Sophos Firewall Out-Of-The-Box Response Integration

Sophos Firewall Out-Of-The-Box Response Integration

To learn more about Out-of-the-box Integrations and their benefits, please refer to this article.

Requirements

  • Sophos Firewall
    • Sophos Firewall with Web Protection
  • Lumu License
    • An active Lumu Defender subscription

Add Integration

1. Log in to your Lumu account through the Lumu Portal and navigate to the integrations screen.

2. Locate the Sophos Firewall integration in the available apps area and click to add, then click to view details.

3. Familiarize yourself with the integration details available in the app description and click the button below to activate the integration.

4. To activate the integration, add a description and select the threat types you want to include.

5. Once you create the integration, you will be provided with the Integration URL


Once the integration is activated, the Suspicious Object Management section will be updated with confirmed compromises found by Lumu within the preceding 3 days.

Configure Sophos Firewall

1. Start with opening the Sophos Firewall platform:

2. You will see the dashboard with all registered activity. Go into the Protect > Web option, where you can register Categories with an external database that will feed your Firewall with malicious lists.


3. Click on the Categories option to add a new category.

4. Complete the following steps:

a. Set the name of the Category.

b.  Add a Description (Optional).

c. On the Classification option, select Objectionable.

d. To keep synchronicity with the Lumu list, select the External URL database and paste the link provided by the integration.

The refresh time of the content provided by the list is about 48 hours.

4. Finally, add the Web Category you just created to an existing Web Policy in order to control and manage Web traffic based on it.

You can create your own Web Policy for Lumu if necessary.









You must use the Web policy referencing Lumu Web category in your Firewall policies. That way, your Sophos Firewall will block the traffic related to the database provided by Lumu.

Bear in mind that the configuration depends on your environment’s characteristics and must be done according to your business needs. For more information on how to carry out this procedure, please refer to Sophos Firewall’s official documentation.

        • Related Articles

        • Sophos XG Firewall Custom Response Integration

          This article shows how to leverage the Lumu Defender API and Sophos XG API to mitigate security risks. Requirements Sophos XG Firewall A Sophos XG Firewall with SFOS 19.0.0 GA-Build317 with the Xstream Protection bundle (Network Protection and Web ...
        • Juniper SRX Firewall Out-of-the-box Response Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. In this article, you will find out how to configure Juniper SRX Firewall to receive and block adversaries detected by Lumu and improve the detection & ...
        • Sophos Endpoint Protection Out-of-the-Box Response Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. Requirements Sophos Central Sophos Central Account Access. API Token. You can obtain it in the API Token Management console. Lumu License An active Lumu ...
        • Sophos UTM SG Custom Response Integration

          This article shows how to leverage the Lumu Defender API and Sophos UTM SG API to mitigate security risks. Requirements Sophos UTM SG subscription You need a Sophos UTM SG with Firewall and Web filter capabilities. Lumu Defender API key To retrieve ...
        • SonicWall Firewall Simplified Out-of-the-Box Response Integration

          Requirements SonicWall Firewall SonicWall Operating System 6.5 or 7 For SonicOS 6.5, the integration is tested with SonicOS 6.5.4.5-53n or above. Please follow the instructions in the corresponding section to deploy it. Lumu License Lumu Defender ...