On this page
What's New in TOS 5
The list below will sometimes include upcoming versions that are not yet released. Check available versions.
New naming convention
Starting with 5.0.00, we are introducing a new naming convention for TOS. Platform version replaces major version and feature version replaces minor versions of type PGA and PHF. As new features and bug fixes are made available, they are released as new feature versions within that platform version.
-
Platform version: Includes many versions - an initial release version, a number of feature versions, plus unplanned versions if and when needed. Platform version examples: TOS 5, TOS6.
-
Initial release version: The first version, not for production deployment. Meant to test and verify that the new TOS infrastructure deploys and runs smoothly in a lab environment. It contains infrastructure updates and bug fixes, but little or no new features. Examples: 5.0.00, 6.0.00.
-
Feature versions: These versions are production-ready. They contain feature enhancements and bug fixes with little or no infrastructure changes. They will typically be spaced out around six weeks apart. Updating to a feature version within the same platform version generally takes less time than updating to a new platform version. Examples: 5.1.0, 5.2.0, 6.1.00.
The previous naming convention (e.g. R25-2 PHF3.0.0) will continue be used for R25-2 and earlier versions. For more information, see the Tufin Customer Portal
5.4.00 (upcoming release)
To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.
|
Feature |
Description |
|---|---|
|
AWS Network Firewall - Cleanup & Optimization (Last Hit & Rule Optimizer) |
When managing AWS Network Firewall, you can now identify unused rules and act on optimization recommendations directly within TOS. Last hit data and rule optimizer support have been extended to AWS Network Firewall, and last hit data for these rules is shown in Rule Viewer. Benefits:
|
|
Audit Usage Support for any AWS Resource, and Prefix Lists in SGs |
The license usage report now counts any resource type attached to SGs beyond VMs, including NLBs, ALBs, VPC Endpoints, etc. as part of the CLOUD-VM type. In addition, Prefix lists are now supported as part of the SG rules in TOS, and are supported across the suite. Each adopted managed service protected by an SG is counted as one billable VM, and SG rules that reference a managed prefix list are modeled as a network group of the list's entry CIDRs, so all downstream views, reports, and analysis resolve them correctly. Benefits:
|
|
Block policy by App ID in USP |
You can now enforce application identity-specific blocking directly within USP policies. App ID is now supported in blocking policies within the Unified Security Policy. Benefits:
|
|
Broadcom NSX VCF (NSX 9.1) Support |
When migrating to VMware Cloud Foundation (VCF) with NSX 9.1 you can now use TOS without losing any functionality. Benefits:
|
|
Dynamic Routes Support for SCM NGFW (IPv4 & IPv6) |
SCM NGFW environments now benefit from accurate dynamic and static route resolution in topology, including IPv6. Routing data is retrieved directly from local gateway firewalls, improving the reliability of network path analysis across SCM-managed deployments. Additionally, SecureTrack now retrieves static routes from the local gateway firewalls instead of from SCM. Benefits:
|
|
Filter Rules by Device Status in TQL (Rule Viewer and GQL API) |
You can now filter rules in Rule Viewer and GQL API results by device status—enabled or disabled—making it easier to focus on active devices. This eliminates the need to manually exclude inactive device rules from policy analysis. Additionally, device status is exposed as a field in the GQL API rule projection. Benefits:
|
|
FortiManager Cloud Support and Integration |
When managing FortiGate firewalls through FortiManager Cloud, you can now manage these devices' policies through TOS without remaining on on-premises FMG appliances. TOS delivers the same visibility, topology, compliance, and automation capabilities available for on-premises FortiManager. Additionally, TOS supports the cloud-based FortiCloud authentication. Benefits:
|
|
FortiManager Global Object Support |
When using FortiManager with global-only object policies, you can now automate network changes end-to-end. SecureChange provisions new objects directly as global objects in FortiManager, and leverages existing global objects as part of the change process. Additionally, SecureChange provisions services and object groups as global objects, and synchronizes them from the Global ADOM to the assigned Local ADOMs. Benefits:
|
|
Modify Groups for Check Point IPv6 and Dual Stack Objects |
