Section | ||||
---|---|---|---|---|
| ||||
Section | ||||
| ||||
Section | ||||
| ||||
Table of Contents | ||||
maxLevel | 3 | 3 | ||
Section | ||||
| ||||
Note | ||||
To fully use this screen, you must add the following permissions to your account:
|
Anchor Overview Overview
Overview | |
Overview |
You can use the Cloud Connections screen to sync your public cloud account into the Armor Management Portal (AMP). Afterwards, you can use AMP to:
- Collect and store logs with the Log Relay add-on product
View the security status of your instance in the Virtual Machines screen
Note While all instances from your public cloud account will appear in the Virtual Machines screen, you should only focus on the security status for the instances that contain the Armor agent.
- Add AWS Security Hub feature to your public cloud account.
Review Cloud Connections
...
The Cloud Connections screen displays the public cloud accounts you have synced.
Column | Description |
---|---|
Account Name | This column displays the descriptive name for your account. You can also click the arrow to see which Armor services are associated with the account. |
Provider | This column displays the public cloud provider. |
Account ID | This column displays the ID for your public cloud account. |
Status | This column displays the connection status between your Armor accounts and your public cloud account. |
Anchor | ||||
---|---|---|---|---|
|
...
You can use the Cloud Connections screen to sync your AWS public cloud environment with the Armor Management Portal (AMP).
To complete these instructions, you must be able to access your AWS console.
Note |
---|
Armor will generate an External ID for every new Cloud Connection account. As result, an incomplete cloud connection account will be listed in the table as (Pending Connection). You can click this entry in order to continue with the cloud connection creation process. |
Step 1: Add your AWS account to AMP
- In the Armor Management Portal (AMP), in the left-side navigation, clickAccount.
- ClickCloud Connections.
- Click the plus ( + ) icon.
- In Account Name, enter a descriptive name.
- In Description, enter a short description.
- In Services,select the desired services.
- In IAM Role, copy theExternal ID. You will need this information at a later step.
- TheArmor's AWS Account Number andExternalIDfields are pre-populated.
- Access the AWS console.
- Under Security, Identity & Compliance, click IAM.
- In the left-side navigation, click Roles.
- Click Create role.
- Under Select role type, selectAnother AWS account.
- In Account ID, enter 679703615338.
- MarkRequire external ID.
- In field that appears,paste the External ID you copied earlier from the Armor Management Portal (AMP).
- Do not mark Require MFA.
- ClickNext: Permissions.
- Locate and mark the SecurityAudit policy.
- Locate and mark theAWSSecurityHubFullAccess policy.
- Click Next: Tags.
- ClickNext: Review.
- In Role name, enter a descriptive name.
- In Role description, enter a useful description.
- Click Create role.
- Locate and select the newly created role.
- UnderSummary, copy theRole ARNinformation.
- Return to the Cloud Connections screen in AMP.
- Paste theRole ARNinformation into the IAM Role ARN field.
- Click Save Cloud Connection.
- Once the newly added cloud connections gathers data, the instance will appear in the Virtual Machines screen.
Step 2: Configure Your AWS Regions
In this step, you will enable AWS Security Hub in the desired AWS regions; this action will capture the findings from Security Hub in every configured region.
- Access the AWS console.
- Access theSecurity Hubsection.
- In the left-side navigation, clickIntegrations.
- Locate and selectARMOR Armor Anywhere.
- ClickEnable.
- In the pop-up window, clickEnable.
Anchor | ||||
---|---|---|---|---|
|
...
After you add your public cloud account into the Armor Management Portal (AMP), you can view the corresponding instances (and their security status) in the Virtual Machines screen.
Note |
---|
The Cloud Connection screen simply lists the synced public cloud account; the Virtual Machines screen lists all the instances listed in that public cloud account. |
- In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure.
- Click Virtual Machines.
Column | Description |
---|---|
Name | The name of the instance from your public cloud account |
Type | The type of instance, specific to the offerings offered by your public cloud provider, such as en EC2 instance for AWS |
Provider | The public cloud provider for the instance |
OS | The operating system associated with the instance (For AWS, the associated AMI is listed) |
Date Created | The date the instance was created in your public cloud account |
Security Group | The security group that corresponds to your AWS instance.
|
Keypair | The keypair that corresponds to your AWS instance.
|
State | The security status of the instance, in relation to the installed agent. There are three states:
|
Power | The power status of the instance, either powered on (green) or powered off (red) |
Info | ||||||
---|---|---|---|---|---|---|
Anchor |
|
Related Documentation
To specifically sync your AMP account with AWS Security Hub, see Create a Cloud Connection for AWS Security Hub.
Was this helpful?
Topics Discussed
Table of Contents | ||||
---|---|---|---|---|
|