Skip to content

Integrate WatchGuard Firebox

You can integrate WatchGuard Firebox firewalls so that they send events to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in a WatchGuard integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure WatchGuard to send data to the data collector.

Requirements

The following is required for WatchGuard configuration:

  • A valid account for either WatchGuard System Manager or WatchGuard Web UI.
  • Check the requirements for the data collector you are using by reviewing the guides at Data collectors.

Add a WatchGuard integration

To integrate WatchGuard, you must first install a Sophos XDR data collector, then configure WatchGuard to send logs to it.

Install and configure a data collector

WatchGuard Firebox must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

Once the data collector is created, you can configure WatchGuard to send data to us.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in WatchGuard's own guide: Configure Syslog Server Settings
  2. Be sure to configure the following data collector details:

    • IP address: The Sophos XDR data collector's server IP address
    • Port: 514 or 601
    • Log Format: Syslog

      • Include time stamp: Check to include.
      • Include serial number of the device: Check to include.
    • Syslog Facility: Select according to your priorities.

Your WatchGuard Firebox alerts should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during WatchGuard configuration:

  • You can configure multiple instances of WatchGuard to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of WatchGuard. You don't need to repeat the steps in Sophos XDR.

Additional resources