Setting up ATR for Cisco Duo

Setting up ATR for Cisco Duo

What ATR does

ATR determines whether an alert is malicious.

If the alert is identified as malicious, the IP Address is automatically added to the firewall or network security solution block list, depending on how malicious ATR determines it to be.

For more information about Automated Threat Response (ATR), see https://documentation.campus.barracuda.com/wiki/pages/createpage.action?spaceKey=skout&title=Setting%20up%20ATR&linkCreation=true&fromPageId=674988131.

Setting up ATR

When ATR detects a Cisco Duo account has been compromised, Barracuda XDR automatically responds by suspending the affected account through the API. This suspension restricts access and triggers session invalidation, helping to contain threats in real time.

Requirements

You must have:

  • Access to the Barracuda XDR Dashboard set up and working properly

  • Access to Cisco Duo Admin Panel with an account that has the Owner role

Setting up ATR for Cisco Duo

To set up ATR for Cisco Duo, do the following procedures:

  • To create an Admin API application in Duo

  • To enable ATR in XDR Dashboard

To create an Admin API application in Duo
  1. Sign in to the Duo Admin Panel with an account that has the Owner role.

  2. Go to Applications > Application Catalog.

    A screenshot of the Application Catalog screen
  3. Find Admin API and click + Add.

    A screenshot of the API Add screen
  4. Enter a descriptive name for the application, such as Barracuda XDR ATR.

    A screenshot of the Descriptive Name screen
  5. In the Permissions section, enable the permissions required for Barracuda XDR to perform ATR.

  6. Enable the following permissions:

    • Grant administrators - Write

    • Grant read information

    • Grant read log

    • Grant resource - Read

    • Grant resource - Write

      Required resources.png
  7. (Optional) In the Ownership and Risk section:

    • Ownership: Assign the Administrator or Team responsible for the integration, if desired.

    • Risk: Select a value based on your organization's internal risk classification policy, if desired.

    • These settings are recommended for governance and audit tracking, but aren't required for the ATR setup.

  8. In Networks for API Access, add the Barracuda XDR ATR IPs:

    • 52.20.168.25

    • 18.211.110.238

    • 54.209.207.251

      A screenshot of the Networks for API Access screen
  9. Click Save Changes.

  10. Copy the following values from the Admin API Application > Details:

    • Integration Key

    • Secret Key

    • API Hostname

To enable ATR in XDR Dashboard
  1. In Barracuda XDR Dashboard, select Integrations Integrations.png > Duo.

  2. Paste the following:

    • API Hostname

    • Secret Key

    • Integration Key

  3. Select the Auto Remediation Enabled checkbox.

    Screenshot of the Enable Dashboard screen
  4. Click Test to verify the integration is working properly.

  5. Click Save.

 


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.