TOS now supports IPv6 and dual stack network objects for Check Point, and IPv6 for NSX, within the modify group workflow. You can create and manage IPv6, IPv4, and dual stack objects as part of standard group modification change requests, removing the need for manual intervention outside of the workflow. This update brings IPv6 environments into alignment with existing group management automation capabilities for Check Point and NSX. Benefits:
|
|
NGFW Security Profile Group and Log Forwarding Profile Violations in USP |
You can now use USP violations to detect rules that violate your organizational security policies by missing a Security Profile Group or Log Forwarding Profile. To do this, configure the USP cell property to raise a violation when a Security Profile Group or Log Forwarding Profile is missing on NGFW rules. Benefits:
|
|
Palo Alto Predefined DNS Application Recognition in Topology Map |
Topology path analysis now correctly identifies Palo Alto rules using predefined DNS applications. The TOS DNS application group has been updated to include Palo Alto's predefined DNS apps, resolving a gap that caused those rules to go unrecognized. Benefits:
|
|
Return to Last TQL Query in Rule Viewer |
You no longer lose context when navigating away from Rule Viewer while it presents an already defined query. The last TQL query and results are automatically restored when you return to the view within the same session. Benefits:
|
|
Revert Changes via API in SecureApp |
It is now possible to revert, via API, changes made to a SecureApp application connection (add/edit) since the last ticket was created. Benefits:
|
|
Rule Recertification for OPM Devices |
Rule Recertification now covers most supported devices*, closing a gap that left cloud and OPM device rules outside the standard recertification process. Additionally, you can submit and handle recertification tickets for all rules visible in Rule Viewer (excluding global rules). *Rule recertification support was added to the following devices:
Benefits:
|
|
Segmentation Intelligence Configuration Page |
You can now configure Segmentation Intelligence analysis directly from a dedicated settings page. Configurable items, including reporting mode, subnet volume limits, and zone, model, and device exclusions, are now accessible without requiring back-end intervention, and apply to the next analysis run. Benefits:
|
|
Support FortiManager VDOMs Renaming and Moves Between ADOMs |
You no longer need to manually re-import FortiManager firewalls and VDOMs after device renaming or moves between ADOMs. TOS now automatically detects these changes and follows these moves, preserving revision history, change tracking, and automation continuity. Benefits:
|
|
TQL Query by Violations Count |
You can now search for rules in Rule Viewer by USP violations count using TQL, making it faster to identify and prioritize the rules causing the most policy violations. This targeted query capability enables you to address compliance gaps quickly and accurately. Benefits:
|
|
Topology Support for Source Domain in Path Analysis |
When managing networks with overlapping IP address spaces you can now specify a source domain in Path Analysis, ensuring the correct network is targeted. A new optional Source Domain field appears in the Topology Map when overlapping IP mode is enabled and the default domain view is active. Benefits:
|
|
Topology for Illumio & Guardicore - Enforcement Mode Support |
Path analysis in SecureTrack now accurately reflects real-world enforcement for Guardicore and Illumio assets, so you can trust whether traffic is actually allowed or blocked. Each microsegmentation asset in the path now shows its enforcement mode (Visibility-only, Monitoring, Selective Enforcement, or Full Enforcement), the resulting allow/block decision, and the specific rule that drove it. Additionally, you can run a what-if analysis that overrides the actual asset state during a path query and treats all microsegmentation assets as managed and fully enforced, so the resulting allow/block decision reflects a fully enforced hypothetical rather than current reality. Benefits:
|
|
USP violations for micro-segmentation rules by asset tags |
When using micro-segmentation solutions, you can now enforce the Unified Security Policy against tag-based assets residing inside rules. Additionally, USP security zones that include tag strings can calculate violations by matching zone tags against object tags and tagged assets in security rules. Benefits:
|
|
Visibility & Topology Support for Panorama Target Field |
You can now see exactly which devices a Panorama rule targets, with accurate shadowing analysis and topology calculations that respect the Target field. TOS reads and models the Panorama rule target field across Rule Viewer, Compare Revision, shadowing detection, and traffic path simulation in topology. Benefits:
|
5.3.01
Bug fix only. See 5.3.00 for feature enhancements.
