Skip to main content

Integrations

Prerequisites for the Illumio and Check Point Integration

To onboard Check Point, you must take the following actions to make sure that logs are properly formatted, aggregated, enriched, and securely transmitted.

Important

Note the following about the Log Exporter and the API Connector:

  • Onboarding the Check Point Connector using the Log Exporter and adding the API Connector are two separate procedures.

Prerequisites for the Log Exporter

  • All Check Point clients must enable the Check Point Log Exporter feature to allow logs to be forwarded from the gateway or log server. Set the log format for the Check Point Log Exporter to Common Event Format (CEF) and aggregate all logs to the Check Point Management Server. Configure each Security Gateway to forward its logs to the Check Point Management Server so that it can process them. Doing so makes sure that the Illumio application receives a unified and complete view of Check Point data and confirms that the Check Point Management Server acts as a central point for sending logs to the Illumio application.

    See Log Exporter and Configuring the Security Management Server and Security Gateways.

  • To onboard Check Point, you must have access to the Check Point Management Server CLI in Expert Mode.

  • You must enable mTLS between the Check Point Management Server and the Illumio syslog server to secure log transmission. The Illumio and Check Point integration uses mTLS secure connectivity. When you onboard, you will generate a client certificate that Illumio will sign and return to you.

  • To ensure that Illumio associates each log to the correct tenant, the onboarding process injects the Tenant ID value into the CEF logs using an automated script.

Prerequisites for the Infinity Portal API Connector

Review these prerequisites before you use the Infinity Portal API Connector.

Note

You do not need to enable log sharing as Illumio ingests logs directly from the management server.

Prerequisites for the Firewall Orchestrator API Connector

Illumio Prerequisites
  • The Illumio Firewall Connector instance name. You can have multiple instances, but each must have a unique name.

  • A PCE Service Account with administrator or higher privileges, the username and the client secret.

Check Point Prerequisites
  • The connector must be installed on a host with network connectivity to the Check Point Management Server as well as the PCE.

  • You must have permission to run sudo commands.

  • You must have permission to run the connector binary.

  • You must add the data center server object for Illumio.

  • You must have Check Point credentials for the Check Point Smart Console.