SonicWall SonicOS
You must have the "Firewall" integrations license pack to use this feature.
You can integrate the SonicOS security appliance with Sophos Central so that it sends event messages to Sophos for analysis.
This integration uses a log collector hosted on a virtual machine (VM). Together they are called a data collector. The data collector receives third-party data and sends it to the Sophos Data Lake.
Note
You can add multiple instances of SonicWall firewalls to the same data collector.
To do this, set up your SonicWall SonicOS integration in Sophos Central, then configure one firewall to send logs to it. Then configure your other SonicWall firewalls to send logs to the same Sophos data collector.
You don't have to repeat the Sophos Central part of the setup.
The key steps to add an integration are as follows:
- Add an integration for this product. This configures an image to use on a VM.
- Download and deploy the image on your VM. This becomes your data collector.
- Configure SonicOS to send data to the data collector.
Requirements
Data collectors have system and network access requirements. To check that you meet them, see Data collector requirements.
Add an integration
To integrate SonicOS with Sophos Central, do as follows:
- In Sophos Central, go to Threat Analysis Center and click Integrations.
-
Click SonicWall SonicOS.
If you've already set up connections to SonicOS, you see them here.
-
Click Add.
Note
If this is the first integration you've added, we'll ask for details about your internal domains and IPs. See My domains and IPs.
Integration steps appears.
Configure the VM
In Integration setup steps you configure your VM to receive data from SonicOS. You can use an existing VM, or create a new one.
To configure the VM, do as follows:
- Add a name and description for the new integration.
-
Enter a name and description for the data collector.
If you've already set up a data collector integration you can choose it from a list.
-
Select the virtual platform. Currently we support VMware ESXi 6.7 Update 3 or later and Microsoft Hyper-V 6.0.6001.18016 (Windows Server 2016) or later.
-
Specify the IP settings for the Internet-facing network ports. This sets up the management interface for the VM.
-
Select DHCP to assign the IP address automatically.
Note
If you select DHCP, you must reserve the IP address.
-
Select Manual to specify network settings.
-
-
Select the Syslog IP version and enter the Syslog IP address.
You'll need this syslog IP address later, when you configure SonicOS to send data to your data collector.
-
Select a Protocol.
You must use the same protocol when you configure SonicOS to send data to your data collector.
-
Click Save.
We create the integration and it appears in your list.
In the integration details, you can see the port number for the data collector. You'll need this later when you configure SonicOS to send data to it.
It might take a few minutes for the VM image to be ready.
Deploy the VM
Restriction
If you're using ESXi, the OVA file is verified with Sophos Central, so it can only be used once. If you have to deploy another VM, you must create an OVA file again in Sophos Central.
Use the VM image to deploy the VM. To do this, do as follows:
- In the list of integrations, in Actions, click the download action for your platform, for example Download OVA for ESXi.
- When the image download finishes, deploy it on your VM. See Deploy a VM for integrations.
When you've deployed the VM, the integration shows as Connected.
Configure SonicOS
You now configure SonicOS to send data to us.
To configure syslog settings on your firewall, do as follows:
Note
If you use SonicWall's Global Management System (GMS) to manage your firewall, you can't change the syslog format (Default) or the syslog ID (Firewall). You can change the other settings. The following instructions don't use GMS.
- Go to Log > Syslog.
- Select Syslog Servers and click Add.
-
Enter the syslog IP address you set for your data collector.
You must enter the same setting you entered in Sophos Central when you added the integration.
-
In Syslog Format choose ArcSight. The Sophos data collector receives ArcSight CEF format alerts.
When you select Arcsight, the Configure icon becomes active.
-
Click the Configure icon. The ArcSight CEF fields Settings configuration window appears.
- Select the ArcSight options that you want to log. In most cases, this is All. To select all options, click Select All.
- Click Save.
-
In the Syslog ID box, enter the syslog ID that you want.
A Syslog ID field is included in all generated messages, prefixed by
id=
.For example, for firewall, the default value, all syslog messages include
id=firewall
. You can set an ID consisting of 0 to 32 letters, numbers, and underscores.Note
When Override Syslog Settings with Reporting Software Settings option is turned on, the Syslog ID field is fixed to "Firewall". You can't change it.
-
Click Accept at the top of the page.
- Go to Log > Settings to configure which alerts are forwarded to Sophos.
-
In Logging Level you must select Warning.
This filters out lower priority events.
-
On the Log > Settings page you can also filter events according to their Event Attributes.
- Select a category and click Configure.
-
In Edit Log Category, select the syslog checkbox for specific categories.
Your changes apply to all groups and events in the selected category.