Page tree

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

Lumeta now offers a DisruptOps/AWS integration, which replaces the Lumeta CloudVisibility engine.  

DisruptOps is a cloud security operations platform to monitor, alert and respond to security risk across your public cloud infrastructure. 

Prerequisite

To use the feature, you must have the DisruptOps platform deployed in your AWS environment.  For guidance, pen a Support ticket (lumetasupport@firemon.com) and request Disrupt:Ops. FireMon Support will respond by providing you with implementation steps and login credentials. They will also help you deploy the necessary "cloudformation stack."

Configuration

  1. To configure this new integration, browse to Settings > Integrations > Disrupt:Ops and click Configure.
  2. Complete the form, supplying your Disrupt:Ops credentials as the Username and Password (not your AWS credentials).
  3. Firewall ACL rules must be open for Lumeta to access these URLs over port 443
    1. https://api.prod.disruptops.com/auth/login
    2. https://graph.prod.disruptops.com/graphql
    3. https://graph-v3.prod.disruptops.com/graphql

DisruptOps Cloud Dashboard

Navigate to Dashboards/Integrations and view your results under the DisruptOps Cloud Dashboard

Security Group Risk

Lumeta considers the following factors in calculating the Security Group violation:

  1. Wildcard in a Security Group.
  2. IPv4 mask is too large for a Security Group.
  3. Src/Dest checks disabled on an instance
  4. Inbound/outbound path to the public internet (direct and indirect)

Instance Inventory

Lumeta will display AWS Instance Information including Instance ID, Public MAC Address, Public IP, VPC ID, Security Group IDs and Region.  All this information can be configured into reports; combing you cloud instance information with your on prem devices.

Map

Lumeta Map offers a quick view of your AWS instances.  Map can be organized by Region, Account, or VPC ID. 

The Map will only show Regions, Accounts, and VPC IDs for which we have retrieved EC2 Instances.





  • No labels