Skip to main content

Integrations

Onboard the Firewall Orchestrator

Note

Use this option if you want to install a connector in your Data Center to allow the Illumio Core to sync policies to Check Point.

  1. Log in to the Illumio Console, navigate to Settings > Connectors, and click the Check Point tile.

  2. On the Check Point Connector page, select API Connector.

  3. Within the API Connector pane, select Illumio Firewall Orchestrator (On-Prem).

  4. Enter a unique name for your connector instance in the Name the Connector Instance field.

  5. Under Enter PCE Service Account Credentials, create the API connection to the Illumio PCE:

    1. Service Account User

    2. Service Account Secret

  6. Under Enter Check Point Smart Console Credentials, enter the following:

    1. Check Point Management Server URL

    2. Username

    3. Password

    4. Illumio Data Center Server Name

  7. Under Download Firewall Orchestrator, click Download.

  8. Identify a host on which you will run the Orchestrator.

    This server must be able to connect with the Check Point Management Server.

  9. Transfer the .tar file to the server that you will run the Orchestrator on.

  10. Run the following command to deploy the Orchestrator:

    tar -xvf <archive-name>.tar.gz

  11. Execute the Orchestrator binary included in the .tar file.

    Illumio recommends that you run the binary on a non-terminating session (such as by using tmux).

  12. Navigate to the Check Point tile on the Connectors page to view the status.

    Confirm that the orchestrator shows a Health status of Connected.

  13. Next, go to the Firewalls page to see the Illumio policies and the associated firewalls that have been applied to it.

View the Label-Based Policies Applied to the Firewalls

After you have onboarded the API connector, you can view the Illumio label-based policies that are applied to the firewalls. You can see the policies on the Check Point Management Server and the Illumio added rules.

  1. Go to the Firewalls page.

  2. View the list of firewalls.

  3. Click the Subnets Enforced column to open the slide-out and specify the subnets that the firewall is able to enforce on.

  4. Click the Firewall Rules tab to view the Illumio label-based policies that are applied to the firewalls.

View the Policy Impact

View the policy impact where it takes into account the subnets that a firewall enforces.

  1. Go to Policies > Show Impact to see the firewall that is impacted.

  2. View the number of protected resources that fall within this firewall's IP range in the Impact of Policy page.

Policy Sync

After you've evaluated and provisioned your policy, Illumio will sync the policy to your Check Point firewalls.