Collect Firewall Metadata with Lumu VA and Sangfor Athena Firewall

Collect Firewall Metadata with Lumu VA and Sangfor Athena Firewall

Requirements

  • A Sangfor Athena NGFW device.
  • An administrator user to configure a Log Server on Sangfor Athena Firewall.
  • The most recent version of the Lumu Virtual Appliance.

These are the general steps you should follow to configure a Syslog server destination on Sangfor Athena Firewall to send all metadata to Lumu:


Deploy and Set Up Lumu VA

All the detailed steps and guidance to create, download, and install a virtual appliance on your preferred hypervisor or Cloud solution are available in our documentation:

Set up a Lumu VA Firewall Log Collector

Go to the Lumu Virtual Appliance and refresh the VA Collectors settings by running the command lumu-appliance collectors refresh. If the appliance is running, it must be stopped to continue the setup process.


Select the option Sangfor Athena, then input the following data:

  • Protocol type: Select UDP. Sangfor Athena devices use the UDP protocol to send Syslog data.
  • Port number: Provide a number between 1024 and 65535, inclusive.
  • Timezone: The timezone for VA setup. Use the canonical ID (e.g. America/Chicago). Check this article for further reference.

Configure Sangfor Athena to Send Metadata to Lumu VA

You will need to configure your Sangfor Athena device to send logs to the Virtual Appliance. This requires the following:

  • A Log Server destination
  • Enable logging for Application Control Policies.
  • Enable logging for Network Security Policies.

Configure a Log Server

     1. First, log in to your Sangfor Athena Firewall.


2. Click the Monitor option. Then click Logging Options under the Settings section in the left navigation bar.


3. In the Logging Options window, ensure the Security Logs tile is marked as Enabled. Enable the Log Server option.


4. Repeat step 2 for Application Control Logs, Traffic Audit Logs, and Local ACL Logs.

5. Head to the Log Servers section below. Click the Add button.


6. Enter the IP address and the listening port. Ensure the Log Type field is set to all configured logs: Security, Application Control, Traffic, and Local ACL.


7. When finished, click the Save button at the bottom of the configuration page.

Enable logging for Application Control Policies

NotesWe recommend enabling logging for all your rules to have full visibility.

Now, you must configure each rule to generate a log entry when matched. Head to Policies and select Application Control under the Access Control section in the left navigation bar.


From this screen, follow the following steps for each rule:

1. Click the Edit option on the right side of the policy record.


2. In the Edit Application Control Policy window, scroll down and click the Settings button next to the Advanced label.


3. Enable the Logging options: Log at session start and Log at session end. When finished, click the Save button.


Repeat all steps for all the Application Control Policies. This ensures Lumu has complete visibility of the network metadata moving through the Firewall.

Enable logging for Network Security Policies

NotesWe recommend enabling logging for all your policies to have full visibility.

Now, you must configure each rule to generate a log entry when matched. Head to Policies and select the Policies option under the Network Security section in the left navigation bar.


From this screen, follow the following steps for each rule:

1. Click the Edit option on the right side of the policy record.


2. In the Edit Network Security Policy window, move to the Detection and Response section by clicking the Next button twice.


3. Enable the Log events option at the end of the policy window. When finished, click the Save button.


Repeat all steps for Content Security Network Security Policies. This ensures Lumu has complete visibility of the Web navigation network metadata moving through the Firewall.

      Get an AI Summary

          • Related Articles

          • Collect MikroTik Firewall Metadata with Lumu VA

            Requirements MikroTik Router OS 6 or newer. Have admin access to create a new Forwarding configuration. Have the most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a syslog server ...
          • Collect Firewall Metadata with Lumu VA and Huawei USG Firewall

            Requirements A Huawei USG Firewall device. Have admin access to create a new Forwarding configuration. Have the most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a syslog server on ...
          • Collect Firewall metadata with Lumu VA and WatchGuard

            Requirements Admin access to configure a syslog server on WatchGuard. The most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a syslog server on a WatchGuard Firewall to send all ...
          • Collect Firewall Metadata with Lumu VA and Juniper SRX

            Requirements Juniper SRX Firewall Junos version 20+. Have admin access to configure a Syslog server on Juniper SRX. Have the most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a ...
          • Collect FortiGate Firewall Metadata with FortiAnalyzer and Lumu VA

            In scenarios where all your FortiGate deployment logs are centralized within a FortiAnalyzer, you can use it to accelerate the deployment of Lumu and forward all firewall logs at once using the FortiAnalyzer data collection capabilities from Lumu. ...