Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Watch this video for an overview of the value of FireMon Security Manager (SM) plus FireMon Lumeta: Include PageThe Value of Lumeta + Security Manager IntegrationThe Value of Lumeta + Security Manager IntegrationAsset Manager:

To validate that devices on your network are managed by FireMonFiremon SM, integrate FireMon it with LumetaAsset Manager. Then check the results on the FireMon Management Dashboard dashboard. 

Here's how the integration works:

  1. Lumeta Lumeta Asset Manager accesses the API of FireMon SM (at a polling interval set by the user) and retrieves the inventory of FireMonSM-managed endpoints.
  2. Lumeta Lumeta Asset Manager correlates this inventory against LumetaAsset Manager's authoritative index of IP address space. Any endpoint devices not running FireMon SM are reported as undefended and not managed.
  3. Lumeta Lumeta Asset Manager highlights the differences and commonalities into in views that are presented on the FireMon Management Dashboard dashboard.

Criteria for Devices Pushed to Security Intelligence Platform

Upon Discovery by Asset Manager, a device must meet two criteria to be pushed to SM as a Synthetic Router

  1. Device must be an SNMP Responder
  2. Device must have more than one Interface

User Permissions Requirements

The following user permissions need be configured in Security Managerthe Administration module, at a minimum, for this integration to work: 

  • Administration > Data Collectors > Read/Write
  • Application Module > Administration Center > Read, Security Manager > Read
  • Device Group > All Devices > Read/Write

To create or edit the user group, browse to Administration to Administration > Access tab and click > User Groups.

Image Added

Configuring the FireMon Feed

To configure the FireMon Security Intelligence Platform integration:

  1. On LumetaAsset Manager's main menu, browse to to Settings > Integrations  > Other Solutions > > FireMon


  2. Enable the integration by moving the Active slider to the right
    The label changes from Off to On. To disable the feed while leaving the credentials in place, move the slider to the Off position. 

  3. Input a Polling Interval to indicate the time that should elapse between fetching the latest feed data. Input 24 to poll daily, input 12 to poll twice a day, and so on.

  4. Input the IP address or system name of your FireMon SIP server.

  5. Input your FireMon SM credentials.

  6. Click Submit.  
    The configuration is saved.

See FireMon Management Dashboard to see where the data from this integration populates in the Lumeta Asset Manager and Security Manager SM browser interfaces.