Security Compliance

Integrate SonicWall firewalls with SolarWinds SEM

This article provides instructions on forwarding SonicWall logs to the SEM manager and adding a SonicWall connector in the SEM console.

First published date

10/10/2018 2:11 AM

Last published date

10/10/2018 2:11 AM

Overview

This article discusses how to forward SonicWall logs with the Security Event Manager (formerly Log & Event Manager) manager and how to add a SonicWall connector in the SEM console. The information applies to all SonicWall versions.

Product section

Security Event Manager

Resolution

Forward SonicWall logs to your SEM manager

  1. Connect to your SonicWall firewall using a web browser on a computer that is on the SonicWall LAN.
  2. Log in using administrator credentials for your SonicWall firewall.
  3. Click Log > Log Settings.
  4. In the Syslog Server field, enter the IP address of your SEM manager which you can find in the SEM console under Manage > Appliances. 
  5. Verify that the Local Interface and Outbound Interface selections are correct.
  6. Click Submit. 
  7. When SonicWall prompts you to restart the firewall, click Restart to apply your changes. 

 

Add a SonicWall connector in your SEM console

SEM HTML5 console (versions 6.6 and newer)
  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, enter sonicwall.
  3. Select the SonicWall Firewalls connector, and then click Add Connector.
  4. Replace the name with a more descriptive connector name. Solarwinds recommends using the word firewall in your firewall connector name. This helps the Firewall filter function correctly.
  5. Leave the Log File value set to its default value (SonicWall does not allow you to change the logging location of its log files).
  6. Click Add.
  7. Under Configured connectors, select the connector, and then click Start.
SEM Flash console 
  1. On the SEM console menu bar, navigate to Manage > Appliances, and then log in to the SEM manager where you can configure the connector. 
  2. Next to the SEM manager, click the gear icon, and then select Connectors.
  3. In the Connector Configuration window, enter SonicWall in the search box at the top of the Refine Results pane.
  4. Next to the SonicWall connector, click the gear icon, and then select New.
  5. Replace the Alias value with a more descriptive connector alias. SolarWinds recommends using the word firewall in your firewall connector alias. This helps the Firewall filter function correctly.
  6. Leave the Log File value set to its default value. This is because SonicWall does not allow you to change the logging location of its log files.
  7. Click Save.
  8. Next to the new connector, click the gear icon, and then select Start. The Status icon will turn green to indicate the connector has started.
  9. To exit the Connector Configuration window, click Close.

Once the connector starts running, the default Firewall filter will begin displaying alerts from your SonicWall firewall, provided you assigned the appropriate alias in Step 5.

The conditions for the default firewall filter read... Any Alert.ToolAlias = *Firewall*, where the asterisks serve as wildcard characters. If the connector alias defined in Step 5 does not contain the word firewall, the default filter will not work until it has been edited to match the alias you defined.

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.