Skip to main content

Integrations

Once a Connector is paired and online (see Installation or Deploying the OVA appliance), point one or more on-prem integrations at it from Settings > Accounts in Connect. A single Connector can serve multiple accounts/integrations at once.

What a Connect Group is

A Group is a named list of IP addresses and CIDRs, defined by filters over your FireMon inventory rather than maintained by hand. You create one under Groups in Connect's main navigation. Three fields on a Group matter for the integrations below:

  • UpdateAutomatic keeps membership current as matching resources appear and disappear; Manual only changes membership when someone refreshes the Group. Use Automatic for Group export, so your enforcement point tracks reality without anyone touching it. (This is fixed when the Group is created and can't be changed later.)
  • Export To — which accounts the Group is pushed to. Selecting an on-prem account here is what turns a Group into a Group export job for the Connector. One Group can export to several targets at once, including a mix of Panorama and NSX.
  • Group Candidates — the panel where you build the membership filters (tags, resource type, vendor, CIDR, account, region, and so on) and preview exactly which inventory items currently match, before you save.

Groups are built from what's in Inventory — including on-prem assets that an inventory discovery integration brought in.

Integration types

Each on-prem integration falls into one of two kinds of work:

  • Group export — the Connector keeps a Connect Group's IP addresses/CIDRs in sync with an address object on your on-prem enforcement point (a Dynamic Address Group in Panorama, a Group in NSX), so you can write policy against a FireMon-managed object instead of maintaining lists by hand.
  • Inventory discovery — the Connector pulls assets from an on-prem platform into FireMon's Inventory, so on-prem resources show up alongside your cloud inventory.
IntegrationTypeWhat it does
Palo Alto PanoramaGroup exportPushes a Connect Group to your firewalls as a Dynamic Address Group (DAG), kept in sync automatically.
VMware NSXGroup exportPushes a Connect Group to an NSX Group, kept in sync automatically.
InfobloxInventory discoveryWalks your Grid Manager networks and used IPs and brings them into FireMon's inventory.

Common to every integration

  • Setup lives in one place. Every integration is configured from Settings > Accounts > (add new) in Connect, choosing the matching Cloud Provider and a Provision page. On-prem integrations require you to select the paired Connector that should route the work.
  • Self-signed certificates. Every integration's Provision page has an Allow Self-Signed Certificate toggle for on-prem systems using internally-issued or self-signed TLS certificates. This only affects the Connector's connection to that specific on-prem system — every connection from the Connector back to FireMon Connect always requires full certificate validation and cannot be relaxed.
  • Group export deletes are non-destructive. For both Group export integrations (Panorama, NSX), deleting a Connect Group leaves the corresponding object on the enforcement point in place rather than removing it — this avoids the Connector silently pulling an address object out from under a live policy. Remove it manually on the provider side if it's no longer wanted.

For issues with a specific integration, see its page above, or the general Troubleshooting page.