Overview
SonicWall is an American cybersecurity company that sells a range of Internet appliances primarily directed at content control and network security. These include devices providing services for network firewalls, unified threat management (UTM), virtual private networks (VPNs), virtual firewalls, SD-WAN, cloud security and anti-spam for email.
Prerequisites
- Logsign 6.3.26+ versions support this integration.
Configure On Sonicwall
Forwarding settings are completed as follows:
- Log in to the Sonicwall portal.
- In the Main menu, click Network > Address Objects.
- Click “+Add” button for create a new group.
- In this part, you can define the custom group and you can add ip to the group.
(Note: Creating and adding groups are explained here. For Sonicwall integration, host, user and password are needed.)
Configure On Logsign
Forwarding settings are completed as follows:
- Click Settings > Integrations > Responses.
- In the ‘Search’ part, write Sonicwall.
- Click ‘Configure’ and then click ‘+Device’.
- Define the settings as follows:
- Device Name: Define the Device Name.
- Host: The IP address of the Sonicwall device/product to be integrated with Logsign.
- Username: Specify the user you have defined in Sonicwall.
- Password: Specify the password you have defined in Sonicwall.
Methods
BLOCK-IP
- Device Name: Define the Device Name.
- Ip: Specify the ip you have blocked in Sonicwall.
- Group Name: In Sonicwall you can add whatever object you want to include in the group.
- Zone: You can select the relevant zone for the process you want to do.
- Expire Time: The duration of how long the object that we add to the group will stay in that group is specified.
UNBLOCK-IP
- Device Name: Define the Device Name.
- IP: Specify the unblock IP address.
BLOCK-FQDN
- Device Name: Define the Device Name.
- Group Name: In Sonicwall you can add whatever object you want to include in the group.
- Zone: You can select the relevant zone for the process you want to do.
- Domain: Specify the domain you want to block.
UNBLOCK-FQDN
Device Name: Define the Device Name.
Domain: Specify the domain you want to unblock.