Learn how to configure the Cloud Identity Engine to collect IP-Tags for rule
enforcement.
| Where Can I Use This? | What Do I Need? |
|
| The Cloud Identity Engine service is free; however, the
enforcement points utilizing directory data may require specific
licenses. Click here for more
information. |
An IP-Tag Cloud Connection enables the Cloud Identity Engine to collect IP
address-to-tag information from cloud service providers. To enforce a tag-based
Security policy that adapts to IP address changes, configure
Dynamic Address Groups using the IP
address-to-tag information.
To configure the Cloud Identity Engine to collect IP address-to-tag (also known as
IP-tag) information for policy rule enforcement, configure a connection to your
cloud service provider to
synchronize the mappings. The identity
management system provides the IP-tag information to the Cloud Identity Engine for
processing, which then provides the information to the firewalls for policy rule
enforcement.
To collect IP-tag information from your cloud service provider, you must grant the
Cloud Identity Engine the required permissions.
If you use
Strata Cloud Manager, you can view your
IP-tag information using the unified interface and use it to create your
tag-based Security policy.
For each region, you can synchronize up to 60,000 IP-tag mappings from a
cloud service in a monitoring configuration at one time. The Cloud Identity
Engine sync only the new or modified mappings each time. You can view up to
32,000 IP-tag mappings per page.
You can also view all IP-tag information in the Cloud Identity Engine ().