Skip to main content

Security Policy Guide 25.2.10

Illumio Policy Enforcement Model

Illumio employs an allowlist security model. By default, workload-to-workload communication is blocked unless explicitly permitted by defined Illumio policy rules. Administrators create these explicit rules to allow only necessary traffic, significantly enhancing security.

Why Use Selective Enforcement?

Deploying the allowlist model universally and simultaneously can be challenging or disruptive. Illumio addresses this by providing selective enforcement, an intermediate enforcement state that allows a gradual security rollout.

Selective Enforcement provides:

  • Gradual Security Implementation: Smooth transition from open ("Idle" or "Visibility-only") states to full enforcement ("Full Enforcement").

  • Targeted Visibility: Enforcement focused on selected services and ports via labels or groups, while other services remain in visibility mode.

  • Rapid Threat Response: Immediate enforcement on vulnerable or critical ports and services without impacting entire workloads.

How Selective Enforcement Works

Selective enforcement is applied individually per workload through labels or label groups.

Enforcement Progression Model

Selective Enforcement is a crucial step in Illumio's structured enforcement progression:

Idle (Visibility-only) → Selective Enforcement → Full Enforcement

where

  • Idle: Visibility and monitoring are in place, but there is no enforcement.

  • Selective Enforcement: Partial enforcement on chosen ports/services.

  • Full Enforcement: Complete allowlist enforcement on all ports and services.

This structured approach simplifies the implementation of secure policies, offering flexibility in managing risk and operational complexity.

Use Cases and Limitations

Basic use cases for Selective enforcement are:

  • Incremental Policy Rollout: Enables the gradual introduction of policies, reducing risks to critical systems.

  • Rapid Security Response: Quickly enforce specific, critical, or vulnerable port and service policies.

Selective Enforcement Mode Limitations

Limitations of Selective Enforcement are grouped as follows:

  • Selective enforcement is available only for workloads managed directly by Illumio. Unmanaged workloads or workloads managed via Network Enforcement Nodes (NEN) cannot utilize selective enforcement.

  • Impact on Virtual Services: Selective enforcement does not apply directly to virtual services as a single entity.

    Instead, policies must target individual workloads within virtual services. Enforcement is applied at the workload level within virtual services.

    Virtual services themselves are not directly enforced.

Workload Enforcement States

Workload policy modes determine how Illumio rules impact workload network communications. Illumio provides four policy modes.

The enforcement state displayed in the Policy Compute Engine (PCE) indicates the desired state for the next policy update. Failure to apply this state successfully will result in a Policy Sync error.

Idle Enforcement State

This state is typically used during initial VEN installation or activation. Its characteristics are:

  • No firewall rule enforcement.

  • Collects and reports network traffic data every 10 minutes.

  • Report OS compatibility every four hours.

  • Immediately reports network interface configuration changes.

Note

SecureConnect rules are only applied to workloads where the VEN is in a non-idle enforcement state.

However, unlike other rules, SecureConnect requires matching rules to be applied to workloads on both sides of any connection. Therefore, SecureConnect traffic is not supported between two workloads where a VEN on either side is in idle state.