Skip to main content

FAQ

Short answers to the questions FireMon Support hears most, each with a link to the page that covers it properly.

General

Does Connect change my firewall rules? Connect changes only objects it created. Group exports create and maintain address objects (an Azure IP Group, a Palo Alto Dynamic Address Group, an NSX Group) and leave the rules that reference them alone. Change requests are evaluated and handed on: to ServiceNow as staging rows, or to Guardicore as segmentation rules in a ruleset of Connect's own, which Connect keeps in step with the request and never mixes into yours. See How Connect collects data.

What does Connect need from my network? Outbound HTTPS from your browser to FireMon's cloud. Your cloud and SaaS systems are reached from FireMon's cloud with the credentials you provision (AWS accounts also forward events to Connect from the stack you create). For systems inside your network, the Connector makes outbound connections only; see Network Requirements.

Does Connect work with FireMon Cloud Defense? Yes. Where an organization uses both, they share one sign-in and one inventory: Cloud Defense monitors cloud accounts for risk, and Connect uses the same inventory to keep firewall objects current and check firewall changes. See Concepts.

Groups, Boundaries, or Change say they aren't enabled. Those features haven't been switched on for your organization. Contact FireMon Support.

Accounts and discovery

Why is the password field blank every time I open the Provision page? Passwords, secrets, and tokens are stored encrypted and never shown back, so every save of the page needs the secret typed in again, even a save that only changes another field. See Common to every integration.

I saved an account and nothing appeared in Inventory. The first discovery is what tests the connection. Once it has run, check the account under Settings > Accounts for a warning icon and the Provision page for Resource Errors. See Watching for problems.

How current is Inventory? Every provisioned account is re-discovered daily. AWS accounts can also forward events so changes arrive within minutes. Connector discoveries run as jobs you can watch under Settings > Connectors > Jobs. See Concepts.

Which integrations need the Connector? Palo Alto Panorama and VMware NSX always; Infoblox when your Grid Manager is inside your network. Everything else connects directly. See Which integrations need the Connector.

Groups

Can I change a Group's Update type or Project? Both are set when the Group is created. To change either, create a new Group with the right values and delete the old one. See Creating a Group.

A Group's counts show 10,000+. Its criteria match more than the 10,000-item cap, so it holds only the first 10,000, and removals are skipped when it's recomputed. Narrow the criteria or split the Group. See Group size limits.

My new Manual Group has no members. Expected. A Manual Group starts empty with every match listed as a pending addition; approve them under Pending Changes. See Automatic and Manual.

My firewall gets an authentication error fetching a Group's dynamic list. The URL needs HTTP basic authentication: either the username and password under Settings > Group Credentials, or an API key as the password with the username shown on the Group page. If the Group Credentials were changed recently, every firewall using the old ones needs updating. See Dynamic lists.

I deleted a Group and its Dynamic Address Group or NSX Group is still there. Expected. Panorama and NSX objects stay in place so live policy keeps a valid reference; remove them by hand. Azure IP Groups are deleted. See Deleting a Group.

I renamed a Group and Azure now has two IP Groups. Expected. The IP Group follows the Group's name, so a rename creates a new one and leaves the old one for any rules still referencing it. See Azure.

Can I get an alert when a Group changes? Yes, as a Slack direct message. See Alerts.

Boundaries and change requests

A request matched no Boundaries and went to Review. That's the default when nothing matches. Change it under Settings > Boundaries if unmatched requests should pass or fail instead. See The default result.

A request passed, but nothing arrived in ServiceNow or Guardicore. Check that the Boundary it matched lists the account under Target(s), and that that Boundary's result is Pass or Score & Review, since those are the results that export. See Change Requests.

Can I check a request before submitting it? The walkthrough shows the evaluation result on its last step before you save, and the API's Evaluate Change Request does the same for scripts. Both evaluate without saving.

Why does a user see only the Change page? Their only role is Firewall Change Requestors, which is meant for requesters. Add another role if they need more. See Users and Roles.

Which roles can see change requests? Firewall Change Requestors, Firewall Change Approvers, Connect Boundary Author, Project Managers, and Administrators. See Roles.

Decommission

Saving an action fails saying decommission workflows aren't enabled. The feature hasn't been switched on for your organization. Contact FireMon Support.

An action finds no candidates. By default an action looks for items that have been deleted from their source, so an inventory with no deletions produces nothing. Check the Change Type criterion, and whether Last Hit or Last Seen is filtering everything out. See Finding candidates.

When are decommission candidates exported? Every candidate found when an action with a destination is saved is queued for export at once, and an Automatic action exports the candidates it finds later as it finds them. The History tab shows each attempt and whether it succeeded. See Export behavior.

Connector

The Connector shows red under Settings > Connectors. The Connector has stopped, or it can't reach FireMon Cloud. See Connector status.

A job has been In Progress for a long time. It's probably being retried after a temporary problem, such as an unreachable host. See Troubleshooting.

Signing in

"Sign in with your corporate ID" says corporate sign-in is unavailable. You opened Connect through an address it isn't configured for; use https://connect.firemon.cloud. If single sign-on hasn't been set up for your domain, the page shows a different error after you enter the domain. See Signing in.