"Great Dashboard and Account Team, but Deployment and Map Blind Spots Need Work"
I really like the dashboard, the account team, and the map that shows which tools are communicating with other tools. Deployment was a bit difficult and, naturally, overly dependent on other teams. I also felt the map may have had some blind spots. Since we were the engineers building the solution and not the server owner, we had to do extra research and, in some cases, learn things the hard way. Illumio has helped limit our blast radius in the event of a breach, specifically for our nuclear assets.
"Simple Cost Optimization and Integration"
I think Illumio is an easy-to-use product that's been helping me quite a lot with the portfolio of customers that I manage. I think it's a good tool to leverage. I also find the complete suite to be a good one. The initial setup was easy, with a team of experts that made the implementation less complicated and fairly simple. Overall, it's a product that helps us at a larger enterprise level. Nothing much but the UI could be a bit more simpler I use Illumio for cost optimizations and tech recoveries, leveraging it to save on costs and plan for ROI. It's an easy-to-use product that helps manage my customer portfolio effectively.
"Strong Micro-Segmentation with Valuable Enterprise Visibility"
I use Illumio for its core micro-segmentation functionality. I appreciate that it offers visibility that proves highly beneficial for large enterprises. After installation, it generated a map of all workloads, aiding in restricting lateral movement and better identifying and mapping our environment. I also found the initial setup very straightforward, with a professional team providing guidance and support at every stage. I believe Illumio needs to improve their solution in container environments to offer enforcement with an agentless solution. I find that Illumio limits the damage of potential breaches by restricting lateral movement. We gain visibility with its core functionality, and it creates a map of our workloads, helping us identify and map our environment better.
"User-Friendly Microsegmentation with Clear Illumination Maps"
It effectively provides microsegmentation for workload security and is easy to use. The illumination maps are available and straightforward to understand, which helps with visibility. I also like that applications can be grouped together, making organization and management simpler. There are no time-bound ACL rules we can use to track temporary ACL requests. VM cloning also has issues because it copies the VEN’s identity to the cloned machine. There should be a way to remediate this automatically. Effective microsegmentation is a major plus, since security policy enforcement is no longer reliant on the network gateway and SVI ACL. Workloads can be locked down, and stricter rules can be applied to help prevent security breaches.
"Robust microsegmentation tool, but not the most user-friendly"
Able to ringfence server and application groups. Can easily find traffic that is being blocked internally and why. Not intuitive. Long learning curve. Needs the ability to allow traffic but block some. Only does deny all but allow some. Policies sometimes don't work and the reason you get from Support doesn't make any sense, when other policies made the same way work just fine. Support has gone downhill, now just normal. Lets me easily segment my environments and application groups to only allow the required traffic on the required ports from the allowed workstations. More than meets my compliance requirements.
"Improved Network Segmentation"
I highly value Illumio’s illumination feature as it allows me to map current traffic and understand communication patterns before implementing stricter policies. The various maps and dependency views make it easier to see system interactions and give me a more comprehensive picture, especially useful when working on network segmentation. Adopting Illumio hasn’t been seamless; even after a year, we’re still figuring out how to enable and use certain features effectively. I’d like our security analysts, network engineers, and sys admins to use it more confidently. More guided, hands-on technical workshops for customers would significantly boost our full adoption. We utilize Illumio for network segmentation to monitor and control traffic, block lateral movement, and better understand communication patterns. The Illumination feature maps traffic flows and dependencies, giving me a clear, complete view of what’s communicating with what before applying policies.
