USM Appliance™

GTA Firewall

When you configure GTA Firewall to send log data to USM Appliance, you can use the GTA Firewall plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:

Plugin Information
Device Details
Vendor GTA
Device Type Firewall
Connection Type Syslog
Data Source Name Gta-firewall
Data Source ID 1882

Integrating GTA Firewall

Before you configure the GTA Firewall integration, you must have the IP Address of the USM Appliance Sensor.

To configure GTA Firewall to send Syslog messages to USM Appliance

  1. From the GTA Firewall user interface, select Configure > Services > Remote Logging.

  2. Select the Enable check box.
  3. Select AUTOMATIC in the source IP address object from the Binding Interface drop-down list box.
  4. Enter the USM Appliance IP address and port 514 in the Syslog Server field, for example:

    172.19.19.1:514

Plugin Enablement

For plugin enablement information, see Enable Plugins.

Additional Resources and Troubleshooting

https://www.gta.com/assets/pdf/guides/current/GB-OS_6.2_Users_Guide.pdf

For troubleshooting, see the vendor documentation.