Illumio PCE

Illumio PCE and VEN device pack installation is required. VEN devices (managed endpoints) will be managed by the PCE (endpoint manager).

Level 1 & 2 support

Security Manager can connect to the Illumio policyfor retrieval and normalization of the following: Security Rules - Workloads - Labels (application, environment, role, location) - VENs (virtual enforcement nodes) and their status.

Normalization

  • Illumio uses Labels but Security Manager converts these to Vendor Tags

  • Every higher order Normalized object, such as Policies, Rules, Networks, and others, are tagged with NdObjectTags

  • Security Manager uses NdVendorTags to display how objects are linked together

Compliance

The following are used for compliance governance:

  • Custom Controls

  • Custom Assessments

  • Compliance Report on Assessment

  • Violations on rules

Policy Optimizer

The ability to submit a rule for review is currently unavailable. This issue has been identified and will be addressed in the April release.
  • Manually route review ticket through workflow

  • Route rules with custom controls to workflow

To onboard an Illumio PCE management station, complete the following steps.

Step 1: Configure the Device

FireMon strives to provide up-to-date product information, however we are not always aware when vendors change their device UI. If any Configure the Device procedure differs from your device version (UI location of fields, not information needed), please consult your device's user guide.
  1. Log in to the Illumio dashboard.

  1. In your user name profile, click My API Keys. For users that are an Owner of their PCE instance, go to Access > Service Accounts.

  1. Copy the following information:

  • API Endpoint: You only need the IO section or hostname (https://us-scp00.illum.io/api/v0/)

  • Organization ID

  1. Create a new Client ID and Client Secret.

    It is important to copy the following information after creating.

    For users that are an Owner of their PCE instance, go to Access > Service Accounts > Add to create an API Key.
    1. On the My API Keys page, click +Add.

    2. Enter a Name and Description for the API Key

    3. Click Create.

    4. In the API Key Created dialog box, you will need to copy the Authentication Username and the Secret. Click Download Credentials.

    Click Download Credentials to save these values or you will not be able to retrieve them later.

Step 2: Onboard the Device in the Administration Module

Contact FireMon Support to receive a specific device pack (a .jar file) if it was not included in the FMOS GA release. Review the steps to upload a device pack.

After onboarding, if you change any device settings, confirm that those updates were automatically applied to the discovered devices.
  1. On the toolbar, click Device > Management Stations.
  2. Click Create, and then click Illumio > Illumio PCE.
  1. General Properties section.
To prevent errors in device group-level device maps and incorrect reporting data, all devices added in Administration must have unique IP addresses. If devices with duplicate IP addresses must be added within a domain, it is strongly recommended that those devices be separated into discrete device groups, where no duplicate IP addresses are included in the same device group. Devices with duplicate IP addresses will cause errors in the All Devices device map, and may cause incorrect data in reports, even if they are in discrete device groups.
  1. In the Name box, type the name of the device as you want to see it in SIP.
  2. In the Description box, type an optional description of the device being added.
  3. In the Management IP Address box, type the IP address of the device.
  4. In the Data Collector Group box, select the IP address of the data collector group that will collect data from this device.
  5. In the Central Syslog Server box, select the syslog server from the list (optional).
Syslog fields are optional if the device uses the same IP for syslog and management. A central syslog server is required only if syslog messages come from a different IP. A central syslog server must be created before it can be assigned to a device. To track usage via syslog, the device must support Level 3+.
  1. In the Syslog Match Names box, type the syslog match names (optional). You can enter multiple names separated by a comma.
  2. By default, the Automatically Retrieve Configuration checkbox is selected.
  3. In the External ID box, type a unique identifier to be used when the device identifier is different than what is displayed in SIP.
  1. For Collection Configuration, enable Update Rule Documentation on Member Devices to allow Rule Documentation fields on member devices to inherit a value from the management station. Any management stations Rule Documentation field updates will override updates on the member device. A rule marked to be removed will not be updated. Default is what is set on the installed device pack.
  1. Device Settings section.

Credentials

  1. In the URI box, paste your copied API Endpoint hostname.
  2. In the Client ID box, paste the Authentication Username you copied from the API Key Created dialog box.
  3. In the Client Secret box, paste the Secret value you copied from the API Key Created dialog box.. Reenter the Client Secret.
  1. In the Organization ID box, paste your copied Organization ID value.
  1. Retrieval section

    Scheduled Retrieval

    Select the Enable Scheduled Retrieval checkbox to perform a retrieval at a set time regardless of change detection. This will activate additional fields to complete.

    • Set the Scheduled Retrieval Time to fit your requirements.

    • Choose a Scheduled Retrieval Time Zone from the list.

    Check for Change Retrieval

    Select the Enable Check for Change checkbox to check for configuration changes after the specified interval and perform a retrieval if changes are detected. This will activate an additional field to complete.

    • The default Check for Change Interval time is 1440 minutes (every 24 hours). You can change the check interval time to best fit your requirements. The minimum required interval is 60 minutes (1 hour).

  1. Advanced section: Select to determine which VENs (managed workloads) will be discovered and retrieved from. These will also be created as devices and be added to device policy, interface, and route information to the network map.

    • VENs Server

    • VENs Workstations

  1. Click Save.

Devices being managed will be listed in the Discovered Devices section. Click Device Details to open Security Manager to view more details about these managed devices.