S
Senior Advisory Cloud Security Engineer
"Simplified Segmentation, Needs Improved Logging"
I really like how Illumio simplifies workload management through Labels. When a new server arrives, we just apply the labels, and everything is configured. This setup means that when new servers are added, the correct policies are automatically applied without manual lookup. Understanding Illumio wasn’t difficult for our team; it’s quite intuitive. Logging definitely needs enhancement; that’s the frustrating aspect. I’ve raised support tickets, but they didn’t resolve the issue. Sometimes I wait 30-40 minutes for new logs to appear in the Illumio console. There should be no delay in logs. If we’re troubleshooting and need Illumio logs, they should be available in real-time. If not, we should have the option to configure or send VEN logs directly to our internal SIEM or syslog server. We use Illumio for microsegmentation, which reduces lateral movement risk without needing extra firewalls. Managing workloads with labels streamlines our process by enabling automatic policy application without manual lookups.
"Zero Trust Segmentation Enhancing Visibility and Reducing Breach Impact"
Illumio proves valuable by preventing attackers from moving laterally within the network if a breach occurs. It employs Zero Trust segmentation to restrict access without requiring significant network changes. It provides clear visibility into application traffic across data centers and cloud environments. Overall, it reduces the blast radius of attacks, simplifies operations, and bolsters security with minimal disruption. It may take time to fully fine-tune Illumio, as defining the right policies requires upfront effort. It focuses solely on segmentation, so it doesn’t substitute for other security tools like EDR or firewalls. Its value is most pronounced in complex environments, possibly limiting its impact for smaller setups. Teams may also need training to become proficient with the model and workflows. Illumio helps halt cyberattacks from spreading inside a network by partitioning it into small, controlled segments. It offers clear visibility into how systems and applications communicate. This simplifies spotting risky connections and unusual behavior. Illumio functions across on-premises, cloud, and hybrid environments. In the event of a breach, damage is contained rather than spreading everywhere.
S
Solution Architect, Core Infrastructure
"Exceptional Architecture Facilitating Onboarding and Micro-Segmentation"
Illumio stands out as a superbly architected platform, making our onboarding experience efficient and smooth. The methodology of tagging each workload with different labels, then leveraging those labels to comprehend and visualize traffic and formulate the appropriate policies, has significantly accelerated our micro-segmentation rollout. The Rule Sets and Policies are crafted with the destination in focus, so it’s simple to establish policy for applications that have the Illumio VEN Agents installed, permitting traffic into those apps/workloads by defining the Scope for the Rule Set. It becomes a bit more challenging to write outbound Rule Sets when workloads must communicate with an application lacking a VEN Agent, as there’s no Scope for such destinations, which may not be classified as workloads. Illumio resolves three key challenges for us. Primarily, it safeguards our applications and workloads by permitting only the intended network traffic to and from them, nothing more. This moves us significantly closer to Zero Trust. The second advantage is the enhanced visibility, as observing network traffic simplifies the creation of application traffic maps and dependency maps for both on-premises and cloud workloads. The third issue it addresses is that by analyzing network traffic and identifying risky flows, it can recommend security improvements by closing ports the platform flags as dangerous, such as common ransomware ports.
P
Principal Security Architect
"Enhancing Zero Trust via Workload Visibility and Microsegmentation"
The standout feature of Illumio for me is how it offers clear insights into workload communications and supports detailed microsegmentation without a heavy dependence on traditional network perimeters. The label-based policy approach simplifies segmentation management across intricate hybrid setups, offering robust oversight of east-west traffic and curbing lateral movement risks. One aspect that might be enhanced is the workload management interface. For instance, the Workloads page doesn’t facilitate searching or handling multiple specific workloads simultaneously, which can be cumbersome in large-scale environments. Additionally, reporting and bulk operations could benefit from greater flexibility, particularly for larger implementations. Improved filtering, easier bulk actions, and more customizable dashboards and reports would elevate the daily operational experience. Illumio tackles the issue of managing east-west traffic and minimizing lateral movement in complex hybrid environments. It offers visibility into inter-workload communications and enables the application of detailed segmentation policies based on labels rather than network boundaries. This reinforces our Zero Trust strategy, mitigates exposure to risky or unnecessary traffic, and offers better control during security incidents without necessitating major network infrastructure changes.