Prerequisites for the Illumio and Check Point Integration
To onboard Check Point, you must take the following actions to make sure that logs are properly formatted, aggregated, enriched, and securely transmitted.
Important
Note the following about the Log Exporter and the API Connector:
Onboarding the Check Point Connector using the Log Exporter and adding the API Connector are two separate procedures.
You must use the Log Exporter to onboard the integration, but adding the API Connector is optional. However, adding the API Connector allows you to ingest additional firewall data that enhances the traffic logs.
Prerequisites for the Log Exporter
All Check Point clients must enable the Check Point Log Exporter feature to allow logs to be forwarded from the gateway or log server. Set the log format for the Check Point Log Exporter to Common Event Format (CEF) and aggregate all logs to the Check Point Management Server. Configure each Security Gateway to forward its logs to the Check Point Management Server so that it can process them. Doing so makes sure that the Illumio application receives a unified and complete view of Check Point data and confirms that the Check Point Management Server acts as a central point for sending logs to the Illumio application. See Log Exporter and Configuring the Security Management Server and Security Gateways.
To onboard Check Point, you must have access to the Check Point Management Server CLI in Expert Mode.
You must enable mTLS between the Check Point Management Server and the Illumio syslog server to secure log transmission. The Illumio and Check Point integration uses mTLS secure connectivity. When you onboard, you will generate a client certificate that Illumio will sign and return to you.
To ensure that Illumio associates each log to the correct tenant, the onboarding process injects the Tenant ID value into the CEF logs using an automated script.
Follow these prerequisites to ensure that the connectivity between Illumio Insights and Check Point is secure and efficient.
Prerequisites for the API Connector
Review these prerequisites before you use the API Connector.
Activate Remote API Access. See Enable Remote API Access in Check Point.
Create a Security Management API Key. See Create an API Key for Quantum Security Management.
Note
As long as your API key is valid and has not expired, you can use it to run APIs on your Management Server.
Create an administrator type user with read only, read and write, or super user permissions to allow Illumio to make API calls. See Create an Administrator User to Make API Calls.
Integrate the Check Point SmartConsole with the Check Point Infinity Portal.
Note
You do not need to enable log sharing as Illumio ingests logs directly from the management server.