Barracuda CloudGen Firewall Integration
Overview
Barracuda CloudGen Firewalls provide network security with advanced threat protection, SD-WAN, and cloud integration. KYRA MDR collects Barracuda syslog data for security monitoring and incident detection. Supports firmware 8.x and 9.x.
Prerequisites
- A KYRA MDR Collector installed and running
- Barracuda CloudGen Firewall with administrative access
- Barracuda Firewall Admin or web interface access
- Network connectivity from the firewall to the collector on port 514
Configuration
Configure syslog streaming in Barracuda Firewall Admin:
- Open Barracuda Firewall Admin
- Navigate to Configuration > Infrastructure Services > Syslog Streaming
- Click Add and configure:
Name: KYRA-MDRIP Address: <collector-ip>Port: 514Protocol: TCPLog Level: Notice- Under Log Selection, enable:
- Firewall Activity Logs
- Firewall Audit Logs
- Threat Scan Logs
- Click Send Changes and Activate
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Firewall Activity | Connection allow/block events | Network security monitoring |
| Audit | Configuration change events | Change management compliance |
| ATP | Advanced threat protection results | Zero-day malware detection |
| IPS | Intrusion prevention events | Exploit and attack detection |
| URL Filter | Web categorization events | Web security policy enforcement |
| VPN | Site-to-site and client VPN events | Remote access monitoring |
Troubleshooting
No logs streaming: Verify the syslog streaming configuration is activated. Barracuda requires both saving and activating changes.
Missing ATP logs: Advanced Threat Protection logging requires an active ATP subscription. Verify the license status.
Connectivity issues: Barracuda uses the management interface for syslog by default. Ensure the correct source interface is configured.
Contact kyra@seekerslab.com for support.