Collect Firewall Metadata with Lumu VA and Cisco Firepower
The
Lumu Virtual Appliance
(VA)
offers the option to create Collectors, a seamless way to integrate the network metadata
of your entire enterprise into the Lumu cloud with the lowest impact on the network operation
.
In cases where attacks avoid domain resolution, the traces of adversarial contact can lie in the access logs of firewalls. This option is also available for accommodating networks where DNS configuration is not possible. In this scenario, the firewall forwards the logs to Lumu’s VA for processing traffic. If the firewall has URL filtering enabled, and the URLs can be included in the logs, all the IT assets using the firewall would be monitored. This approach ensures compromise visibility without having to make major changes.
In this guide, we provide you with instructions and resources on how to configure Cisco Firepower Firewall to forward all Firewall logs to Lumu through a Virtual Appliance.
These are the general steps you should follow to configure a Syslog server on a Cisco Firepower firewall to send all metadata to Lumu:
All the detailed steps and guidance to create, download, and install a virtual appliance on your preferred hypervisor or Cloud solution are available in our documentation:
Go to the Lumu Virtual Appliance and refresh the VA Collectors settings by running the command
lumu-appliance collectors refresh.
If the appliance is running, it should be stopped for setting up collectors.
Select the option that refers to Check Point and the format that suits you best, then inform the following data:
Once you have installed and configured a Lumu Virtual Appliance with the respective firewall collector, the next step is to set up Cisco Firepower to forward firewall metadata to Lumu. Following, you will find the overall steps to configure the forwarding of the required events. The detailed guide can be found in Cisco’s official documentation:
Cisco Firepower classifies its events using a specific ID and a severity level. In the next table, you can find the events of interest for Lumu:
Event ID |
Severity level |
106100 |
6 (informational) |
302013 |
6 (informational) |
302014 |
6 (informational) |
302015 |
6 (informational) |
302016 |
6 (informational) |
430002 |
5 (notification) |
430003 |
1 (alert) |
It’s recommended to create a custom event list filter to avoid sharing non-required events with your Lumu VA. This allows you to optimize resources on your Firewall and also bandwidth. To create an event list filter follow these steps:
3. Click the
OK
button.
You need to add your Lumu VA as a Syslog server object inside Cisco Firepower Firewall. Follow these steps to add a new Syslog server object: