Skip to content

Barracuda CloudGen Firewall Integration

Overview

Barracuda CloudGen Firewalls provide network security with advanced threat protection, SD-WAN, and cloud integration. KYRA MDR collects Barracuda syslog data for security monitoring and incident detection. Supports firmware 8.x and 9.x.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Barracuda CloudGen Firewall with administrative access
  • Barracuda Firewall Admin or web interface access
  • Network connectivity from the firewall to the collector on port 514

Configuration

Configure syslog streaming in Barracuda Firewall Admin:

  1. Open Barracuda Firewall Admin
  2. Navigate to Configuration > Infrastructure Services > Syslog Streaming
  3. Click Add and configure:
Name: KYRA-MDR
IP Address: <collector-ip>
Port: 514
Protocol: TCP
Log Level: Notice
  1. Under Log Selection, enable:
    • Firewall Activity Logs
    • Firewall Audit Logs
    • Threat Scan Logs
  2. Click Send Changes and Activate

Collected Log Types

Log TypeDescriptionSecurity Use
Firewall ActivityConnection allow/block eventsNetwork security monitoring
AuditConfiguration change eventsChange management compliance
ATPAdvanced threat protection resultsZero-day malware detection
IPSIntrusion prevention eventsExploit and attack detection
URL FilterWeb categorization eventsWeb security policy enforcement
VPNSite-to-site and client VPN eventsRemote access monitoring

Troubleshooting

No logs streaming: Verify the syslog streaming configuration is activated. Barracuda requires both saving and activating changes.

Missing ATP logs: Advanced Threat Protection logging requires an active ATP subscription. Verify the license status.

Connectivity issues: Barracuda uses the management interface for syslog by default. Ensure the correct source interface is configured.

Contact kyra@seekerslab.com for support.