Use Case #1: Firewall Policy Update

Use Case #1: Firewall Policy Update


Firewall response actions are the best way to deal with noisy public IPs attempting to ping/connect to external public-facing servers in the customer’s environment. This can also help respond to potential malicious IPs very quickly through automated response actions and provide necessary feedback based on customer preferences. 

Typical Actions

  1. Write to Blocklist 

Default Playbooks

  1. XDR: Public to Private Exploit Anomaly
  2. XDR: Bad Reputation Login Anomaly

Base Workflow Example



What is needed?

  1. API Credentials
    1. Username/Password - for most Firewall vendors
  2. API Root 
    1. URL of the firewall (along with port in most cases) 
  3. Address Group 
    1. Group name to which SOAR will add IPs 
    2. The groups need to be configured to drop packets from IPs that belong to this group in both directions (incoming/outgoing traffic) 
  4. IP Zone 
    1. For some firewalls, we are required to know which interface we need to add these IPs: WAN or LAN. 
    2. In most cases, this is set to WAN but if not, confirm with the customer.

Note: If you do not see an integration, it still may be possible to configure, CyFlare has an internal SOAR team that can develop integrations within SOAR. This may be of extra cost to a client, depending on the request. Reach out to your CSM or socir@cyflare.com for more details. 


How to get started?

Two Options:
  1. You can work with your dedicated Customer Success Manager, and they will coordinate with the SOAR Team in getting this Automation built out for you. 
  2. Send an email to socir@cyflare.com and specify what integration you would like to leverage for automation to be built out. 
    1. The SOAR Team will process your request and get back to you with the criteria we need and meet with any customer to further explain and validate any questions they may have.