NetBox Labs logo

NetBox Labs + Elisity: Network Source of Truth Driven Microsegmentation

NetBox is where your network team documents every device: site, location, device role, device type, and asset tag. Elisity pulls that authoritative record into IdentityGraph™ and turns it into microsegmentation policy enforced through the network infrastructure you already own. Your source of truth stops being documentation and becomes a security control.

Device Intelligence
CMDB
NetBox Labs and Elisity integration showing NetBox network source of truth data in the Elisity Cloud Control Center
 

Support Documentation

Read the complete integration details and resources.
 

Challenge


Your Network Source of Truth Never Reaches Your Security Policy

Network teams keep NetBox current. Every device carries a site, a location, a rack, a device role, a device type, a manufacturer, a platform, a serial number, and an asset tag. That record governs provisioning, capacity planning, and change management, and the people who maintain it treat it as authoritative. It almost never reaches the security policy engine. Segmentation policies get written from a different set of inputs: subnet ranges, VLAN IDs, and a spreadsheet an analyst assembled by walking the floor. Two inventories of the same network now exist, maintained by two teams, and they disagree within weeks. The security team is the one working from the stale copy. A device that moved from the Cleveland plant to the Columbus lab is correct in NetBox and wrong in the policy that governs it. When an auditor asks which record is authoritative, there is no good answer.

Elisity Solution


NetBox Attributes Enrich Elisity IdentityGraph Automatically

Elisity pulls your NetBox records into IdentityGraph through an API connection and keeps them current, so the record your network operations team trusts becomes the record your security policy runs on. The connector imports device name, site, location, device role, device type, manufacturer, operating system platform, serial number, asset tag, and any custom tags your team has defined. Those attributes land on the asset in IdentityGraph next to everything Elisity already knows about it: observed traffic behavior, user identity, and context from your other connected sources such as EDR, CMDB, and OT visibility platforms. One asset record, many contributing systems, no manual reconciliation. NetBox stays the authority on how your infrastructure is documented. Elisity becomes the place that documentation is enforced. Nothing changes about how the network team works, and nothing has to be re-entered by the security team.

Challenge


Manual Device Classification Delays Every Segmentation Project

Building a segmentation policy starts with knowing what each device is, where it sits, and who owns it. Most security teams gather that by hand: exporting ARP and MAC tables, correlating against DHCP leases, chasing owners by email, and reconciling all of it in a spreadsheet that is stale the day it is finished. The work runs for weeks and restarts every time the environment changes. It also produces errors that surface later as production incidents: an infusion pump grouped with guest wireless, a badge reader classified as a workstation, a lab instrument that loses reach to its collection server overnight because someone typed the wrong role. Meanwhile the correct answer already exists, documented by the network team the day the device was racked. Classification is rarely a knowledge problem. It is a plumbing problem between the system that holds the truth and the system that enforces it. See how automated asset discovery closes that gap.

Elisity Solution


Verified in NetBox Becomes an Attribute You Can Enforce On

Elisity cross-references every discovered device against your NetBox source of truth by MAC address and IP address, and assets that match receive a “Known in NetBox Labs” attribute in IdentityGraph. That single attribute turns a documentation process into an access control. A device that appears in NetBox is documented, owned, and accounted for, so it can be granted the access its role calls for. A device on the same subnet that does not appear in NetBox arrived without passing through change management, and you can restrict it, quarantine it, or send it to a review queue before you know anything else about it. Security teams have wanted that control for years and have usually had to approximate it with certificates or 802.1X enrollment. Here it comes from a record your network team already maintains, and it stays accurate because they keep maintaining it.

Challenge


Static Segmentation Policy Drifts as Infrastructure Changes

Infrastructure moves. A device is relocated to another site during a consolidation. A rack of servers changes device role when the application it hosted is retired. New equipment arrives every quarter, and the network team records all of it in NetBox as it happens. Segmentation policies written against IP ranges and VLAN assignments follow none of that. They hold whatever state they were given on the day they were written, so the gap between documented reality and enforced policy widens every week. Security teams try to close it with change tickets: a manual policy update for every infrastructure change, filed after the fact, queued behind whatever else is burning. Some of those tickets are never filed at all. What auditors find in a segmentation review is the predictable result: policies that were correct at deployment and have not been correct since.

