Tufin.club
  • www.tufin.club
  • imprint
  • data privacy statement

Version update

Tufin Orchestration Suite 5.3.00

Details
Version update
Last Updated: 20 August 2026

Tufin has officially released TOS 5.3.00. It's available as GA and can be downloaded from the Tufin Portal (authentication and subscription contract required).
Some improvements of TOS 5.3.00:

  • Amazon AWS Network Firewalls are supported now in SecureTrack regarding Policies, Rule Bases as well associated Firewalls.
  • AWS Cloud WAN is supported to retrieve and model Network Function Groups (NFGs) and their service insertion configuration in the Topology Map.
  • Regarding any AWS Resource Type (generic resources) are supported by SecureTrack, i.e. support of NLBs, ALBs, private/public VPC endpoints, and more, in addition to EC2 instances, representing them as network entities in the revision, topology map, and path analysis.

  • Cisco L3 switches now can be imported to SecureTrack via Bulk Device API, as it has been possible before for routers and other L3 devices.
  • For Cisco Meraki provisioning of changes is possible for Meraki MX devices, as it is for other platforms before. Site-to-Site VPN rules are placed at the organization level, Layer 3 firewall rules at the per-network level, and group policy rules at the per-group-policy level. 

  • For Check Point, SecureTrack supports Object Usage (last hit), Rule Viewer now also displays the statistics for FQDN/domain-based objects.

  • Microsoft Entra ID is supported now as it is Active Directory (AD) on prem. Entra ID user groups can be used for topology and end-to-end access requests.
    Currently supported for Palo Alto Panorama and Strata Cloud Manager only.

  • Palo Alto Networks (PAN) Strata Cloud Manager is supporting dynamic as well as static routes in the Topology Map. 
  • Strato Cloud Manager allows automation for Strata Cloud Manager (SCM) NGFW Folders in Access Request Workflows for IPs when in Topology Mode. Support of Designer, Verifier, and Provisioning.
  • PAN Shared Gateways with shared gateway interfaces are supported by the Topology Map now. They are mapped to their privacy zones as defined in the PAN devices.
  • For Palo Alto Panorama-managed Firewalls information about "rule last hit" can be retrieved via API now. 

  • NSX devices are supported better regarding rule matching. It now now considers traffic associated with Security Groups (SGs) specified in the NSX rule's Applied To field,
  • NSX-T Distributed Firewalls (DFW) are supported in SecureChange Access Requests without activated Topology (Designer, Verifier, Provisioning).
  • NSX Security Group (SG) types are fully supported now across Rule Viewer as well as Topology Map.
  • Syslogs following RFC-5424 are supported for NSX devices now. '

  • SecureTrack shows additional new options 
    • Zones and Subnet Data are analyzed in regard of configuration errors, hints are delivered
    • USP violations consider now User Identity also (no subnet specification), they are validated agains a pre-defined User Network Zone. 
    • SecureTrack Rule Viewer has a new TQL field: "added", so rules can be searched for the date they were added
    • SecureTrack Rule Viewer supports the search for 3rd party vendors (OPM) now.
    • SecureTrack Rule Viewer allows to search for rules regarding Security Zones containing source or destination IP

Further improvements, as well as corrections, are included in TOS 5.3.00.
The latest version of the Tufin Orchestration Suite can be found and downloaded from the Tufin Portal: https://portal.tufin.com

 

 

 

 

Tufin Orchestration Suite 5.x

Details
Version update
Last Updated: 07 July 2026

After referencing the publication year in the version since 2012, Tufin now has introduced the new naming convention - starting with 5.0.00 (even if that version number has already been published in 2010/2011).

Starting with 5.0.00 Tufin will provide major versions (PGA) and hotfixes (PHF), respectively. Regarding versions this needs to be considered

  • Platform version, e.g. TOS 5, TOS 6
  • Initial release version, e.g. 5.0.00, 6.0.00 -> not for production
  • Feature version, e.g. 5.1.0, 5.2.0 with feature enhancements, bug fixes, but hardly any infrastructure changes

In version 5.1.0 some new features and options have been integrated

  • Operating System:
    TOS can now be installed on Red Hat Enterprise Linux 9 and Rocky Linux 9 operating systems

  • For Amazon AWS, TOS now supports not only SDKv1, but also SDKv2 for AWS Monitoring. SDKv1 has reached End of Support.
  • Amazon AWS RDS instances are now visible in TOS. It requires AWS SDKv2 and delivers some advantages (details here).   
  • Amazon AWS accounts can be monitored by TOS, i.e. AWS opt-in regions using assume role authorization. SDKv2 required.
  • Arista VeloCloud SD-WAN devices can now be monitored by TOS
    Please follow these links to find information about feature support in SecureTrack and SecureChange.
  • Cisco IOS-XE SDWAN (cEdge) - GRE Tunnel is supported by TOS now, more here.
  • Regarding Cisco FMC, FQDN objects are supported now in SecureTrack and SecureChange.
  • In Microsoft Azure, TOS now supports VNet flow logs when configured correctly.

