To configure Network Security and Email Security - Cloud integration using the Network Security Web UI:
In the Network Security appliance's Settings page, set the following values:
HTTP alerts | HTTP server listing |
|---|---|
All checked |
|
hostname # fenotify http service fireeyecloud auth username <username>
hostname # fenotify http service fireeyecloud auth password <password>
hostname # fenotify http service fireeyecloud auth enable
Enable the CLI configuration mode on your Network Security appliance:
hostname > enablehostname # configure terminalEnable HTTP notifications:
hostname # fenotify http enablehostname # fenotify http alert domain-match enablehostname # fenotify http alert infection-match enablehostname # fenotify http alert malware-callback enablehostname # fenotify http alert malware-object enablehostname # fenotify http alert web-infection enableSpecify the server that will post HTTP notifications:
hostname # fenotify http service fireeyecloud enableSpecify the user name and password for HTTP authentication and enable authentication. The user name and password were provided in your welcome email. Contact FireEye Support if you no longer have this information.
Specify notification preferences:
hostname # fenotify http service fireeyecloud prefer notification all-eventshostname # fenotify http service fireeyecloud prefer message delivery per-eventhostname # fenotify http service fireeyecloud provider generic message format xml-extendedhostname # fenotify http service fireeyecloud server-urlhttps://ace.fireeyecloud.com:8443/public/xmlhttps://ace.us.fireeyegov.com:8443/public/xmlhostname # fenotify http service fireeyecloud ssl enableSave the configuration:
hostname # write memory
If integration is not configured successfully it will be reflected in the Network Security logs.