Solution Brief | Accelerating Zero Trust | Check Point Software
Solution Brief | Accelerating Zero Trust
Check Point Hybrid Mesh Firewall and Illumio Insights
The Visibility Gap in Hybrid Environments
Security teams are not short on data. They are short on clarity. As applications spread across on-premises and cloud environments, traffic patterns become harder to interpret through IP addresses, ports, and isolated log records alone. Traditional tools can show that traffic exists, but they often do not show what that traffic relates to, why it matters, or how it connects to broader risk across the environment. This creates three practical challenges:
- Fragmented hybrid visibility
Traffic and policy data are often split across management domains, cloud environments, and operational tools. Analysts are forced to stitch together partial views to understand what happened. - Limited context for east-west risk
Many attacks spread through internal traffic paths after gaining an initial foothold. Without better context around risky communication paths, suspicious protocols, and asset relationships, lateral movement can be difficult to detect early. - Slower investigation and response
When analysts must reconstruct incidents from disconnected firewall logs and infrastructure details, response times slow down, and prioritization becomes harder.
What the Integration Delivers
The Check Point and Illumio Insights integration helps organizations make better use of their existing telemetry. Check Point provides firewall telemetry and policy metadata, while Illumio Insights ingests that data and turns it into a clearer operational picture of traffic behavior, risky paths, and investigation context across hybrid and multi-cloud environments. At its core, Illumio Insights provides:
- Real-time visibility into traffic behavior across your environment.
- A thorough understanding of risks that can help identify suspicious patterns before they occur.
- A more informed investigation context so security teams can connect events rapidly, prioritize threats, and respond faster.
How It Works
The integration between Illumio Insights and Check Point’s Hybrid Mesh Firewall combines two data paths:
- Log ingestion from Check Point Log Exporter, which forwards firewall telemetry into Illumio Insights.
- An optional API integration with Check Point Security Management, which enriches findings with firewall metadata and policy information.
This allows Illumio Insights to transform Check Point firewall logs from passive records into an active source of visibility and detection spanning on-prem and cloud estates. In practice, security teams can use the integration to:
- Understand traffic behavior across hybrid environments in a more unified view.
- Investigate suspicious east-west activity with better asset and environment context.
- Identify risky communication paths and over-broad access patterns.
- Improve prioritization by correlating network activity with firewall and policy context.
- Strengthen detection and response using Hybrid Mesh Firewall telemetry.
What You Get
Check Point’s Hybrid Mesh Firewall is a unified firewall in multiple form factors. It can be deployed as an appliance whether a data center hyperscale rack or a single-branch appliance, as a virtual firewall with unique cloud integrations for private and public clouds, or as a Firewall as a Service for plug-and-play, cloud-native deployments. As a Hybrid Mesh Firewall, Check Point gateways collect and correlate logs and telemetry in Check Point’s centralized management system. This means that Check Point already generates rich firewall telemetry across hybrid environments. However, telemetry alone does not automatically create clarity.
In many organizations, logs are stored for compliance, reviewed after an incident, or left in separate tools, making it harder for security teams to detect suspicious internal activity quickly or understand which traffic paths matter most. This is where Illumio Insights comes in. By ingesting Check Point firewall telemetry and enriching it with asset, traffic, and environment context, Illumio Insights helps teams see traffic behavior more clearly, investigate suspicious activity faster, and prioritize response with greater confidence.
Typical Use Cases
- Suspicious east-west traffic investigation: Detect and investigate unusual internal traffic patterns, including protocols, paths, or communication behaviors that may indicate compromise.
- Remote management abuse analysis: Examine remote management traffic and access paths that may expose administrative systems or provide attackers with a route to expand access.
- Risky workload behavior triage: Identify anomalous traffic associated with potentially compromised resources and understand what those resources connect to across the environment.
- Potential data exfiltration review: Investigate suspicious outbound communication and understand where traffic is going, what environment it touches, and why it may matter.
Conclusion
The Check Point and Illumio Insights integration helps teams get more value from the controls they already use. Instead of leaving firewall telemetry in isolated systems or reviewing it only after an incident, teams can use that telemetry to improve day-to-day visibility, threat hunting, investigation, and prioritization. The integration is also designed to support distributed environments, including multiple Check Point Log Exporters across different domains, providing organizations with a more centralized and comprehensive view of network flow information.