Review Summary
Users appreciate Illumio's Zero Trust Segmentation Platform for its intuitive interface, easy installation, and exce ...
Users appreciate Illumio's Zero Trust Segmentation Platform for its intuitive interface, easy installation, and exce ...

Illumio, the Zero Trust Segmentation company, stops breaches and ransomware from spreading across the hybrid attack surface. The Illumio ZTS Platform visualizes all traffic flows between workloads, devices and the internet, automatically sets granular segmentation policies to control communications, and isolates high-value assets and compromised systems proactively or in response to active attacks. Illumio protects organizations of all sizes, from Fortune 100 to small business, by stopping breaches and ransomware in minutes, saving millions of dollars in application downtime, and accelerating cloud and digital transformation projects.
Do You Manage Peer Insights at Illumio?
Access Vendor Portal to update and manage your profile.
My favorite feature of the product is the Traffic explorer allowing me to easily see all inbound and outbound traffic, the processes, services, or users initiating the traffic. Also, the ability to write policy and then view how it will impact traffic in draft mode before publishing the updated policy. There are some limitations to this feature related to outbound process-based rules to an IP list, but other than that it works great.
Intuitive interface, detailed logs, and organization with IC tags.
What I like most is the traffic visualization and analysis function. Personally, I found traffic analysis to be a time-consuming and stressful task, but at least with Illumio's management console, it works smoothly. Furthermore, I understand that network visibility and control within the company are essential requirements for future security enhancements. This visualization also allows us to proactively identify communications that truly need control. The ability to control communications without relying on interviews significantly improves communication with users regarding communication requirements. The administrator console is also well-designed, making the main functions easy to use for anyone with network knowledge.
My biggest gripe with this solution is that label changes are instantaneous. If you change a label on a workload, you could inadvertently end up blocking required traffic. Making label changes a publishing event is something that has been asked for by myself and other customers I have talked to. So far, there seems to be no movement on adding this feature. Not having this feature can make label changes a very tedious task because you need to make sure to update policy everywhere that workload has access. For example, when we started out, we overused some role labels like R-APP, which is preventing us from getting some policies as granular as we would like. This could all be solved if a label change was publishable so you could change the label and then review traffic in draft mode to see where you need to update policy based on the new label prior to publishing the change.
Traffic logs take a long time to appear in the graphical interface, about 20 minutes, which makes incident analysis difficult.
While this is partly due to our company's structure, there are times when we don't have time to check the Illumio management console. It would be helpful to have a support function that can pick out recent characteristic communications in such situations. This could also be considered a system that can be easily operated even with a small team. Furthermore, one issue that cannot be resolved with network knowledge alone is the need to truly understand our own network environment. While this should ideally be grasped through network visualization during initial deployment, there are situations where this requires considerable effort.