Tufin.club
  • www.tufin.club
  • imprint
  • data privacy statement

www.tufin.club

Tufin Orchestration Suite 5.3.00

Details
Version update
Last Updated: 20 August 2026

Tufin has officially released TOS 5.3.00. It's available as GA and can be downloaded from the Tufin Portal (authentication and subscription contract required).
Some improvements of TOS 5.3.00:

  • Amazon AWS Network Firewalls are supported now in SecureTrack regarding Policies, Rule Bases as well associated Firewalls.
  • AWS Cloud WAN is supported to retrieve and model Network Function Groups (NFGs) and their service insertion configuration in the Topology Map.
  • Regarding any AWS Resource Type (generic resources) are supported by SecureTrack, i.e. support of NLBs, ALBs, private/public VPC endpoints, and more, in addition to EC2 instances, representing them as network entities in the revision, topology map, and path analysis.

  • Cisco L3 switches now can be imported to SecureTrack via Bulk Device API, as it has been possible before for routers and other L3 devices.
  • For Cisco Meraki provisioning of changes is possible for Meraki MX devices, as it is for other platforms before. Site-to-Site VPN rules are placed at the organization level, Layer 3 firewall rules at the per-network level, and group policy rules at the per-group-policy level. 

  • For Check Point, SecureTrack supports Object Usage (last hit), Rule Viewer now also displays the statistics for FQDN/domain-based objects.

  • Microsoft Entra ID is supported now as it is Active Directory (AD) on prem. Entra ID user groups can be used for topology and end-to-end access requests.
    Currently supported for Palo Alto Panorama and Strata Cloud Manager only.

  • Palo Alto Networks (PAN) Strata Cloud Manager is supporting dynamic as well as static routes in the Topology Map. 
  • Strato Cloud Manager allows automation for Strata Cloud Manager (SCM) NGFW Folders in Access Request Workflows for IPs when in Topology Mode. Support of Designer, Verifier, and Provisioning.
  • PAN Shared Gateways with shared gateway interfaces are supported by the Topology Map now. They are mapped to their privacy zones as defined in the PAN devices.
  • For Palo Alto Panorama-managed Firewalls information about "rule last hit" can be retrieved via API now. 

  • NSX devices are supported better regarding rule matching. It now now considers traffic associated with Security Groups (SGs) specified in the NSX rule's Applied To field,
  • NSX-T Distributed Firewalls (DFW) are supported in SecureChange Access Requests without activated Topology (Designer, Verifier, Provisioning).
  • NSX Security Group (SG) types are fully supported now across Rule Viewer as well as Topology Map.
  • Syslogs following RFC-5424 are supported for NSX devices now. '

  • SecureTrack shows additional new options 
    • Zones and Subnet Data are analyzed in regard of configuration errors, hints are delivered
    • USP violations consider now User Identity also (no subnet specification), they are validated agains a pre-defined User Network Zone. 
    • SecureTrack Rule Viewer has a new TQL field: "added", so rules can be searched for the date they were added
    • SecureTrack Rule Viewer supports the search for 3rd party vendors (OPM) now.
    • SecureTrack Rule Viewer allows to search for rules regarding Security Zones containing source or destination IP

Further improvements, as well as corrections, are included in TOS 5.3.00.
The latest version of the Tufin Orchestration Suite can be found and downloaded from the Tufin Portal: https://portal.tufin.com

 

 

 

 

Tufin Orchestration Suite 5.x

Details
Version update
Last Updated: 07 July 2026

After referencing the publication year in the version since 2012, Tufin now has introduced the new naming convention - starting with 5.0.00 (even if that version number has already been published in 2010/2011).

Starting with 5.0.00 Tufin will provide major versions (PGA) and hotfixes (PHF), respectively. Regarding versions this needs to be considered

  • Platform version, e.g. TOS 5, TOS 6
  • Initial release version, e.g. 5.0.00, 6.0.00 -> not for production
  • Feature version, e.g. 5.1.0, 5.2.0 with feature enhancements, bug fixes, but hardly any infrastructure changes

In version 5.1.0 some new features and options have been integrated

  • Operating System:
    TOS can now be installed on Red Hat Enterprise Linux 9 and Rocky Linux 9 operating systems

  • For Amazon AWS, TOS now supports not only SDKv1, but also SDKv2 for AWS Monitoring. SDKv1 has reached End of Support.
  • Amazon AWS RDS instances are now visible in TOS. It requires AWS SDKv2 and delivers some advantages (details here).   
  • Amazon AWS accounts can be monitored by TOS, i.e. AWS opt-in regions using assume role authorization. SDKv2 required.
  • Arista VeloCloud SD-WAN devices can now be monitored by TOS
    Please follow these links to find information about feature support in SecureTrack and SecureChange.
  • Cisco IOS-XE SDWAN (cEdge) - GRE Tunnel is supported by TOS now, more here.
  • Regarding Cisco FMC, FQDN objects are supported now in SecureTrack and SecureChange.
  • In Microsoft Azure, TOS now supports VNet flow logs when configured correctly.

  • Tufin AI support is integrated, allowing e.g. own dashboards and reports.

TOS 5.1.0 is available in the Download Section of the Tufin Portal: https://portal.tufin.com (authentication required).

