Support for Palo Alto Networks Strata Cloud Manager is available now. Learn more →
[ The Big Shift ]
From Address-Based to Resource-Based Security
Traditional network security relies on static IP addresses, like sending mail to a building.
FireMon Connect shifts to resource-based decisions, like sending email to a person. Access follows identity, not location.
The Old Way
Policy defined by network location
No awareness of device, intent, or access rights
Any device can be at either location
No way to know if device is still there
The FireMon Connect Way
Policy defined by resource/device identity
Full awareness of device, intent, access rights
Location no longer matters
Automatic resource identification/updates
Meet FireMon Connect: Your Policy Decision Platform
Define access based on what resources are, not where they are.
Policies update as infrastructure changes, no manual intervention.
Pulls live data from CMDB, cloud platforms, and security tools.
Works with your existing firewalls, NSPM, and enforcement systems.
Four Steps to Adaptive Security
Pull data from the systems you already trust
Correlate IPs, attributes, tags, and identity context
Build policy objects that update as resources change
Evaluate access requests and route enforcement
Where Connect Fits in Your Zero Trust Architecture
CMDB
Tags
Topology
Risk Posture
Ownership
Validate
Govern
Trigger Enforcement
Firewalls
Cloud
[ Day 1 Value ]
Evidence-Based Entitlement Removal from Day One
Connect correlates signals from your existing systems to identify resources that should have access removed — from day one, without waiting for a full deployment.
CMDB
Server indicated as physically decommissioned
category:hardware
type:server
owned_by:hr_mnh-grp
EDR
Hasn't seen server in X days
last_seen:2025-01-12T18:43:22Z
Network
Scan indicates server is inactive
last_seen:inactive
last_hit:2025-01-12
[ Use Cases ]
Three High-Value Workflows
Challenge: Access requests are manual, IP-based, requiring multiple teams — increasing risk and causing delays
Define access using resource identity and context
Automatic request mapping to resource identity
Validation against policy boundaries before change
Route and implement via existing workflows
Connect and Security Manager: Better Together
Connect decides access. Security Manager enforces it.
Connect works alongside Security Manager, and can also integrate with other enforcement systems and native cloud controls.
Security Manager
Manages and enforces policy
Works with firewall rules
Based on IP addresses and zones
Policy lifecycle and compliance
Evaluates existing rules and changes
Reactive to change requests
Operates at enforcement layer
FireMon Connect
Decides what policy should exist
Works with resources, identity, and context
Based on resource attributes and relationships
Access intent and decisioning
Determines what access should be allowed or removed
Proactive and continuously adapting
Operates at decision/control layer