Corero SmartWall (Beta)
Quick DetailsRecommended Agent: Self-Managed (an Agent with network access to the CMS or Smart Service Portal)
Supported Agents: Liongard Hosted and Self-Managed. On-Demand is not supported.
Is Auto-Discovered By: N/A
Can Auto-Discover: Corero SmartWall Child Inspectors (one per tenant, Service Provider mode only)
Parent/Child Type Inspector: Conditional — Yes in Service Provider mode; No (single launchpoint) in Enterprise mode
Inspected via: API
Default Frequency: Daily. (max every 12 hours)
Data Summary: Corero SmartWall Inspector Summary
Overview
Corero SmartWall Inspector (Beta)
Corero Network Security's SmartWall ONE is an on-premise and hybrid DDoS protection platform — NTD/vNTD/TDS/TDD appliances managed by a Central Management Server (CMS), with MSSP/MSP Partners often running a Smart Service Portal (SSP) that aggregates multiple CMS deployments across managed Customers. The Corero SmartWall Inspector (Beta) is a read-only inspector that rolls up appliance inventory, software and Smart-Plugin versions, license and contract state, recent DDoS attacks and mitigations, and system-health issues into Liongard's inventory and change-detection trail — complementing, not duplicating, Corero's own SecureWatch dashboards.
What you can monitor
- Appliance inventory (NTD/vNTD/TDS/TDD) with model, serial, software/SXOS version, and connection state
- Installed Smart-Plugins and their version and status
- License type, capacity, validity, and expiry
- System-health issue level and open-issue count
- Recent DDoS attacks and mitigations, with per-tenant attribution
- (Service Provider mode) managed tenants, their service level, and protected assets
How it works
The Corero SmartWall Inspector supports two deployment shapes, chosen when you create the launchpoint. In Enterprise mode, a single launchpoint connects directly to one Central Management Server as one flat Environment. In Service Provider mode, a parent launchpoint connects to the Smart Service Portal and automatically discovers one child launchpoint per managed Customer tenant.
Benefits
- Catch a license nearing expiry, or a licensed-capacity ceiling, before it becomes an outage.
- See an appliance disconnect or a Smart-Plugin version change as soon as it happens.
- Get per-tenant DDoS attack and mitigation attribution for reporting and incident review, without leaving Liongard.
- (Service Provider Partners) every appliance, license, and attack is automatically attributed to the right Customer Environment.
Inspector Setup Preparation
Prerequisites & Access RequirementsTo configure the Corero SmartWall Inspector, ensure you have the following:
- A read-only Corero API token, generated on the CMS under AAA > Authentication > API Tokens, or on the Smart Service Portal under its API Tokens settings
- The Host (FQDN or IP) and HTTPS Port of the CMS or Smart Service Portal — typically 443 for a CMS, 10443 for a Smart Service Portal
- Knowledge of which Deployment Type you're configuring — Enterprise (single CMS) or Service Provider (Smart Service Portal)
Inspector Setup:
Step 1: Create the API Token in Corero
- On a CMS, sign in to the Corero console and navigate to AAA > Authentication > API Tokens. Create a token with a read-only role and copy its value.
- On a Smart Service Portal, open the API Tokens settings and create a token. Copy its value.
Step 2: Configure the Corero SmartWall Inspector in Liongard
In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the Corero SmartWall Inspector > Select Add System.
Fill in the following information:
- Deployment Type: Enterprise (single CMS) or Service Provider (Smart Service Portal)
- Environment: Select the Environment this deployment should be associated to — your MSP's Environment if you're setting up Service Provider mode
- Friendly Name: Suggested: "Corero SmartWall [Customer/MSP Name]"
- Agent: Select a Liongard Hosted or Self-Managed Agent with network access to the CMS or Smart Service Portal (On-Demand is not supported)
- Inspector Version: Latest
- Host: The CMS or Smart Service Portal FQDN or IP — no
https://and no path - HTTPS Port: 443 for a CMS; often 10443 for a Smart Service Portal
- API Token: The token generated in Step 1
- Verify TLS Certificate: Leave enabled unless the appliance presents a self-signed certificate
- CMS API Version: (Enterprise mode only) Leave at
v17unless your CMS runs a different release - Scheduling: The Inspector will default to run once a day at the time it's set up. Here you can adjust the schedule
Select Save. The Inspector will now be triggered to run within the minute.
Step 3: Child Inspector Setup (Service Provider mode only)
If you configured Deployment Type as Service Provider, the parent launchpoint automatically discovers one child launchpoint per Customer tenant on the Smart Service Portal after its first run, surfaced on the Discovered Systems tab on the Inspectors > Corero SmartWall Inspector page.
- Activate your Discovered Systems by ensuring they're mapped to the correct Environment > Select the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints.
- Archive Discovered Systems the same way, using Archive Launchpoints instead.
Enterprise mode does not produce any Discovered Systems — the single launchpoint is the complete Environment.
Flexible Asset/Configuration Auto-Updating
This inspector does not yet contribute to Flexible Assets/Configurations — no ConnectWise or IT Glue asset mappings ship with it today, so turning on those auto-updating toggles will not produce any data for this inspector.
Troubleshooting
- Authentication fails: Regenerate a read-only API token in the Corero console and re-enter it. Confirm the token's role can read the required resources.
- Empty or partial data: A too-narrow token role causes optional endpoints to be skipped — widen the role. A missing feature (no Service Portal licensed on a CMS, an uninstalled IP-Intelligence plugin) returns empty for that resource by design, not an error.
- Connection refused / TLS errors: Confirm the Host and Port (443 for a CMS, often 10443 for an SSP) are reachable from the Agent. Disable Verify TLS Certificate only for a self-signed internal certificate.
Known V1 LimitationsRead-only — no configuration enumeration or mutation; the 600+ policy, detection-profile, and Smart-Rule configuration endpoints are out of scope. No real-time syslog ingest (a SIEM job, not a polled inspector). No SecureWatch Analytics/Splunk dashboards — the inspector surfaces only the SecureWatch status. No
/statistics/*query-engine data (deferred to a later release).
Updated about 3 hours ago

