Getting Started
Connect runs at connect.firemon.cloud, in FireMon's cloud: you sign in, add the systems Connect should read from or write to, and build Groups and Boundaries on what it finds. The one component you run yourself is the on-prem Connector (optional), used for Palo Alto Panorama, VMware NSX, and an Infoblox grid inside your network.
This page covers what you need, how to sign in, and the order to do things in. Finding Your Way Around covers the screens.
Before you start
- A Connect user. An administrator invites you from Settings > Users, and you receive an invitation email to set your password. The roles you're given decide what you can see and change; see Users and Roles.
- Something to connect. At least one account: an AWS account, an Azure subscription, or one of the on-prem and IT systems listed under Integrations. Each page there says what credentials the account needs.
- Outbound HTTPS from your browser to
connect.firemon.cloud. Connect reaches cloud and internet-facing systems from FireMon's cloud with the credentials you provide. Systems inside your network are reached only through the Connector, which connects outward.
Signing in
Sign in with your username and password. If your organization also uses FireMon Cloud Defense, the same username and password work in both.
Corporate sign-in. If your organization has set up single sign-on, click Sign in with your corporate ID below the sign-in form and enter your corporate email domain. You're sent to your identity provider to sign in. The link appears for everyone; it works once single sign-on has been set up for your domain. Setting this up is a one-time task for an administrator and FireMon Support; see SAML Setup, which applies to Connect as well.
Password reset. The sign-in page has a reset link. It applies only to users with a FireMon password; corporate sign-in users reset their password with their own identity provider.
Where you land depends on your roles. Most people see the home page. Someone whose only role is Firewall Change Requestors lands on Change, the only page in their menu, so requesters have one place to go.
First steps
The home page shows a Getting Started checklist; its current step moves on once you have an account, and again once you have a Group. Adding accounts and creating Groups needs the Administrators role. The recommended order is:
- Add an account. Go to Settings > Accounts and click New Integration Account. Choose the Cloud Provider, enter the account's ID and a name, pick the project it belongs to (and an Environment label if you want one), and click Continue to Provisioning. You land on the Provision page, where the credentials go. Integrations has a page for every provider. Palo Alto Panorama and VMware NSX (and Infoblox when the Grid Manager is inside your network) need a paired Connector before the account can do anything.
- Confirm discovery worked. The first discovery starts on its own once the account is provisioned. When it finishes, the Integrations page shows a green check in the row's Active column with an item count, and Inventory > Resources lists the items. A red warning icon on the account under Settings > Accounts means discovery encountered a problem; see Watching for problems.
- Set attribute shortcuts (optional). Open the account from Settings > Accounts, pick a typical item, and mark the attributes your team makes policy decisions on. They're offered as one-click criteria when you build Groups and Decommission actions. See Attribute shortcuts.
- Create a Group. Go to Groups > New Group. Set Update and Project first, because both are permanent, then add criteria under Group Candidates until the preview shows the members you expect, and save. Groups explains each field.
- Use the Group. Reference it in a Boundary, export it to Azure, Panorama, or NSX under Export To, or point a firewall at its dynamic list URL. One Group can be used all three ways at once.
- Write Boundaries and submit a change request. With a Boundary in place, submit a change request under Change and watch it evaluate. Change Requests walks through it.
Groups, Boundaries, and Change are enabled per organization. If one of them shows a message saying it isn't enabled, contact FireMon Support.
In this section
- Finding Your Way Around: the navigation menu, what's on each page, the Settings pages, and the controls that work the same everywhere