 

 

 

TufinOS 4.70 available

Details
Version update
Last Updated: 11 June 2026

In April, Tufin has released TufinOS 4.70, based on Rocky Linux 8.10 latest versions. 
It includes Kernel version 4.18.0-553.89.1.el8_10.x86_64 and 105 updated RPMs. TufinOS includes now 755 RPMs in total. 

TufinOS is available for Tufin Appliances Gen 4.0 (T-800, T-1200), as well as Gen 4.5 (T-820, T-1220) and the new Gen 5.0 applicances (T-900, T-1300). 
It cannot be deployed on Gen 3.5 appliances T-1100XL and T-1100 (!)
As before, the supported hypervisor is VMware. 

TufinOS is available in the Download Section of the Tufin Portal: https://portal.tufin.com (authentication required).

 

Granular SLAs for Workflows

Details
SecureChange
Last Updated: 11 June 2026

Since many years it's possible to configure SLAs for SecureChange Workflows. In earlier times, there was no option to disregard e.g. weekends. So if a step needed to be completed within 2 days, a problem was there during weekends: Step started on Friday afternoon and not worked on until Monday. 

Today, a granular configuration is possible. It's done in SecureChange via Menu > Settings > SecureChange > Miscellaneous. 

As shown above, it's possible to define business hours as well as business days. Additionally, there is an option to import / export further dates like e.g. public holidays. When exporting the list as CSV file, it should not be edited in Excel - the import will fail afterwards. It's recommended to modify this file with a simple editor like Notepad++ or similar. Then, the import is usually successful.
Please find below a sample for 2026 (Germany) that you can copy, modify and import into your TOS installation. 

"name","from_date_yyyy-mm-dd","to_date_yyyy-mm-dd","comment"
"New Year's Day","2026-01-01","2026-01-01","Neujahr"
"Twelfth Day","2026-01-06","2026-01-06","Heilige Drei Könige (nicht überall)"
"Good Friday","2026-04-03","2026-04-03","Karfreitag"
"Easter","2026-04-05","2026-04-06","Ostern"
"Labor Day","2026-05-01","2026-05-01","Tag der Arbeit"
"Ascension Day ","2026-05-14","2026-05-14","Christi Himmelfahrt"
"Pentecost","2026-05-25","2026-05-26","Pfingsten"
"Feast of Corpus Christi","2026-06-04","2026-06-04","Fronleichnam (nicht überall)"
"Feast of the Assumption","2026-08-15","2026-08-15","Mariä Himmelfahrt (nicht überall)"
"German Unity Day","2026-10-03","2026-10-03","Tag der deutschen Einheit"
"All Saints' Day","2026-11-01","2026-11-01","Allerheiligen (nicht überall)"
"Christmas","2024-12-24","2025-12-26","Weihnachten"
"New Year's Eve","2026-12-31","2026-12-31","Silvester"

 

 

 

Check Point Management-HA and SecureTrack (2)

Details
SecureTrack
Last Updated: 02 April 2026

Nearly since the first versions of Tufin SecureTrack, Check Point Management-HA has been supported by Tufin. The requirements at that time were not as high as today and the software has been much more simple than today. 

In an earlier article about Check Point Management-HA some restrictions of SecureTrack have been pointed out (regarding e.g. Ticket-IDs or certification dates for rules). Today, there are further "specialities" when using the Rule Viewer. 
Actual versions don't consider the mechanism of Check Point Management-HA (not even in the data base). So if two Management Servers are connected to SecureTrack, each rule is shown twice (also if the secondary Management is imported correctly to SecureTrack using https://<ST>/tools). 

Following Tufin Support, the official workaround is to filter also for the Device ID of one of the two Check Point Management Servers. And, it's recommended to open a Request for Enhancement (RFE) asking Tufin to improve the functionality when Check Point Management-HA is deployed. 

 

 

 

 

New Tufin Appliances available

Details
TOS Aurora
Last Updated: 18 February 2026

Tufin has released a new generation of appliances for TOS. 
They incluce enterprise-grade hardware and deliver sufficient resources to run Tufin's solution. Two appliances are available:

T-900 (R470XL Platform)

  • Processor
    1 x Intel® Xeon® 6 Performance 6521P, 2.6GHz
    (24 physical cores; 48 threads)
  • RAM
    256GB DDR5-6400 RDIMM (8 x 32GB)
  • Data Storage
    Data SSD: 1.92 TB (2 x 1.92 TB RAID1)
    ETCD SSD: 800 GB (2 x 800 GB RAID1)

T-1300 (R670SL Platform)

  • Processor
    2 x Intel® Xeon® 6 Performance 6515P 2.3GHz
    (32 physical cores; 64 threads)
  • RAM
    256GB DDR5-6400 RDIMM (16 x 16GB)
  • Data Storage
    Data SSD: 7.68 TB (4 x 3.84 TB RAID10)
    ETCD SSD: 800 GB (2 x 800 GB RAID1)

Please refer to here for getting more detailed information. 

 

 

 

Page 1 of 26
  • Start
  • Prev
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • Next
  • End
Bootstrap is a front-end framework of Twitter, Inc. Code licensed under MIT License. Font Awesome font licensed under SIL OFL 1.1.