Skip to main content

Illumio Segmentation for the Cloud User Guide

Cloud Map Overview

The Cloud Map is an interactive connectivity map that visualizes and analyzes your cloud resources and their traffic flows across hybrid, multi-cloud environments.

Because Illumio Segmentation for the Cloud understands the relationships between cloud resources, Cloud Map displays resources using cloud-native constructs such as region, cluster, account, and more.

Tip

View cloud-native resources only. Use Global Map to view cloud and non-cloud resources. Learn more.

Cloud Map displays your cloud resources on an interactive canvas.

  • Select between different views (Cloud or Kubernetes).

  • Drag and pan the canvas.

  • Zoom in, zoom out, or zoom to fit all resources within your page.

  • Double-click on a resource to view its contained resources.

  • Filter visible resources by searching for specific resource attributes.

  • Filter visible traffic flows by configuring the time frame of traffic to capture.

See the Cloud view and Kubernetes view.

Benefits of the Cloud Map

  • View inventory from all onboarded cloud accounts. View resources from all onboarded cloud accounts as a network topology map.

  • Visualize with cloud-native resources. Use the Cloud Map to view resources as cloud-native constructs, such as cloud providers, regions, and accounts. Choose between cloud and Kubernetes views.

  • Browse cloud topology hierarchically. Choose between different views of your cloud topology. Drill into the resource hierarchy, from cloud to regions to accounts and more.

  • Filter viewable resources and traffic flows. Display only resources and traffic flows that match specified attributes.

Filtering displayed resources and traffic

You can configure Cloud Map to display only resources and traffic flows that match specified attributes.

To specify resource attributes and filter Cloud Map:

  1. Click the magnifying glass icon to open the filter modal.

  2. Select attributes to filter with.

  3. For traffic flows, select both the attributes to filter with and the historical time frame of traffic to capture.

  4. Click Apply.

Cloud Map loads and displays the resources and traffic flows allowed by your filters.

Examining resources

You can interact with each resource displayed in Cloud Map by single-clicking, double-clicking, or hovering over it.

A resource may contain a group of nested resources. You can double-click or right-click on a resource to expand its group and display its contained resources (down one nesting level). You can also hover-over or right-click on a group to collapse the display (up one nesting level).

Examining traffic flows

Cloud Map displays traffic flows as solid lines linking resources. You can interact with traffic links by single-clicking or hovering over a link .

Traffic links are directed to represent flow direction and color-coded to represent flow statuses.

Traffic Link Color

Traffic Flow Status

Green

Allowed

Orange

Mixed (both Allowed and Denied)

Red

Denied

Comparing the Cloud Map and the Global Map

Illumio Platform provides the Global Map for visualizing resources.

Feature

Cloud Map

Global Map

Availability

Illumio Segmentation for the Cloud

Illumio Platform

Supported Views

Cloud Infrastructure view

Label view

Kubernetes view

Label view

Displayed resources

Cloud-native constructs

Labeled

Limitations of the Cloud Map

The Cloud Map has maximum limits on the number of loadable objects.

  • Resources: 1,000 objects

  • Traffic: 10,000 flows

These limits are not configurable. The Cloud Map sets these limits to maintain UI performance.

When exceeding these limits, the Cloud Map displays a note recommending that you refine the filters to decrease the number of objects.

Note

When the Cloud Map loads more than 100 objects, by default it collapses the view rather than displaying all objects.

Startup latency for traffic flow