Up
Previous Next

Sheriff CSMâ„¢

Barracuda NextGen Firewalls

When you configure Barracuda NextGen Firewalls to send log data to Sheriff CSM, you can use the Barracuda Next Gen Firewall plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:

Plugin Information

DeviceDetails
Vendor Barracuda
Device Type Firewall
Connection Type Syslog
Data Source Name barracuda-ng
Data Source ID 1753

Note: The Barracuda Next Gen Firewall plugin supports both Barracuda NextGen Firewalls X-Series and F-Series.

Integrating Barracuda NextGen Firewalls

To configure Barracuda NextGen Firewalls to forward log data over Syslog to Sheriff CSM
  1. Go to the LOGS > Log Streaming.

  2. In the Stream target field, type the hostname or IP address of your Sheriff CSM Sensor (Deputy).

    Note: Only one target can be defined.

  3. In Protocol / Port, enter

    • port 514 if you're using UDP
    • port 601 if you're using TCP
  4. Select the log streams you want to enable.

  5. Click Save Changes.

  6. Verify that a connection exists between the device and the Sheriff CSM Sensor.

    • Go to BASIC > Recent Connections.
    • Filter the list of connections for the Protocol, Service, and Destination IP of your Sheriff CSM Sensor.

Plugin Enablement

For plugin enablement information, see Enable Plugins.

Additional Resources and Troubleshooting

https://campus.barracuda.com/product/nextgenfirewallf/article/NGF70/LogsConfigSyslogStreaming/

For troubleshooting, refer to the vendor documentation:

https://www.barracuda.com/support/knowledgebase
Topic revision: r11 - 28 Jun 2022, SheriffCyberSecurity
Copyright 2020 Sheriff Cyber Security, LLC. All rights reserved.