Cisco Secure Firewall (Firepower Threat Defense)

Modified on Wed, 06 Sep 2023 at 09:57 PM

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the Samurai Help Center and we'll get it updated.

 

This guide describes the steps required to configure Cisco Secure Firewall Threat Defense (FTD) (previously entitled Firepower Threat Defense) to send syslog to the Samurai XDR

 

mceclip0.png Cisco Secure Firewall Management Center (FMC) is required.

 


1) Configure Samurai XDR application

  • Complete the Cisco Firepower Threat Defense Integration


2) Configure Cisco Secure Firewall Management Center Console

  • Security Event Syslog Messages from FTD Devices


 

Configure Samurai XDR Application

To complete the configuration to receive logs:

  1. Login to your Samurai XDR application tenant
  2. Click Telemetry > Integrations from the main menu
  3. Click Create
  4. In the Create Integration screen, find and select Cisco Secure Firewall (Firepower Threat Defense)
  5. The screen will show the Telemetry Collection and parameters.
  6. Make note of the IP Address and Port on the screen, they will be used in the device configuration below.
  7. Click on Finish


Configure Cisco Secure Firewall Management Center Console

Follow the "Stepsoutlined within the Cisco documentation:


mceclip0.png Default settings should be used unless otherwise specified in the listed parameters

 


mceclip0.png You can also refer to Configure a Syslog Server if you have queries based on options available.


Field NameParameter
IP AddressSamurai Secure Syslog Collector IP address
ProtocolTCP
PortSamurai XDR Secure Syslog Collector port number
Security Zones or Named InterfaceSelect the interface/zone on which the Samurai XDR Secure Syslog Collector is reachable
Enable Secure SyslogThis option must be selected
Time Stamp FormatRFC 5424 (yy-MM-ddTHH:mm:ssZ)
Enable Syslog Device IDEnabled (Host Name)
Send syslogs in EMBLEM formatUnchecked (This option is not available, since you would have selected TCP under "protocol".)

Table 1: Syslog settings

 

Field NameParameter
IPS SettingsSend Syslog Messages for IPS Events (Selected)
File and Malware SettingsSend Syslog messages for File and Malware events (Selected)

Table 2: General logging settings

 

Field NameParameter
LoggingLog at End of Connection (Selected)

 Table 3: Logging settings



Configure Certificate

To permit a secure connection between the device and Samurai XDR you must upload a valid certificate.

From the Firewall Management Center

  1. Select Devices > Certificates
  2. Select "Add New Certificate"
  3. Select the device you wish to add the certificate from the Device dropdown.
  4. From "Cert Enrollment" > "Select a certificate enrollment object", click on the plus (+)
  5. "Add Cert Enrollment" menu will appear.
  6. Provide a name e.g. "SamuraiXDR"
  7. Select the "CA Information" tab
  8. Enrollment Type:  Select Manual
  9. Check the box "CA Only"
  10. Open the .PEM digital certificate in a text editor and paste in the "CA Certificate:" text box.
  11. In "Validation Usage", select the check box "SSL Server". All other boxes remain unchecked.
  12. Click on "Save"
  13. Complete the upload from the "Add New Certificate", it will show the device selected and the certificate names as entered in step 6 above.
  14. Click on "Add"
  15. Navigate to Deploy and Deployment. Select your device.
  16. The configuration is now complete.


Once you have completed the configuration of your firewall to send logs to Samurai XDR, your integration will automatically be discovered once Samurai XDR starts receiving logs from your firewall.