁠Parameters
  • <COMPANY_ID>: Lumu Company UUID.
  • <INTEGRATION_ID>: Lumu Integration UUID.
  • <PRIVATE_KEY_FILE_PATH>: Path to the RSA private key file (private_key.pem). This should be the private key matching the public key you provided during the integration configuration in the Lumu portal.
  • [Optional] APP_DEBUG: Set to True to enable debug logging; otherwise, omit or set to False.
⁠Steps:
  1. Prepare the Configuration File config.yaml

    Create a config.yaml file with the following structure:

    integrations:
      -  
        company_id: <COMPANY_ID>  # UUID from Lumu portal
        id: <INTEGRATION_ID>      # UUID from Lumu portal
      -  
        # Integration 2
      -
        # Integration N
    

    Replace <COMPANY_ID> and <INTEGRATION_ID> with the appropriate values for each integration.

  2. Create the Docker Container

    Replace <PRIVATE_KEY_FILE_PATH> with the path to your RSA private key file (private_key.pem):

    docker create -v $PWD/config.yaml:/app/config.yaml \
      -v ./indicators.db:/app/indicators.db \
      -v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
      --name "lumu-watchguard-fw-threat-feeder" \
      --restart unless-stopped \
      --log-opt max-size=20m \
      --log-opt max-file=3 \
      lumutools/watchguard-fw-threat-feeder:latest
    

    If you want to run your component in DEBUG mode, use the following command:

    docker create -v $PWD/config.yaml:/app/config.yaml \
      -v ./indicators.db:/app/indicators.db \
      -v <PRIVATE_KEY_FILE_PATH>:/tmp/p.key \
      --name "lumu-watchguard-fw-threat-feeder" \
      --env "APP_DEBUG=True" \
      --restart unless-stopped \
      --log-opt max-size=20m \
      --log-opt max-file=3 \
      lumutools/watchguard-fw-threat-feeder:latest
    
  3. Create a blank indicators database

    touch indicators.db
    
  4. Run the Docker Container

    docker start lumu-watchguard-fw-threat-feeder
    
⁠Generating an RSA Key Pair

If you have not yet generated an RSA key pair, you can create one using OpenSSL. This key pair is used to secure communication between the on-premises component and the Lumu platform.

Note: If you have already generated a key pair during the integration setup in the Lumu portal, skip this section and ensure you use the matching private key during the on-premises component setup.

⁠Steps to Generate an RSA Key Pair
  1. Generate a Private Key

    Run the following command to generate a 2048-bit RSA private key:

    openssl genrsa -out private_key.pem 2048
    
  2. Extract the Public Key

    Run the following command to extract the public key from the private key:

    openssl rsa -in private_key.pem -pubout -out public_key.pem
    
  3. Keep the Public Key to use it in the Lumu Portal

    When configuring the integration, you will be asked to provide a public key to encrypt your credentials. Be sure to provide the file you just created.

  4. Securely Store Your Private Key

    Keep the private_key.pem file in a secure location. This is the only artifact that can be used to decrypt the credentials you provide during integration setup. Also, you will need this private key file (private_key.pem) during the on-premises component setup.

⁠General Recommendations

For the proper functioning of the integration, please follow these recommendations:

  • The integration between Lumu and your firewall is carried out using the Blocked Sites list.
  • These objects are actively used and updated by this integration; therefore, they must not be modified manually.
  • When using the Docker image, do not stop the container. Stopping the container will cause the synchronization process to restart from scratch.

⁠Find out more about us

Tag summary

Content type

Image

Digest

sha256:5d7fb2c87…

Size

92.7 MB

Last updated

about 1 year ago

docker pull lumutools/watchguard-fw-threat-feeder