Barracuda SSL VPN

Barracuda is a platform that hosts several different security products, such as a firewall, web application firewall, web security, VPN, and others.

To start using Barracuda with InsightIDR:

  1. Configure Barracuda Syslog
  2. Configure the Barracuda VPN Event Source

Configure Barracuda Syslog

You can configure your Barracuda SSL VPN to send syslog to the InsightIDR Collector.

To get started:

  1. Sign in to your Barracuda VPN interface using the ssladmin username and credentials.
  2. In the upper right corner, click the Manage System link.
  3. On the “Systems” dashboard, select the Advanced > Syslog tabs.
  4. In the “Syslog Identifier” field, provide a name for how you want this log to appear.
  5. Select the Yes radio button to include a Timestamp.
  6. Choose whether or not to use UDP.
  7. In the “Syslog Host” field, enter the IP or FQDN of your InsightIDR Collector.
  8. Click the Save Changes button.

Configure InsightIDR to collect data from the event source

After you complete the prerequisite steps and configure the event source to send data, you must add the event source in InsightIDR.

To configure the new event source in InsightIDR:

  1. From the left menu, go to Data Collection and click Setup Event Source > Add Event Source.
  2. Do one of the following:
    • Search for Barracuda SSL VPN in the event sources search bar.
    • In the Product Type filter, select VPN.
  3. Select the Barracuda SSL VPN event source tile.
  4. Choose your collector and select Barracuda SSL VPN as your event source. You can also name your event source if you want.
  5. Choose the timezone that matches the location of your event source logs.
  6. Optionally choose to send unparsed logs.
  7. Configure your default domain and any advanced settings.
  8. Select a data collection method and specify a port and a protocol.
    • Optionally choose to encrypt the event source if you choose TCP by downloading the Rapid7 Certificate.
  9. Click the Save button.