Prerequisites for the Illumio and Check Point Integration
To onboard Check Point, you must take the following actions to make sure that logs are properly formatted, aggregated, enriched, and securely transmitted.
Important
Note the following about the Log Exporter and the API Connector:
Onboarding the Check Point Connector using the Log Exporter and adding the API Connector are two separate procedures.
Prerequisites for the Log Exporter
All Check Point clients must enable the Check Point Log Exporter feature to allow logs to be forwarded from the gateway or log server. Set the log format for the Check Point Log Exporter to Common Event Format (CEF) and aggregate all logs to the Check Point Management Server. Configure each Security Gateway to forward its logs to the Check Point Management Server so that it can process them. Doing so makes sure that the Illumio application receives a unified and complete view of Check Point data and confirms that the Check Point Management Server acts as a central point for sending logs to the Illumio application.
See Log Exporter and Configuring the Security Management Server and Security Gateways.
To onboard Check Point, you must have access to the Check Point Management Server CLI in Expert Mode.
You must enable mTLS between the Check Point Management Server and the Illumio syslog server to secure log transmission. The Illumio and Check Point integration uses mTLS secure connectivity. When you onboard, you will generate a client certificate that Illumio will sign and return to you.
To ensure that Illumio associates each log to the correct tenant, the onboarding process injects the Tenant ID value into the CEF logs using an automated script.
Prerequisites for the Infinity Portal API Connector
Review these prerequisites before you use the Infinity Portal API Connector.
Activate Remote API Access. See Enable Remote API Access in Check Point.
Create a Security Management API Key. See Create an API Key for Quantum Security Management.
Note
As long as your API key is valid and has not expired, you can use it to run APIs on your Management Server.
Create an administrator type user with read only, read and write, or super user permissions to allow Illumio to make API calls. See Create an Administrator User to Make API Calls.
Integrate the Check Point SmartConsole with the Check Point Infinity Portal.
Note
You do not need to enable log sharing as Illumio ingests logs directly from the management server.
Prerequisites for the Firewall Orchestrator API Connector
Illumio Prerequisites
The Illumio Firewall Connector instance name. You can have multiple instances, but each must have a unique name.
A PCE Service Account with administrator or higher privileges, the username and the client secret.
Check Point Prerequisites
The connector must be installed on a host with network connectivity to the Check Point Management Server as well as the PCE.
You must have permission to run
sudocommands.You must have permission to run the connector binary.
You must add the data center server object for Illumio.
You must have Check Point credentials for the Check Point Smart Console.