  • Tufin AI support is integrated, allowing e.g. own dashboards and reports.

TOS 5.1.0 is available in the Download Section of the Tufin Portal: https://portal.tufin.com (authentication required).

 

 

 

TufinOS 4.70 available

Details
Version update
Last Updated: 11 June 2026

In April, Tufin has released TufinOS 4.70, based on Rocky Linux 8.10 latest versions. 
It includes Kernel version 4.18.0-553.89.1.el8_10.x86_64 and 105 updated RPMs. TufinOS includes now 755 RPMs in total. 

TufinOS is available for Tufin Appliances Gen 4.0 (T-800, T-1200), as well as Gen 4.5 (T-820, T-1220) and the new Gen 5.0 applicances (T-900, T-1300). 
It cannot be deployed on Gen 3.5 appliances T-1100XL and T-1100 (!)
As before, the supported hypervisor is VMware. 

TufinOS is available in the Download Section of the Tufin Portal: https://portal.tufin.com (authentication required).

 

TufinOS 4.60 available

Details
Version update
Last Updated: 31 December 2025

Tufin has released TufinOS 4.60, based on Rocky Linux 8.10 latest versions. 
It includes Kernel version 4.18.0-553.74.1.el8_10.x86_64 and 188 updated RPMs. TufinOS includes now 741 RPMs in total. 

TufinOS is available for Tufin Appliances Gen 3.5 (T-1100, T1100-XL), Gen 4.0 (T-800, T-1200), as well as Gen 4.5 (T-820, T-1220). 
Supported hypervisor is (as before) VMware. 

TufinOS is available in the Download Section of the Tufin Portal: https://portal.tufin.com

 

 

 

Tufin Orchestration Suite 25-2

Details
Version update
Last Updated: 20 November 2025

Tufin has officially released TOS R25-2. It's the second and final version of the Tufin Orchestration Suite of 2025. 
TOS R25-2 is available as GA and can be downloaded from the Tufin Portal (authentication required).
Some improvements of TOS R25-2:

Change Monitoring, Automation, and Orchestration

  • SecureTrack
    Legacy reports in SecureTrack now use a 64-bit process, delivering better performance esp. for devices with a large number of rules and objects

  • SecureTrack
    A Rule Optimizer allows to deliver hints how to tighten the rule base, based on real-time traffic logs, for AWS, Azure NSGs and Zscaler ZIA

  • SecureTrack
    The Topology Map now supports generic policy-based routing (PBR) in the Path Analysis. PBR rules of monitored devices can be defined, edited, monitored and mapped. 

  • SecureChange
    The Rule Recertification Workflow has got some improvements, including a better UI and certification history

  • SecureChange
    The Designer now has a new interface for Access Requests involving changes on OPM devices, Azure NSGs, Azure firewalls, Zscaler ZIA, Huawei, Versa and others

Devices and Platforms

  • TufinOS
    TufinOS is now available as an Amazon Machine Image (AMI) in the AWS Marketplace

  • Azure
    Starting with R25-2 PHF1, Microsoft Azure Subscriptions for a given Tenant can be onboarded very simple, allowing Azure Subscriptions to be managed and monitored in an easy way

  • Azure
    Starting with R25-2 PHF2, Azure VNET is going to be imported automatically, enabled for individual subscriptions

  • Azure and OPM devices
    Change automation is possible for access requests involving Azure NSGs and OPM devices

  • AWS
    Management of AWS accounts at organizational level is possible now, also automatically

  • Cisco
    Cisco ACI endpoint security groups (ESGs) are supported now in object and contract comparisons, change tracking, and ESG-based path analysis in the Topology Map

  • Cisco
    For Cisco FMC Tos now takes AppID and URL category into account, improving also path analysis

  • Cloud
    Checking compliance with USPs is now also possible for AWS, GCP and Azure network security groups installed on a NIC

  • Palo Alto
    Palo Alto Networks external dynamic lists (PAN EDLs) are supported now, alloing e.g. filtering by IP in the Rule Viewer

  • Zscaler
    Zscaler ZIA is now integrated into SecureChange, allowing automatic Target selection in Access Requests as well as Risk Analysis and the use of Designer and Verifier

