Illumio adds agentless firewall telemetry to Insights
Illumio has launched an agentless addition to its Insights product that uses telemetry from Check Point and Fortinet firewalls to map traffic flows and identify potential breach pathways across hybrid environments.
Illumio Insights ingests real-time telemetry and policy data from the two firewall providers and converts it into live traffic maps. Illumio said the update extends visibility beyond cloud workloads to data centre networks and endpoint estates without requiring software agents.
Many organisations rely on a mix of on-premises infrastructure and multiple cloud services, which can leave security teams with fragmented views of application traffic and policy enforcement. Illumio argues that normalised and mapped firewall telemetry can provide a unified view of communications patterns across environments.
Illumio said the result is an end-to-end view of network posture that highlights high-risk pathways and policy gaps. The same data can also help detect lateral movement, when attackers move between systems after an initial compromise.
Firewall telemetry
The integration uses data organisations already collect from perimeter and internal firewall deployments. Check Point and Fortinet appliances generate logs and telemetry based on observed connections and enforcement decisions. Illumio Insights uses that information to map traffic across data centre and cloud environments.
Illumio said an agentless approach reduces the need to install and manage software across large fleets of servers and endpoints. Many security tools rely on agents for deep visibility or enforcement, which can be difficult in environments with legacy systems, tight change windows, or third-party-managed infrastructure.
Agentless approaches, however, typically depend on the completeness of network telemetry and the placement of sensors or enforcement points. Illumio's position is that existing firewall infrastructure can serve as a broad data source for visibility, while still allowing organisations to use agents when they need host-level controls.
"Modern hybrid environments require security controls that are open, integrated, and prevention-focused. By leveraging Check Point firewall telemetry for Illumio Insights with agentless visibility, enterprises can reduce blind spots and act faster across cloud and on-prem environments," said Paul Barbosa, VP Cloud & SASE, Check Point Software Technologies.
Fortinet highlighted the role of telemetry across its firewall and SASE portfolio. "Fortinet firewalls and FortiSASE deliver rich telemetry that helps customers extract more value from their existing security investments. This integration transforms that data into clearer insight about application behavior across on-premises and cloud environments, enabling teams to identify risks faster and advance Zero Trust across hybrid networks," said Neil Prasad, Vice President and Head of Global Technology Alliances at Fortinet.
Visibility and containment
Illumio Insights is part of a broader product set that also includes Illumio Segmentation. Illumio said Insights works alongside Segmentation, which it describes as enforcing microsegmentation and containment policies intended to limit the spread of ransomware and other intrusions.
Microsegmentation restricts east-west traffic inside networks, rather than focusing only on north-south perimeter controls. It is often applied to data centres and cloud environments where applications have complex dependencies. Security teams typically need accurate traffic maps before implementing restrictive policies without breaking systems.
Illumio is positioning the agentless mapping feature as a way to shorten the time between starting a visibility programme and taking action on segmentation and containment. The approach supports a mix of agentless and agent-based visibility depending on operational constraints.
Mario Espinoza, Chief Product Officer at Illumio, described the launch as a shift away from default reliance on endpoint agents for visibility.
"Hybrid complexity isn't a trend-it's reality. For decades, data centers were blind spots, and the default response was to deploy more agents. While agents remain foundational for segmentation and enforcement, visibility shouldn't have to wait," said Mario Espinoza. "Together with Check Point and Fortinet, we're rewriting the rules, delivering visibility and containment where it matters most, across every environment, without the friction that's held us back for years."
The launch also reflects a broader push for tools that span cloud and on-premises environments with consistent policy models. Security teams increasingly track risk and policy drift across mixed estates, especially where cloud network controls, data centre segmentation, and endpoint protections are managed through separate consoles.
Illumio said the new capability provides unified visibility across cloud and on-premises environments and a path to breach containment without disruption from large-scale agent rollouts. It will continue to position Insights and Segmentation together as a platform approach for hybrid breach containment.