Administrator and secure Amazon EC2 instances with Dynamic Address
Groups.
| Where Can I Use This? | What Do I Need? |
|
|
- AWS account
- Amazon Machine Image (AMI) ID
- VM-Series License (PAYG or BYOL)
- VM-Series plugin
- Panorama
- Panorama plugin for AWS
|
In a dynamic environment such as the AWS-VPC where you launch new EC2 instances on-demand, the
administrative overhead in managing security policy can be cumbersome. Using Dynamic
Address Groups in security policy allows for agility and prevents disruption in
services or gaps in protection.
In this example,
you can use the VM Information Source on the firewall to monitor a
VPC and use Dynamic Address Groups in security policy to discover
and secure EC2 instances. As you spin up EC2 instances, the Dynamic
Address Group collates the IP addresses of all instances that match
the criteria defined for group membership, and then security policy
is applied for the group. The security policy in this example allows
internet access to all members of the group.
Instead of using VM Information Source on the firewall, you can opt to use Panorama as the
central point for communicating with your VPCs. Using the AWS plugin on Panorama,
you can retrieve the IP address-to-tag mapping and register the information on the
managed firewalls for which you configure notification. For more details on this
option, see
Resource Monitoring on AWS.
This workflow in the
following section assumes that you have created the AWS VPC and
deployed the VM-Series firewall and some applications on EC2 instances.
For instructions on setting up the VPC for the VM-Series, see
Use
Case: Secure the EC2 Instances in the AWS Cloud.