Illumio PCE
Illumio PCE and VEN device pack installation is required. VEN devices (managed endpoints) will be managed by the PCE (endpoint manager).
Level 1 & 2 support
Security Manager can connect to the Illumio policyfor retrieval and normalization of the following: Security Rules - Workloads - Labels (application, environment, role, location) - VENs (virtual enforcement nodes) and their status.
Normalization
-
Illumio uses Labels but Security Manager converts these to Vendor Tags
-
Every higher order Normalized object, such as Policies, Rules, Networks, and others, are tagged with NdObjectTags
-
Security Manager uses NdVendorTags to display how objects are linked together
Compliance
The following are used for compliance governance:
-
Custom Controls
-
Custom Assessments
-
Compliance Report on Assessment
-
Violations on rules
Policy Optimizer
-
Manually route review ticket through workflow
-
Route rules with custom controls to workflow
To onboard an Illumio PCE management station, complete the following steps.
Step 1: Configure the Device
-
Log in to the Illumio dashboard.
-
In your user name profile, click My API Keys. For users that are an Owner of their PCE instance, go to Access > Service Accounts.
-
Copy the following information:
-
API Endpoint: You only need the IO section or hostname (https://us-scp00.illum.io/api/v0/)
-
Organization ID
-
Create a new Client ID and Client Secret.
It is important to copy the following information after creating.
For users that are an Owner of their PCE instance, go to Access > Service Accounts > Add to create an API Key.-
On the My API Keys page, click +Add.
-
Enter a Name and Description for the API Key
-
Click Create.
-
In the API Key Created dialog box, you will need to copy the Authentication Username and the Secret. Click Download Credentials.
Click Download Credentials to save these values or you will not be able to retrieve them later. -
Step 2: Onboard the Device in the Administration Module
Contact FireMon Support to receive a specific device pack (a .jar file) if it was not included in the FMOS GA release. Review the steps to upload a device pack.
- On the toolbar, click Device > Management Stations.
- Click Create, and then click Illumio > Illumio PCE.
- General Properties section.
- In the Name box, type the name of the device as you want to see it in SIP.
- In the Description box, type an optional description of the device being added.
- In the Management IP Address box, type the IP address of the device.
- In the Data Collector Group box, select the IP address of the data collector group that will collect data from this device.
- In the Central Syslog Server box, select the syslog server from the list (optional).
Syslog fields are optional if the device uses the same IP for syslog and management. A central syslog server is required only if syslog messages come from a different IP. A central syslog server must be created before it can be assigned to a device. To track usage via syslog, the device must support Level 3+.
- In the Syslog Match Names box, type the syslog match names (optional). You can enter multiple names separated by a comma.
- By default, the Automatically Retrieve Configuration checkbox is selected.
- In the External ID box, type a unique identifier to be used when the device identifier is different than what is displayed in SIP.
- For Collection Configuration, enable Update Rule Documentation on Member Devices to allow Rule Documentation fields on member devices to inherit a value from the management station. Any management stations Rule Documentation field updates will override updates on the member device. A rule marked to be removed will not be updated. Default is what is set on the installed device pack.
Credentials
- In the URI box, paste your copied API Endpoint hostname.
- In the Client ID box, paste the Authentication Username you copied from the API Key Created dialog box.
- In the Client Secret box, paste the Secret value you copied from the API Key Created dialog box.. Reenter the Client Secret.
- In the Organization ID box, paste your copied Organization ID value.
-
Retrieval section
Scheduled Retrieval
Select the Enable Scheduled Retrieval checkbox to perform a retrieval at a set time regardless of change detection. This will activate additional fields to complete.
-
Set the Scheduled Retrieval Time to fit your requirements.
-
Choose a Scheduled Retrieval Time Zone from the list.
Check for Change Retrieval
Select the Enable Check for Change checkbox to check for configuration changes after the specified interval and perform a retrieval if changes are detected. This will activate an additional field to complete.
-
The default Check for Change Interval time is 1440 minutes (every 24 hours). You can change the check interval time to best fit your requirements. The minimum required interval is 60 minutes (1 hour).
-
-
Advanced section: Select to determine which VENs (managed workloads) will be discovered and retrieved from. These will also be created as devices and be added to device policy, interface, and route information to the network map.
-
VENs Server
-
VENs Workstations
-
-
Click Save.