Tufin Orchestration Suite 5.3.00
Tufin has officially released TOS 5.3.00. It's available as GA and can be downloaded from the Tufin Portal (authentication and subscription contract required).
Some improvements of TOS 5.3.00:
- Amazon AWS Network Firewalls are supported now in SecureTrack regarding Policies, Rule Bases as well associated Firewalls.
- AWS Cloud WAN is supported to retrieve and model Network Function Groups (NFGs) and their service insertion configuration in the Topology Map.
- Regarding any AWS Resource Type (generic resources) are supported by SecureTrack, i.e. support of NLBs, ALBs, private/public VPC endpoints, and more, in addition to EC2 instances, representing them as network entities in the revision, topology map, and path analysis.
- Cisco L3 switches now can be imported to SecureTrack via Bulk Device API, as it has been possible before for routers and other L3 devices.
- For Cisco Meraki provisioning of changes is possible for Meraki MX devices, as it is for other platforms before. Site-to-Site VPN rules are placed at the organization level, Layer 3 firewall rules at the per-network level, and group policy rules at the per-group-policy level.
- For Check Point, SecureTrack supports Object Usage (last hit), Rule Viewer now also displays the statistics for FQDN/domain-based objects.
- Microsoft Entra ID is supported now as it is Active Directory (AD) on prem. Entra ID user groups can be used for topology and end-to-end access requests.
Currently supported for Palo Alto Panorama and Strata Cloud Manager only. - Palo Alto Networks (PAN) Strata Cloud Manager is supporting dynamic as well as static routes in the Topology Map.
- Strato Cloud Manager allows automation for Strata Cloud Manager (SCM) NGFW Folders in Access Request Workflows for IPs when in Topology Mode. Support of Designer, Verifier, and Provisioning.
- PAN Shared Gateways with shared gateway interfaces are supported by the Topology Map now. They are mapped to their privacy zones as defined in the PAN devices.
- For Palo Alto Panorama-managed Firewalls information about "rule last hit" can be retrieved via API now.
- NSX devices are supported better regarding rule matching. It now now considers traffic associated with Security Groups (SGs) specified in the NSX rule's Applied To field,
- NSX-T Distributed Firewalls (DFW) are supported in SecureChange Access Requests without activated Topology (Designer, Verifier, Provisioning).
- NSX Security Group (SG) types are fully supported now across Rule Viewer as well as Topology Map.
- Syslogs following RFC-5424 are supported for NSX devices now. '
- SecureTrack shows additional new options
- Zones and Subnet Data are analyzed in regard of configuration errors, hints are delivered
- USP violations consider now User Identity also (no subnet specification), they are validated agains a pre-defined User Network Zone.
- SecureTrack Rule Viewer has a new TQL field: "added", so rules can be searched for the date they were added
- SecureTrack Rule Viewer supports the search for 3rd party vendors (OPM) now.
- SecureTrack Rule Viewer allows to search for rules regarding Security Zones containing source or destination IP
Further improvements, as well as corrections, are included in TOS 5.3.00.
The latest version of the Tufin Orchestration Suite can be found and downloaded from the Tufin Portal: https://portal.tufin.com