Elisity Solution


Any NetBox Attribute Can Drive a Dynamic Policy Group

In the Elisity Cloud Control Center, any NetBox attribute can serve as match criteria for a policy group: site, location, device role, device type, manufacturer, or a custom tag your team defined. You write the intent once. Devices whose NetBox role is PLC, at any site tagged for manufacturing, may reach the historian and nothing else. When the network team moves that device to a new site in NetBox, or changes its role, the attribute changes on the next sync and the device moves into the policy group its new state matches. No ticket, no policy edit, no drift. Enforcement runs through the network infrastructure you already own, so a device that changes role does not have to be re-cabled, renumbered, or moved to a different VLAN to land under a different policy. Your source of truth becomes the control plane for segmentation, and it stays current because your network team was already keeping it current.

Explore Our Integrations

Elisity integrates with leading IT, OT, and IoT asset intelligence platforms. Combine deep device discovery and classification with identity-based microsegmentation enforced through your existing network infrastructure.

Device Intelligence / Risk Status

EDR / Risk Status

CMDB

Network Enforcement Point

User Identity / Device Metadata

SIEM

NetBox Labs + Elisity Integration FAQ

Get answers to common questions about how NetBox Labs integrates with Elisity to turn your network source of truth into identity-based microsegmentation policy enforced across your existing infrastructure.

How does the NetBox Labs and Elisity integration work?

NetBox is the network source of truth where your team documents every device: its site, location, device role, device type, manufacturer, platform, serial number, and asset tag. You connect NetBox to Elisity by entering API credentials in the Elisity Cloud Control Center. Once connected, those NetBox attributes flow into Elisity IdentityGraph and attach to the matching asset record. Security teams then build identity-based microsegmentation policies using NetBox attributes as match criteria, and Elisity enforces those policies through the network infrastructure you already own, with no agents on the devices and no new hardware.

What NetBox data does Elisity import into IdentityGraph?

Elisity imports the infrastructure metadata your team maintains on NetBox device records: device name, site, location, device role, device type, manufacturer, operating system platform, serial number, asset tag, and custom tags. Each attribute becomes available in Elisity IdentityGraph as match criteria for policy groups, so a policy can target every device whose NetBox role is PLC, or every asset at a named site, without referencing an IP address or a VLAN. Elisity holds NetBox attributes on the same asset record as context from your other connected sources, including EDR platforms, CMDBs, identity providers, and OT visibility tools.

How does Elisity match discovered devices to NetBox records?

Elisity cross-references every device it discovers on the network against your NetBox source of truth using MAC address and IP address matching. Devices that match a NetBox record receive a “Known in NetBox Labs” attribute in IdentityGraph. That attribute is usable directly in policy, so you can grant documented infrastructure the access its role requires while restricting or flagging any device that appears on the network without a corresponding NetBox record. It gives security teams an enforceable control derived from the change management process the network team already follows, rather than a separate trust list to maintain.

Do NetBox-driven segmentation policies update automatically when infrastructure changes?

Yes. NetBox attributes act as dynamic match criteria for Elisity policy groups, not as static assignments. When your network team updates a device in NetBox, for example moving it to a new site or changing its device role, the updated attribute reaches Elisity IdentityGraph on the next sync and the device is re-evaluated against every policy group. A device that no longer matches one group moves into the group its new attributes match. No policy edit or change ticket is required, and no re-cabling, renumbering, or VLAN change is needed for a device to fall under a different policy.

Do I need new hardware or endpoint agents for NetBox-based microsegmentation?

No. Elisity enforces policy through the network infrastructure you already own, and it discovers and classifies devices without installing anything on them. That matters for the equipment NetBox documents carefully and security tools reach least: PLCs, building management controllers, medical devices, printers, cameras, and other systems that cannot run an agent or absorb an unplanned change window. The NetBox connection is an API integration configured in the Elisity Cloud Control Center, so adding it requires no network redesign, no hardware refresh, and no maintenance window on production devices.

Back to top

Resources

Tackling Enterprise Network Challenges with Elisity: Transforming Asset Inventory and Policy Management Through Automation
Tackling Enterprise Network

Tackling Enterprise Network Challenges with Elisity: Transforming Asset Inventory and Policy Management Through Automation

Sep 5, 2023, 12:57:18 AM 6 min read
OT Asset Inventory: CISA's 2025 Guide to Modern Defensible Architecture

OT Asset Inventory: CISA's 2025 Guide to Modern Defensible Architecture

Sep 5, 2025, 12:09:16 PM 10 min read
How to Automate Palo Alto Networks Dynamic Address Groups with Identity-Based Classification
Palo Alto firewall automation in a modern data center with server racks and network cabling

How to Automate Palo Alto Networks Dynamic Address Groups with Identity-Based Classification

Feb 27, 2026, 4:31:49 PM 12 min read