It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda XDR

Integrating SonicWALL Firewall

  • Last updated on

This articles provides the following procedures:

  • Configuring SonicWALL to forward syslog events (prerequisite)

  • Configuring the Barracuda XDR Dashboard

Configuring SonicWALL to forward syslog events

Overview

SonicWALL captures all SonicOS event activity.

Syslog events are forwarded to QRadar. SonicWALL events that are forwarded to QRadar are automatically discovered and log sources are created. For more information on configuring your SonicWALL appliance or for information on specific events, see your vendor documentation.

Procedure

To configure the Syslog for SonicWALL Firewall Collector, perform the following steps.

  1. Log in to your SonicWALL web interface.

  2. From the navigation menu, select Log Syslog.

  3. From the Syslog Servers pane, click Add.

  4. In Name or IP Address, type the IP address of your QRadar Console or Event Collector.

  5. In Port , type 514.
    SonicWALL syslog forwarders send events to QRadar by using UDP port 514.

  6. Click OK.

  7. From the Syslog Format list, select Default.

  8. Click Apply.

  9. Configure the Barracuda XDR Dashboard (see below).

You can find instructions from SonicWALL here.

Configuring the Barracuda XDR Dashboard

Prerequisite: Configure the Syslog for SonicWALL Firewall Collector. See Configuring SonicWALL to forward syslog events (see above).

To integrate SonicWALL Firewall Collector, perform the following steps.

  1. At the Barracuda XDR Dashboard, click Administration > Integrations.
    The Integrations page is displayed.

    campus int page.png
  2. Scroll to the SonicWALL card and then click Setup.

    campus sonic.png

    The Enable page is displayed.

    campus sonic1.png
  3. Select Enabled.
    The selected check box is displayed.

    campus tanium2.png
  4. Click Save.