Setting up ATR for Cisco Duo
What ATR does
ATR determines whether an alert is malicious.
If the alert is identified as malicious, the IP Address is automatically added to the firewall or network security solution block list, depending on how malicious ATR determines it to be.
For more information about Automated Threat Response (ATR), see https://documentation.campus.barracuda.com/wiki/pages/createpage.action?spaceKey=skout&title=Setting%20up%20ATR&linkCreation=true&fromPageId=674988131.
Setting up ATR
When ATR detects a Cisco Duo account has been compromised, Barracuda XDR automatically responds by suspending the affected account through the API. This suspension restricts access and triggers session invalidation, helping to contain threats in real time.
Requirements
You must have:
Access to the Barracuda XDR Dashboard set up and working properly
Access to Cisco Duo Admin Panel with an account that has the Owner role
Setting up ATR for Cisco Duo
To set up ATR for Cisco Duo, do the following procedures:
To create an Admin API application in Duo
To enable ATR in XDR Dashboard
To create an Admin API application in Duo
Sign in to the Duo Admin Panel with an account that has the Owner role.
Go to Applications > Application Catalog.
Find Admin API and click + Add.
Enter a descriptive name for the application, such as Barracuda XDR ATR.
In the Permissions section, enable the permissions required for Barracuda XDR to perform ATR.
Enable the following permissions:
Grant administrators - Write
Grant read information
Grant read log
Grant resource - Read
Grant resource - Write
(Optional) In the Ownership and Risk section:
Ownership: Assign the Administrator or Team responsible for the integration, if desired.
Risk: Select a value based on your organization's internal risk classification policy, if desired.
These settings are recommended for governance and audit tracking, but aren't required for the ATR setup.
In Networks for API Access, add the Barracuda XDR ATR IPs:
52.20.168.2518.211.110.23854.209.207.251
Click Save Changes.
Copy the following values from the Admin API Application > Details:
Integration Key
Secret Key
API Hostname
To enable ATR in XDR Dashboard
In Barracuda XDR Dashboard, select Integrations
> Duo.
Paste the following:
API Hostname
Secret Key
Integration Key
Select the Auto Remediation Enabled checkbox.
Click Test to verify the integration is working properly.
Click Save.