5.3.00
To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.
|
Feature |
Description |
|---|---|
|
EntraID user identify |
TOS now supports Microsoft Entra ID as a user identity provider, alongside on-prem Active Directory - so Entra ID user groups can be used for topology-based troubleshooting and end-to-end access request automation. Currently supported for Panorama and Strata Cloud Manager. Benefits:
|
|
Strata Cloud Manager dynamic routes |
Dynamic routes are incorporated into the topology map alongside static routes, enabling accurate end-to-end path analysis, troubleshooting, and automated change target selection in SCM NGFW environments that use dynamic routing protocols. Benefits:
|
|
NSX RFC-5424 syslog format |
TOS now supports the RFC-5424 syslog format for NSX devices, ensuring traffic hit logs are correctly parsed and revisions are accurately tracked. Benefits:
|
|
PAN Shared gateways |
The topology map now retrieves shared gateway interfaces and correctly maps them to their policy zones as defined on the Palo Alto device. This ensures accurate network map, correct firewall target selection in Designer, and full policy evaluation for Shared GW-connected network segments. Benefits:
|
|
User identity USP violations |
When calculating USP violations, rules which include User Identity (and no subnet specification), are now validated against a dedicated, pre-defined User Network Zone. Benefits:
|
|
NSX-T DFW access request without topology |
Access request tickets involving NSX-T DFW can now be submitted with topology mode off, including Verifier, Designer, and Provisioning. Benefits:
|
|
Strata Cloud Manager IP-based access request automation |
Tufin extends the access request automation workflow to Strata Cloud Manager (SCM) NGFW Folders, operating in topology mode. Verifier checks whether IP-based traffic is already permitted by existing SCM rules. Designer suggests rule creation or modification against the correct SCM folder in the policy hierarchy, respecting snippet visibility (read-only). Provisioning automatically commits approved changes directly to SCM. Benefits:
|
|
AWS Network Firewall |
TOS now provides policy visibility and topology support for AWS Network Firewall. Support includes AWS Firewall Policies, their rulesets, and associated firewalls. Search for rules in Rule Viewer for troubleshooting purposes, identify USP violations for rules that do no comply with internal and industry regulations, and troubleshoot network access in the topology map to see if it is allowed or blocked. Benefits:
See SecureTrack features by vendor - AWS Network Firewalls and AWS Network Firewall import. |
|
Segmentation insights |
Analyzes existing zone and subnet data, identifies zone configuration errors, and recommends actionable fixes and next steps. Benefits:
|
|
Search rules by date added |
View and search for rules in Rule Viewer by the date they were added to TOS, using the timeAdded TQL field. Benefits:
See TQL fields for Rule Viewer - timeAdded and Rule Viewer Overview. |
|
Search rules by vendor name |
Search for 3rd party OPM rules in Rule Viewer by vendor name. Benefits:
|
|
Search rules by network zone |
Search for rules in Rule Viewer by the network security zone(s) containing their source or destination. Benefits:
|
|
AWS Cloud WAN |
Tufin extends AWS Cloud WAN support to retrieve and model Network Function Groups (NFGs) and their service insertion configuration in the Topology Map - including the NFGs defined in the core network, the segments and attachments associated with them, and the send-to / send-via actions that steer traffic through inspection VPCs. This lets TOS represent the security appliances inserted into the Cloud WAN path, so path analysis reflects the actual inspection hop and SecureChange identifies the correct enforcement target for access requests that traverse NFGs across AWS regions. Benefits:
See AWS Cloud WAN import. |
|
Cisco Meraki Provisioning |
You can now provision approved changes from SecureChange Access Requests directly onto Meraki MX devices, the same way other supported firewall platforms work today. Approved access requests are translated into the correct Meraki construct, depending on rule type — Site-to-Site VPN rules at the organization level, Layer 3 firewall rules at the per-network level, and group policy rules at the per-group-policy level — and pushed to the target MX devices. Implicit IPv4 hosts and subnets are supported as sources and destinations for all three rule types and provisioning is gated by topology being on to make sure each rule lands in the right place. Benefits:
|
|
Cisco L3 Switch bulk API |
You can now onboard Cisco L3 switches into SecureTrack via the bulk device API, the same way routers and other L3 devices are onboarded today. Benefits:
|
|
