Support for Palo Alto Networks Strata Cloud Manager is available now. Learn more →

Network Security Policy That Moves at the Speed of Your Business

Resource-aware policy decisions for the hybrid enterprise. Define access based on identity and context, not static IP addresses.

[ The Big Shift ]

From Address-Based to Resource-Based Security

Traditional network security relies on static IP addresses — like sending mail to a building. FireMon Connect shifts to resource-based decisions — like sending email to a person. Access follows identity, not location.

The Old Way

Policy defined by network location

No awareness of device, intent, or access rights

Any device can be at either location

No way to know if device is still there

The FireMon Connect Way

Policy defined by resource/device identity

Full awareness of device, intent, access rights

Location no longer matters

Automatic resource identification/updates

[ What is Connect ]

Meet FireMon Connect: Your Policy Decision Platform

FireMon Connect is a resource-aware policy decision platform that sits upstream from your enforcement systems, defining access between resources based on identity and context.

Resource-Aware Decisions

Define access based on what resources are, not where they are

Automatic Maintenance

Policies update as infrastructure changes — no manual intervention

Real-Time Context

Pulls live data from CMDB, cloud platforms, and security tools

Enforcement Neutral

Works with your existing firewalls, NSPM, and enforcement systems

[ How it works ]

Four Steps to Adaptive Security

123

Step 1Ingest Resource Data

Pull data from the systems you already trust

Step 2Normalize Resources

Correlate IPs, attributes, tags, and identity context

Step 3Create Dynamic Groups

Build policy objects that update as resources change

Step 4Drive Policy Decisions

Evaluate access requests and route enforcement

Architecture

Where Connect Fits in Your Zero Trust Architecture

Context & Resource Insight
  • CMDB

  • Tags

  • Topology

  • Risk Posture

  • Ownership

Define Policy Intent — FireMon Connect
  • Validate

  • Govern

  • Trigger Enforcement

Enforce Access — FireMon NSPM
  • Firewalls

  • Cloud

[ Use Cases ]

Three High-Value Workflows

Challenge: Access requests are manual, IP-based, requiring multiple teams — increasing risk and causing delays

  • Define access using resource identity and context

  • Automatic request mapping to resource identity

  • Validation against policy boundaries before change

  • Route and implement via existing workflows

[ Benefits ]

Policy Is Power with FireMon Connect

Faster Changes

Automate access decisions to reduce change cycles from weeks to minutes

Reduced Risk

Continuously validate and remove access to minimize exposure and prevent drift

Enables Zero Trust

Align access to identity and context for dynamic least privilege

Improved Accuracy

Ensure policies reflect real resource identity and current infrastructure state

[ Day 1 Value ]

Evidence-Based Entitlement Removal from Day On

Connect correlates signals from your existing systems to identify resources that should have access removed — from day one, without waiting for a full deployment.

CMDB

Server indicated as physically decommissioned

category:hardware
type:server
owned_by:hr_mnh-grp

EDR

Hasn't seen server in X days

last_seen:2025-01-12T18:43:22Z

Network

Scan indicates server is inactive

last_seen:inactive
last_hit:2025-01-12

[ Connect vs NSPM ]

Connect and NSPM: Better Together

Connect decides access. NSPM enforces it.

Connect works alongside NSPM — and can also integrate with other enforcement systems like Tufin, Calico, and native cloud controls.

FireMon NSPM

Manages and enforces policy

Works with firewall rules

Based on IP addresses and zones

Policy lifecycle and compliance

Evaluates existing rules and changes

Reactive to change requests

Operates at enforcement layer

FireMon Connect

Decides what policy should exist

Works with resources, identity, and context

Based on resource attributes and relationships

Access intent and decisioning

Determines what access should be allowed or removed

Proactive and continuously adapting

Operates at decision/control layer