Configuring Network Device - Ubiquiti Unifi Security Gateway (USG)
This article will walk through the steps required to send Syslog data from a Ubiquiti USG device to the RocketCyber Firewall Analyzer
Enable Remote Logging
- Log in to the Unifi Network Controller and click on Settings (gear icon) on the left menu.
- Click on Network Settings
- Click On Advanced
- In the Remote Logging Section switch on Enable Syslog
- In the Syslog Host field, enter the IP address of the RocketCyber Syslog Server
- In the Syslog Port field, enter the Port for the RocketCyber Syslog Server (default is 514 recommended).
- Click Apply Changes at the bottom of the screen
Configure Firewall Rule Logging
Each firewall rule must be configured to allow logging.
- From the Settings Menu, click on Internet Security
- Click on Firewall
- For each rule that you want to log events from click on Edit.
- In the edit details dialog click on Advanced.
- Switch on Enable Logging.
- Click Apply
Configure Default Action Logging
- On the Firewall page, scroll down to the Settings section and click on Default Action Logging.
- Switch on WAN Rules
- Switch on LAN Rules.
- Click on Apply Changes.
The steps for this configuration were verified with Controller Software v5.13.29.