Administration

  • Installation 
    When installing TufinOS on VMware ESXi, the disk setup considers the separation of ETCD as part of the configuration workflow

  • Updates
    When installing a patch, from now on it isn't necessarily the complete package that is installed. Tufin has optimized TOS for being able to receive (smaller) hotfixes also

  • Remote Collector
    From now on, Remote Collectors automatically recover after disaster recovery switchover and restore of the central cluster

Further improvements, as well as corrections, are included in R25-2.
The latest version of the Tufin Orchestration Suite can be found at the Tufin Portal: https://portal.tufin.com

 

 

 

 

 

Tufin Orchestration Suite 25-1

Details
Version update
Last Updated: 15 April 2025

Tufin has officially released TOS R25-1. It's the first version of the Tufin Orchestration Suite of 2025. 
TOS R25-1 is available as GA and can be downloaded from the Tufin Portal (authentication required).
Some improvements of TOS R25-1:

Change Monitoring, Automation, and Orchestration

  • SecureTrack
    When looking at the revision history, comments can be added now. This feature is available for GCP, Meraki, Arista and other OPM devices.

  • SecureTrack
    In Cloud environments, syslogs via TCP can be encrypted with TLS now. 

  • SecureTrack
    Based on Network Configuration, a mapping of zones to interfaces (MZTI) is supported now. This is useful when working with USPs. 

  • SecureChange
    The user experience for "generic workflows" has been improved by introducing a new design and a panel for "Ticket Properties". 

  • SecureChange
    It's possible to automate userID from Network Tickets to Next Generation Firewalls like Panorama and FortiManager

  • SecureChange
    Further improvements in SecureChange SLA allow to pause, resume, and reset the SLA of tickets. Non-handler users can be excluded from the SLA, so the time used by handler teams can be calculated more accurate. 

  • SecureApp
    Applications may now include connections using LDAP user groups from specified networks.

  • TufinMate
    Tufin's AI Assistant is now generally available. It supports in troubleshooting network issues, opening Access Request tickets via Microsoft Teams using natural language and Microsoft Copilot is supported to get questions about Topology. 

Devices and Platforms

  • Arista EOS
    The Linux-based network operation system for Clouds is officially supported now. It's supported for Topology (e.g. VxLAN, MPLS, VPN) for IPv4 as well as IPv6, for USP as well as Change Automation.

  • AWS
    Unused Security Group (SG) rules across AWS environments are recognized now, so rule analytics, last-hit information in Rule Viewer as well as Security Best Practice reports are available. 

  • Azure
    Using USPs is possible for Azure Network Security Groups (NSGs) now. This might increase the security level of the cloud.

  • Azure
    Azure Network Security Groups (NSGs) with Application Security Groups (ASGs) are supported by the Designer in Access Request Workflows now. So changes can be automated, too. 

  • Check Point
    Check Point Last Hit Information is shown in the Rule Viewer for objects in rules. Therefore it's possible now to identitfy unused objects in rules. 

  • Cisco Meraki
    Automatic Target selection in SecureChange is supported now for Cisco Meraki, including USP checks before implementation. 

  • OPM
    OPM (Open Policy Management) devices can be integrated into TOS. Now, in Access Request Workflows Designer support for this kind of devices has been added. 

  • VMware
    NSX-T Gateway Firewalls can be integrated to SecureTrack now. So the policies and their revisions are visible, shown in Topopology, as well as checked against USPs. 

  • VMware
    NSX-T in Azure VMware Solution (AVS) is supported. It allows to extend the on-premis VM environment zu Microsoft Azure. 

  • Zscaler Internet Access (ZIA)
    ZIA devices are supported by SecureTrack now. They are shown in SecureTrack Topology (including VPN) and NGFW objects like URL categorization as well as FQDNs are supported. 

  • Zscaler Internet Access (ZIA)
    SecureTrack Rule Viewer shows rules, last-hit information. Additionally, reports are possible to identify unused rules and objects.

Tufin Appliances

  • Tufin G4 (T800 / T1200) & G4.5 (T820 / T1220) appliances can be connected to two different switches to provide them with Link Redundancy. 


Further improvements, as well as corrections, are included in R25-1.
The latest version of the Tufin Orchestration Suite can be found at the Tufin Portal: https://portal.tufin.com

 

 

 

Page 1 of 6
  • Start
  • Prev
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • Next
  • End
Bootstrap is a front-end framework of Twitter, Inc. Code licensed under MIT License. Font Awesome font licensed under SIL OFL 1.1.