NSX' applied to' field in path analysis |
For path analysis involving NSX devices, the rule-matching logic now considers traffic associated with Security Groups (SGs) specified in the NSX rule's Applied To field. Benefits:
|
|
NSX SG VM name, tag and scope |
Visibility added for two additional NSX Security Group (SG) types:
These SGs are now fully supported across Rule Viewer and topology, and can be leveraged by automation workflows, enabling traffic associated with these groups to be accurately analyzed. Benefits:
|
|
Panorama last hit via API |
A new feature flag for Palo Alto Panorama-managed firewalls that retrieves rule last-hit data using the Panorama API instead of syslogs. When enabled, the Rule Viewer’s last hit indication is based on the timestamp returned by the API. Benefits:
See Configuring TOS - Collect rule last hit information from Panorama devices. |
|
Check Point FQDN last hit |
Extends the existing Check Point object-usage (last-hit) collection and Rule Viewer display to include FQDN/domain-based objects. FQDN objects are now processed by the same object-usage analysis pipeline used for other Check Point objects, so their last-hit data is collected and surfaced consistently in the Rule Viewer. Supported across Check Point CMA, SMC, and Smart-1. Benefits:
|
|
AWS SG modeling on all resource types |
SecureTrack discovers and models security groups applied to any AWS resource type (generic resources) - NLBs, ALBs, private/public VPC endpoints, and more, in addition to EC2 instances, representing them as network entities in the revision, topology map, and path analysis. Benefits:
|
5.2.02
Bug fix only. See 5.2.00 for feature enhancements.
5.2.01
Bug fix only. See 5.2.00 for feature enhancements.
5.2.00
To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.
|
Feature |
Description |
|---|---|
|
Zone API |
A new API to create, update and retrieve SecureTrack zones. Benefits:
|
|
USP Viewer Scroll Bar |
Vertical and horizontal scroll bars appear when needed in the USP Viewer. Benefits:
|
|
View Reports Permissions |
SecureChange admins can define for each user whether they can generate reports on all tickets or only their own. Benefits:
|
|
Check Point License Consumption API |
With this API, you can enable or disable specific Check Point module gateways that have been decommissioned or are standby / test devices, from license counting. You only pay for the devices that deliver value; disabled devices do not consume a license but remain visible in TOS. Benefits:
|
|
PAN IPv6 Support In Topology Map |
TOS now supports IPv6 interfaces and routing (static and dynamic) for Palo Alto Networks devices managed by Panorama, across both advanced routing and legacy routing modes. IPv6 traffic is included in topology mapping, path analysis, and rule matching. In addition, SecureChange access requests now support IPv6 for automatic target selection on PAN devices. Benefits:
|
|
Push Tufin-Only Changes to Panorama |
As part of 'Commit Now' and 'Change Window' in SecureChange, TOS performs two actions in Panorama: 'Commit to Panorama' (can be scoped to Tufin user changes) and 'Push to Devices' (previously always pushed all user changes). The new enhancement lets you configure the 'Push to Devices' scope — either all Panorama users or Tufin user changes only. Benefits:
|
|
Push changes to DGs only |
You can now configure TOS to push only device group policy changes to Panorama-managed firewalls, without pushing Panorama templates. Benefits:
|
|
Guardicore and Illumio Microsegmentation Topology |
TOS topology now includes microsegmentation devices in path analysis. When source/destination is a managed asset, TOS detects and shows the microsegmentation device on the path with its matching rules (including tag-based, tag group, and alert rules). Supports same-subnet and behind-cloud scenarios. You can select Guardicore/Illumio assets as path query endpoints. Benefits:
|
|
Zscaler Designer Objects |
Designer now suggests updating and creating groups as needed on Zscaler ZIA instead of raw embedded IP addresses or services, Benefits:
|
|
Guardicore and Illumio Microsegmentation in Rule Viewer |
You can now get deep, tag-aware visibility into Guardicore policies in the Rule Viewer- including resolving tags to assets, filtering rules by asset tags, IPs or names, and tracking rule history changes triggered by asset tag updates. Benefits:
|
|
Palo Alto Strata Cloud Manager |
You can now detect USP violations, view topology run path analysis for Strata Cloud Manager NGFW policies. Benefits:
|
|
Static NSX-T Groups |
The group modification workflow now lets you add/remove objects from static NSX-T security groups or create new groups, and provision the changes seamlessly. Benefits:
|
5.1.01
Bug fix only. See 5.1.00 for feature enhancements.
