Skip to main content

Integrations

Prerequisites for the Illumio and Check Point Integration

To onboard Check Point, you must take the following actions to make sure that logs are properly formatted, aggregated, enriched, and securely transmitted.

Important

Note the following about the Log Exporter and the API Connector:

  • Onboarding the Check Point Connector using the Log Exporter and adding the API Connector are two separate procedures.

  • You must use the Log Exporter to onboard the integration, but adding the API Connector is optional. However, adding the API Connector allows you to ingest additional firewall data that enhances the traffic logs.

Prerequisites for the Log Exporter

  • All Check Point clients must enable the Check Point Log Exporter feature to allow logs to be forwarded from the gateway or log server. Set the log format for the Check Point Log Exporter to Common Event Format (CEF) and aggregate all logs to the Check Point Management Server. Configure each Security Gateway to forward its logs to the Check Point Management Server so that it can process them. Doing so makes sure that the Illumio application receives a unified and complete view of Check Point data and confirms that the Check Point Management Server acts as a central point for sending logs to the Illumio application. See Log Exporter and Configuring the Security Management Server and Security Gateways.

  • To onboard Check Point, you must have access to the Check Point Management Server CLI in Expert Mode.

  • You must enable mTLS between the Check Point Management Server and the Illumio syslog server to secure log transmission. The Illumio and Check Point integration uses mTLS secure connectivity. When you onboard, you will generate a client certificate that Illumio will sign and return to you.

  • To ensure that Illumio associates each log to the correct tenant, the onboarding process injects the Tenant ID value into the CEF logs using an automated script.

Follow these prerequisites to ensure that the connectivity between Illumio Insights and Check Point is secure and efficient.

Prerequisites for the API Connector

Review these prerequisites before you use the API Connector.

Note

You do not need to enable log sharing as Illumio ingests logs directly from the management server.