Collect Firewall Metadata with Lumu VA and Ubiquiti Unifi Firewall

Collect Firewall Metadata with Lumu VA and Ubiquiti Unifi Firewall

Requirements

  • A Unifi Cloud Gateway device
  • Have admin access to the device via the Unifi Site Manager Portal to create a new Forwarding configuration.
  • The most recent version of the Lumu Virtual Appliance installed.
These are the general steps you should follow to configure a SIEM server destination on Ubiquiti Unifi to send all metadata to Lumu:

Deploy and Set Up Lumu VA

All the detailed steps and guidance to create, download and install a virtual appliance on your preferred hypervisor or Cloud solution are available in our documentation:

Set up a Lumu VA Firewall Log Collector

Go to the Lumu Virtual Appliance and refresh the VA Collectors settings by running the command lumu-appliance collectors refresh. If the appliance is running, it must be stopped in order to continue the setup process.

Select the option Ubiquiti Unifi Cloud Gateway, then input the following data:
  • Protocol type: Select the UDP option. Ubiquiti Unifi devices use UDP protocol to send Syslog data.
  • Port number: Provide a number between 1024 and 65535, inclusive.
  • Timezone: The timezone for VA setup. Use the canonical ID (e.g. America/Chicago). You can use this external article for reference.

Configure Ubiquiti Unifi to Send Metadata to Lumu VA

You will need to configure your Ubiquiti Unifi device to send logs to the Virtual Appliance. This requires the following:

  • A SIEM Server destination
  • A Firewall Action Logging rule

Configure a SIEM Server destination

1. First, login to the Unifi Site Manager portal

2. Head to the left side panel. Click on the Sites icon to open the Sites menu. Then, click on the Site where your Unifi device is enrolled.

3. In the Network panel, head to the left side panel. Click on the Settings (Gear) icon.

4. In the Settings panel, you must do the following:


a. First, click on the System(1) menu.
b. Select the SIEM server(2) option under the Activity Logging section.
c. In the Contents(3) section, select the following : Devices, and Firewall Default Policy. Make sure you click on the Save button when done.

d. Input the address of the Virtual Appliance you want to send logs to under the Server Address(4) field
e. Input the corresponding port for the remote address of the Virtual Appliance you want to send logs to under the Port(5) field.
f. Once you’re done, click on the Apply Changes(6) button.

Configure Firewall Logging rule

Notes
We recommend enabling logging for all your custom rules to have full visibility
1. You must configure specific rules to be logged. To do so, you must configure each rule to generate a Syslog entry when matched. From the window accessed in Step 3 of the Configure a SIEM Server destination section, do the following:
a. Click on the Security(1) menu
b. Click on the Traffic & Firewall Rules(2) tab.
c. Select one of the listed rules(3).

d. In the panel that opens, enable the Logging toggle at the end of the configuration window, and save your changes by clicking on the Apply Changes button.

        • Related Articles

        • Collect MikroTik Firewall Metadata with Lumu VA

          Requirements MikroTik Router OS 6 or newer. Have admin access to create a new Forwarding configuration. Have the most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a syslog server ...
        • Collect Firewall Metadata with Lumu VA and Huawei USG Firewall

          Requirements A Huawei USG Firewall device. Have admin access to create a new Forwarding configuration. Have the most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a syslog server on ...
        • Lumu Log Forwarder Ubiquiti Unifi Cloud Gateway Configuration

          Requirements A Unifi Cloud Gateway device Refer to Unifi Cloud Gateways for further reference Have admin access to the device via the Unifi Site Manager Portal to create a new Forwarding configuration. A configured Virtual Appliance or Log Forwarder ...
        • Collect Firewall metadata with Lumu VA and WatchGuard

          Requirements Admin access to configure a syslog server on WatchGuard. The most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a syslog server on a WatchGuard Firewall to send all ...
        • Collect Firewall Metadata with Lumu VA and Check Point

          Requirements Admin access to configure a syslog server on Check Point firewall. The most recent version of the Lumu Virtual Appliance installed. These are the general steps you should follow to configure a syslog server on a Check Point firewall to ...