Cyber Command integration with Huawei Firewall

Mustajab Azhar Lv1Posted Apr-17-2026 02:58

Hi, i wanted to ask that whether we can integrate Huawei Firewall with Cyber Command? If yes what is the process and will it be able to respond as response policy for NGAF work when we integrate NGAF with Cyber Command.

Thanks.

By solving this question, you may help 225 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Damai_Group Lv1Posted Apr-17-2026 09:48
  
Yes, Huawei firewalls can be integrated with Sangfor Cyber Command for both monitoring and automated response. The process involves configuring the Huawei firewall to send logs (for visibility) and setting up an API connection (for control).

Here is the detailed answer to both of your questions.

1. Integrating Huawei Firewall with Sangfor Cyber Command

Yes, this integration is fully supported. The connection provides Cyber Command with visibility into the Huawei firewall's logs and, more importantly, allows it to use the firewall as an enforcement point for automated responses. The process is configured through Sangfor's XDDR (Extended Detection, Defense, and Response) framework and its built-in SOAR (Security Orchestration, Automation, and Response) module.

The Integration Process (Step-by-Step)

This is a two-part configuration on both the Huawei firewall and the Sangfor Cyber Command platform.

Part 1: Configuration on the Huawei Firewall
- Create an API Administrator: Log in to the Huawei firewall and navigate to System - Administrators - Administrators and create a new administrator. Crucially, under Trusted Hosts, you must add the complete IP address list of your Cyber Command/XDR platform. You will also need to set up an API administrator and assign the necessary permissions.
- Enable the RESTCONF Interface: Go to System - Administrators - Settings and enable the RESTCONF interface. Make a note of the service port number (the default is TCP 8447), as this will be needed for the Cyber Command configuration. This is the port used for SOAR actions like pushing a blocking policy.
- Configure Security Policy: To allow the Cyber Command platform to connect, you must create a security policy on the Huawei firewall that permits traffic from the Cyber Command/XDR's IP address(es) to the firewall's management IP on the designated RESTCONF port (e.g., TCP 8447).
- Configure Syslog (Optional): For log visibility, configure the firewall to send syslog data to the Cyber Command platform. This is typically done under System - Log Configuration - New Log Host, where you will specify the Cyber Command/XDR platform's IP address and port (commonly UDP 514).

Part 2: Configuration on Sangfor Cyber Command
- Access the Console: Log in to the Cyber Command/XDR back-end console.
- Add the New Device: Navigate to Product Access - Third-party Access - Huawei New Device.
- Enter Connection Parameters: Enter the Huawei firewall's management IP address, the RESTCONF port you noted earlier, and the credentials for the API administrator account you created. Then, run a connection test.

Once the test is successful, the integration is complete. The Huawei firewall will appear in Cyber Command's SOAR module, and you can begin using it for automated responses.

2. Response Policies for Sangfor NGAF

When NGAF is integrated with Cyber Command, response policies (often called auto-response or SOAR playbooks) work seamlessly, and this is a core feature of the XDDR framework.

The process is automated and bidirectional:
- Detection & Correlation: Cyber Command continuously monitors and analyzes network traffic, correlating events from NGAF and other sources like Endpoint Secure to identify malicious activity.
- Automated Response Execution: When a threat is confirmed, Cyber Command can automatically instruct the NGAF to take action. These actions are defined in response policies and can include:
  - Blocking an Endpoint: Isolating an infected device from the network.
  - Applying Application Control: Creating a policy to block specific applications or traffic from the suspicious host.
  - Blocking a Domain/URL: Adding malicious domains or URLs to a blocklist.
- Incident Closure: Once the NGAF confirms the policy has been applied, Cyber Command will automatically change the incident's status to Fixed.

Summary and Key Considerations

- Capabilities: Integrating a Huawei firewall with Cyber Command provides Visibility (via logs) and Control (via automated blocking). Integrating NGAF provides Native Response capabilities out of the box.
- Huawei Firewall Model Support: While the configuration is standard for many USG series firewalls, it is best to check the official Sangfor documentation for specific model and firmware compatibility.
- Support Channels: For any troubleshooting or advanced configurations, the best resources are the official Sangfor Community and Huawei Support. Issues like a connection test failing may require checking network connectivity or logs on both sides.

I Can Help:

Change

Moderator on This Board

962
199
98

Started Topics

Followers

Follow

Trending Topics

Board Leaders