5.1.00
This is the first GA release of TOS 5
To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.
|
Feature |
Description |
|---|---|
|
Arista VeloCloud |
VeloCloud SD-WAN devices can now be monitored by TOS, bringing them into the unified control plane used to manage and monitor firewalls, routers, cloud resources, and hybrid environments. Security and traffic policies from VeloCloud are visible, validated, and governed like all other network devices. Benefits:
See SecureTrack features and SecureChange features for Arista VeloCloud. |
|
TufinAI Executive Dashboard |
TOS administrators can now to craft their own dashboards and define charts to present unique and customized aggregations over security rules and SecureChange tickets. Based on specifications given in natural language, AI-generated code fetches filtered data from TOS and renders it into charts and reports. Benefits:
|
| Cisco FMC - FQDN |
FQDN objects are now supported for Cisco FMC including visibility, topology, compliance, and access request automation. Visibility into FQDN content is supported in the Rule Viewer and Compare Revisions. You can run path analysis queries by using FMC FQDN objects and identify allowing/blocking rules. You can automate access requests that include FQDN objects where rules have to be changed / added, including target selection, design, verification and provisioning. Benefits
See SecureTrack and SecureChange features for Cisco FMC. |
| Azure Usage Analysis |
TOS now supports VNet flow logs, and Azure resource specific log analytics collection to provide cleanup and optimization insights for Azure NSGs and firewalls. Benefits:
|
|
RHEL 9 / Rocky Linux 9 |
TOS can now be installed on Red Hat Enterprise Linux 9 and Rocky Linux 9 operating systems Benefits:
See TOS release history. |
|
Monitor AWS using SDK2 |
Amazon's AWS SDK v1 has reached end of support, and will not receive further security or new region updates. Therefore, for all new installations, TOS will monitor AWS using SDK v2. For upgrades, from older installations, TOS will continue using SDK v1. By the end of the year, SDK v2 will become the default both for clean installs and upgrades from previous versions. All TOS enhancements for AWS added in TOS 5 and later will require AWS SDK v2. Therefore, we recommend moving to AWS SDK v2. Benefits:
|
|
AWS RDS Visibility & Policy Support |
AWS RDS instances are now visible in TOS. Security Group policies applied to RDS endpoints can be viewed, searched by IP, and included in topology and path analysis. TOS retrieves AWS RDS instances and associates their security groups, modeling them as network entities. RDS instances are counted as licensed VM entities. This feature requires AWS SDK v2. Benefits:
|
|
AWS Opt-in Regions By Assume Role |
TOS now supports monitoring AWS opt-in regions using assume role authorization. TOS can monitor the accounts and resources deployed in the opt-in regions by AWS using assume role authorization. Requires enablement of AWS SDK2. Otherwise, a local user must be used for authentication and authorization. This feature requires SDK v2. Benefits:
|
|
Cisco IOS-XE SDWAN (cEdge) - GRE Tunnel support |
Cisco IOS-XE SDWAN (cEdge) - GRE Tunnel support
|
5.0.00
This is the initial release, not for production.
To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.
|
Feature |
Description |
|---|---|
|
Initial Release |
5.0.00 is the first version of the TOS 5 platform version. It is not for production deployment but rather meant to test and verify that the new TOS infrastructure deploys and runs smoothly in a lab environment. Generally first versions of platform versions contains infrastructure updates and bug fixes, but little or no new features. Subsequent versions starting with 5.1.00 will contain new features. |
|
New Naming Convention |
Starting with 5.0.00, we are introducing a new naming convention for TOS. Platform version replaces major version and feature version replaces minor versions of type PGA and PHF. As new features and bug fixes are made available, they are released as new feature versions within that platform version. The previous naming convention (e.g. R25-2 PHF3.0.0) will continue be used for R25-2 and earlier versions only.
For more information, see the Tufin Customer Portal |
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague