Dynamic Firewall Objects for AWS and Azure

How to create a dynamic object with the public ip addresses used by AWS or Azure.

  • For standalone Firewalls SSH into the CloudGen Firewall
  • For managed Firewalls SSH into the Control Center Box Level

Example command to create a dynamic network object with the IP addresses of the AWS EU-Central-1 region:

# external-netobj-tool create Aws.Datacenters.Eu-central-1
  • The dynamic object is automatically updated every hour

After creation it should look like this:

Dynamic rule example
Example of the dynamic object

How to increase the Firewall Monitor history on a Barracuda CloudGen Firewall

Issue

Solution

  • Statistics database is stored in
    • /var/phion/appstat
  • Can be increased depending on available disk size
    • Different per appliance
    • Value 0 means automatic adjustment
      • No Barracuda Campus documentation found that describes the mechanism behind it
  • After the changes, keep an eye on the resources in the CONTROL tab
CONFIGURATION > Configuration Tree > Box > Infrastructure Services > General Firewall Configuration