On this page
AWS Device Monitoring
Overview
Add AWS accounts to TOS as devices to monitor and manage them. TOS monitors the AWS devices for configuration and policy changes, providing ongoing visibility into configuration and compliance.
Based on the onboarding model of your choice, configure the settings for the AWS account to monitor TOS and add it as a device. See AWS device settings and adding AWS devices.
After adding the device, you can manually import additional AWS resources, migrate domains and servers, and update the device configuration. See Managing monitored devices.
AWS device settings
The table describes the settings you can configure for an AWS device in TOS.
|
Device Setting |
Description |
|---|---|
|
Device Type |
Automatically populated. |
|
Name for Display |
The name to display for the device in SecureTrack. |
|
Domain |
Domain: Available only if you have configured your system for managing multi-domains and All Domains is currently selected. Select the domain to which to add the device. The Domain can only be entered when adding a device; to change the Domain, you must migrate the device. |
|
Usage Analysis |
|
|
Enable Topology |
Collect routing information to build the
network Map. Topology options for Advanced management mode are configured when you import managed devices. |
|
VPC Import |
Determines how to import VPCs into TOS:
|
|
Cloud Organization |
Applies to Organization-based access.
|
|
Connection |
Applies to single- and cross-account access. The Access Key ID and Secret Access Key for the account from the AWS Identity and Access Management (IAM) console. |
|
ARN |
Applies to cross-account access only.
The Amazon Resource Name (ARN) identifier required to use
For more information, see Amazon AWS AssumeRole Support. |
|
Proxy |
Applies to single- and cross-account access. Connect to AWS through a proxy that requires authentication, and define the following:
|
|
Enable S3 Flow Logs |
Applies to single- and cross-account access. Use S3 flow logs for usage analysis instead of the default CloudWatch, and define the Region and S3 Bucket name. |
|
S3 Centralized Account |
Applies to cross-account access only. Seelect and define the Access Key ID and Secret Access Key as the credentials for the centralized account access. |
|
Use Hashicorp Vault |
Applies to single-account access only. Store your AWS authentication credentials in Hashicorp Vault. NOTE: Use the KV secret engine version 1. Not supported together with a proxy or Cross-Account Access (ARN).
|
|
|
|
|
|
|
| Monitoring Settings > Custom |
Define the polling frequency for SecureTrack to retrieve the configuration from each device.
|
VPC automatic import
When you add an AWS device, you can enable Automatic Import for Virtual Private Clouds (VPCs). When enabled, SecureTrack automatically detects changes to VPCs in the AWS environment (VPCs which were added, deleted, and updated), and reflects them in the device list and revision history. Changes to the VPCs are also reflected in the Map when a scheduled sync occurs or when you manually Sync the map.
When enabled, VPCs are automatically imported at 10-minute intervals.
With Automatic Import enabled, devices that were deleted from AWS are automatically deleted from the list of devices in SecureTrack, and their history is no longer available. Therefore, if your continuous integration/continuous deployment (CI/CD) pipeline regenerates VPCs, the history of the deleted VPC will not be available in the new replacement VPC. To retain revision data in SecureTrack for devices that have been deleted from your Amazon account, manually import the VPCs instead using the Import Virtual Private Cloud option.
The maximum number of VPCs for Automatic Import depends on your TOS deployment. For more information, contact Tufin Customer Support.
Add an AWS device
Add AWS devices to monitor in TOS, one device at a time or multiple devices through management accounts.
Prerequisites
Steps
-
Select SecureTrack > Monitoring > Manage Devices.
-
To add a cloud organization, select Amazon > AWS Organization, and then configure the settings for the cloud organization. Continue from step 3.
-
To add the device, either individually or through cross-account, select Amazon > AWS Account.
-
Define the settings, as described in AWS device settings, and then click Save to add the device.
Managing monitored devices
After adding a device, SecureTyou can update its configuration settings or delete the device. Based on your environment, you can also import additional AWS resources such as VPCs, Transit Gateways, and Load Balancers.
Importing and migrating AWS devices
After you select the device from the list of Monitored Devices, you can:
-
Import Virtual Private Clouds
Manually import VPCs for the device.
Make sure you receive the first policy revision from the device (you can see the revision in Compare view). This may take several minutes.
-
Import Gateway Load Balancers. In multi-domain deployments, select the domain for each load balancer.
-
Import Transit Gateways (supported for Topology only). In multi-domain deployments, select the domain for each Transit Gateway.
When imported, Transit Gateways with associated attachments are displayed on the topology map. -
Migrate (ST servers): Available in distributed deployments. Select the server where the device will be monitored and click Migrate.
-
Migrate (Domains): Available in multi-domain deployments. Select the domain where the device will be monitored and click Migrate.
Related topics


