Connect
FireMon Connect keeps firewall address objects current with the resources running in your cloud accounts and on-prem systems, checks proposed firewall changes against rules you define, and identifies assets that appear to have been decommissioned. It runs as a service at connect.firemon.cloud. The optional Connector is the one component you run inside your network.
What Connect does
Inventory
Connect discovers resources from AWS and Azure, and assets from Illumio, Guardicore, SentinelOne, ServiceNow, Infoblox, and FireMon Security Manager, into one Inventory. Each item carries its IP addresses, its hostname and MAC address where the source reports them, its tags, the account and region it came from, and the source's own attributes. Discovery is read-only and runs daily for every account; AWS accounts can also forward events so changes arrive within minutes. Groups, Boundaries, and Decommission all work on Inventory.
Groups
A Group is a set of IP addresses and CIDRs defined by criteria over Inventory, such as tags, resource type, account, region, environment, CIDR, and attribute values, rather than by a list of addresses. Connect maintains the membership as inventory changes, either automatically or, for a Manual Group, after a person approves each change. A Group can include other Groups.
A Group can be used three ways at once:
- Export. Connect creates an address object on an enforcement point and keeps it in sync: an Azure IP Group, a Palo Alto Dynamic Address Group through Panorama, or a VMware NSX Group. Export manages only that object; your security rules are not changed.
- Dynamic list. Every Group is published at an HTTPS URL in the formats Palo Alto, Check Point, and Fortinet firewalls fetch directly.
- Boundaries. A Boundary can name a Group as a source or destination.
Connect can send a Slack direct message when a Group's membership changes.
Boundaries and change requests
A Boundary describes a kind of firewall rule and says whether requests for it Pass, Fail, or need Score & Review, with a score from 0 to 100. Its statement covers the request type, sources, destinations, services, host and port limits, and fields the request must fill in, such as a justification, an owner, or an expiration. Boundaries can be viewed as a table or as a grid of sources and destinations, and imported and exported as JSON.
A change request describes one or more intended firewall rules. Saving one evaluates it against every enforced Boundary and sets its state, and each matching Pass or Score & Review Boundary can export the request to ServiceNow or Guardicore. Requests are submitted through a step-by-step walkthrough, which shows the result before saving, or an advanced form for several rules at once. A user whose only role is Firewall Change Requestors sees just the Change page.
Decommission
A Decommission action is a set of criteria that identifies assets that appear to have been retired: typically items deleted from their source, narrowed by account, type, tags, and how long since the asset was last seen or last matched a firewall rule. Each matching asset is a candidate, approved automatically or by a person depending on the action, and approved candidates are exported to ServiceNow. Every export attempt is recorded under History.
The Connector
The Connector is an optional agent that runs inside your network and makes outbound connections only. It pushes Groups to Panorama and NSX and discovers Infoblox networks into Inventory. It is installed as a binary, a Linux service, or a VMware appliance, pairs with a single-use registration code, and updates itself.
API
Connect has a GraphQL API, and a REST API for change requests, inventory search, and Group lookups. A change request can be evaluated without being saved, so a pipeline or ticketing system can check a change before raising it.
Administration
Accounts, Groups, Boundaries, change requests, and actions each belong to a project, and roles are granted per project. Users sign in with a FireMon Cloud password or through SAML single sign-on. Organizations that also use FireMon Cloud Defense sign in to both with the same user, and Cloud Defense posture findings appear on cloud resources in Inventory and can be used as Group criteria. See Administration.
In this section
- Getting Started: signing in, the first things to set up, and how to find your way around the app
- Concepts: inventory, Groups, Boundaries, change requests, Decommission, and how they fit together
- Integrations: every system Connect can discover from or export to, and which ones need the on-prem Connector
- Connector: install and pair the on-prem agent, and set up its integrations
- Using Connect: each screen in turn: Inventory, Groups, Boundaries, Change Requests, and Decommission
- API: authenticate and work with the Connect REST and GraphQL APIs
- Administration: users and roles, projects, and the organization-wide settings
- FAQ: short answers to common questions, with links to the detail
- Glossary: one line per term