What's New in TOS 5

The list below will sometimes include upcoming versions that are not yet released. Check available versions.

New naming convention

Starting with 5.0.00, we are introducing a new naming convention for TOS. Platform version replaces major version and feature version replaces minor versions of type PGA and PHF. As new features and bug fixes are made available, they are released as new feature versions within that platform version.

  • Platform version: Includes many versions - an initial release version, a number of feature versions, plus unplanned versions if and when needed. Platform version examples: TOS 5, TOS6.

  • Initial release version: The first version, not for production deployment. Meant to test and verify that the new TOS infrastructure deploys and runs smoothly in a lab environment. It contains infrastructure updates and bug fixes, but little or no new features. Examples: 5.0.00, 6.0.00.

  • Feature versions: These versions are production-ready. They contain feature enhancements and bug fixes with little or no infrastructure changes. They will typically be spaced out around six weeks apart. Updating to a feature version within the same platform version generally takes less time than updating to a new platform version. Examples: 5.1.0, 5.2.0, 6.1.00.

The previous naming convention (e.g. R25-2 PHF3.0.0) will continue be used for R25-2 and earlier versions. For more information, see the Tufin Customer Portal

5.4.00 (upcoming release)

To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.

Feature

Description

AWS Network Firewall - Cleanup & Optimization (Last Hit & Rule Optimizer)

When managing AWS Network Firewall, you can now identify unused rules and act on optimization recommendations directly within TOS. Last hit data and rule optimizer support have been extended to AWS Network Firewall, and last hit data for these rules is shown in Rule Viewer.

Benefits:

  • Reduces risk of retaining unused or redundant rules in AWS Network Firewall environments

  • Lowers manual effort required to identify stale AWS firewall rules

  • Improves accuracy of AWS policy cleanup decisions using last hit data

  • Strengthens security posture by reducing unnecessary attack surface in AWS deployments

Audit Usage Support for any AWS Resource, and Prefix Lists in SGs

The license usage report now counts any resource type attached to SGs beyond VMs, including NLBs, ALBs, VPC Endpoints, etc. as part of the CLOUD-VM type.

In addition, Prefix lists are now supported as part of the SG rules in TOS, and are supported across the suite. Each adopted managed service protected by an SG is counted as one billable VM, and SG rules that reference a managed prefix list are modeled as a network group of the list's entry CIDRs, so all downstream views, reports, and analysis resolve them correctly.

Benefits:

  • Eliminates blind spots in AWS security policies

  • Reduces false positives in policy analysis

  • Improves accuracy of end-to-end connectivity tracing across modern AWS architectures

  • Strengthens security posture by ensuring all AWS Security Group policies are visible and auditable

Block policy by App ID in USP

You can now enforce application identity-specific blocking directly within USP policies. App ID is now supported in blocking policies within the Unified Security Policy.

Benefits:

  • Strengthens enforcement of application-level segmentation policies

  • Reduces risk of unwanted application traffic passing through

  • Improves accuracy of USP blocking rules by targeting specific applications

Broadcom NSX VCF (NSX 9.1) Support

When migrating to VMware Cloud Foundation (VCF) with NSX 9.1 you can now use TOS without losing any functionality.

Benefits:

  • Eliminates compatibility blockers when migrating to Broadcom's mandatory VCF architecture

  • Reduces risk of losing NSX policy management coverage during the required VCF migration

  • Accelerates migration timelines by ensuring TOS is ready before the November deadline

  • Maintains continuity of security operations without capability regression on NSX 9.1

Dynamic Routes Support for SCM NGFW (IPv4 & IPv6)

SCM NGFW environments now benefit from accurate dynamic and static route resolution in topology, including IPv6. Routing data is retrieved directly from local gateway firewalls, improving the reliability of network path analysis across SCM-managed deployments. Additionally, SecureTrack now retrieves static routes from the local gateway firewalls instead of from SCM.

Benefits:

  • Improves accuracy of path analysis for SCM-managed environments

  • Reduces risk of misconfigured or incomplete routing data affecting policy decisions

  • Strengthens IPv6 network visibility for SCM NGFW deployments

  • Eliminates gaps in route resolution caused by retrieving data from SCM instead of local gateways

Filter Rules by Device Status in TQL (Rule Viewer and GQL API)

You can now filter rules in Rule Viewer and GQL API results by device status—enabled or disabled—making it easier to focus on active devices. This eliminates the need to manually exclude inactive device rules from policy analysis. Additionally, device status is exposed as a field in the GQL API rule projection.

Benefits:

  • Reduces noise in rule queries by excluding disabled devices

  • Improves accuracy of policy analysis by scoping results to active devices only

  • Accelerates troubleshooting by surfacing device status directly in rule data

  • Reduces the effort required to identify and exclude rules from inactive devices

FortiManager Cloud Support and Integration

When managing FortiGate firewalls through FortiManager Cloud, you can now manage these devices' policies through TOS without remaining on on-premises FMG appliances. TOS delivers the same visibility, topology, compliance, and automation capabilities available for on-premises FortiManager. Additionally, TOS supports the cloud-based FortiCloud authentication.

Benefits:

  • Eliminates integration blockers when migrating to FortiManager Cloud, so you gain the cloud benefits of agility and flexibility

  • Reduces risk of policy blind spots in unmanaged Fortinet environments

  • Increases agility when adopting Fortinet's cloud-management platforms

  • Strengthens security posture by extending existing policy management coverage to FortiCloud-managed devices

FortiManager Global Object Support

When using FortiManager with global-only object policies, you can now automate network changes end-to-end. SecureChange provisions new objects directly as global objects in FortiManager, and leverages existing global objects as part of the change process. Additionally, SecureChange provisions services and object groups as global objects, and synchronizes them from the Global ADOM to the assigned Local ADOMs.

Benefits:

  • Eliminates manual effort of change implementation caused by the need to use local objects

  • Accelerates change delivery when you enforce global object policies

  • Reduces risk of policy inconsistency across Local ADOMs through automatic synchronization

  • Lowers operational overhead when managing large FortiManager deployments

Modify Groups for Check Point IPv6 and Dual Stack Objects

TOS now supports IPv6 and dual stack network objects for Check Point, and IPv6 for NSX, within the modify group workflow. You can create and manage IPv6, IPv4, and dual stack objects as part of standard group modification change requests, removing the need for manual intervention outside of the workflow. This update brings IPv6 environments into alignment with existing group management automation capabilities for Check Point and NSX.

Benefits:

  • Extends group modification workflows to IPv6 and dual stack objects

  • Reduces manual effort for Check Point and NSX IPv6 object management

  • Supports modern network environments in automated change processes

NGFW Security Profile Group and Log Forwarding Profile Violations in USP

You can now use USP violations to detect rules that violate your organizational security policies by missing a Security Profile Group or Log Forwarding Profile. To do this, configure the USP cell property to raise a violation when a Security Profile Group or Log Forwarding Profile is missing on NGFW rules.

Benefits:

  • Reduces exposure to risky network traffic flows due to missing NGFW security profile definitions

  • Improves compliance posture by surfacing incompliant rules automatically using USP violations

  • Eliminates manual rule report review to identify missing dynamic security controls

  • Strengthens audit evidence with continuous automated detection of NGFW policy gaps

Palo Alto Predefined DNS Application Recognition in Topology Map

Topology path analysis now correctly identifies Palo Alto rules using predefined DNS applications. The TOS DNS application group has been updated to include Palo Alto's predefined DNS apps, resolving a gap that caused those rules to go unrecognized.

Benefits:

  • Reduces troubleshooting time caused by unrecognized DNS rules in traffic path analysis

  • Improves accuracy of topology-based policy analysis for Palo Alto environments

  • Eliminates false negatives when validating DNS traffic paths through Palo Alto devices

Return to Last TQL Query in Rule Viewer

You no longer lose context when navigating away from Rule Viewer while it presents an already defined query. The last TQL query and results are automatically restored when you return to the view within the same session.

Benefits:

  • Reduces time lost re-entering queries after navigating away

  • Accelerates rule investigation workflows by preserving session context

  • Improves analyst efficiency during multi-step policy reviews

Revert Changes via API in SecureApp

It is now possible to revert, via API, changes made to a SecureApp application connection (add/edit) since the last ticket was created.

Benefits:

  • Reduces manual effort for reverting changes across large SecureApp deployments

  • Accelerates remediation workflows through API-driven automation

  • Lowers operational overhead when managing hundreds of SecureApp applications

Rule Recertification for OPM Devices

Rule Recertification now covers most supported devices*, closing a gap that left cloud and OPM device rules outside the standard recertification process. Additionally, you can submit and handle recertification tickets for all rules visible in Rule Viewer (excluding global rules).

*Rule recertification support was added to the following devices:

  • Arista Networks EOS

  • Arista Networks VeloCloud

  • AWS Network Firewall

  • Cisco Meraki

  • Google Cloud Platform VPC Firewall

  • HP Aruba CX 10000

  • HP Aruba EdgeConnect (SilverPeak)

  • Huawei Firewall

  • Microsoft Azure Network Security Groups (NSG)

  • Microsoft Azure Azure Firewall Policies

  • Palo Alto Strata Cloud Manager

  • Versa Networks SD-WAN

  • VMware NSX-T Gateway

  • Stormshield Firewall

  • Zscaler ZIA Cloud Firewall

Benefits:

  • Reduces compliance gaps by covering OPM device rules in recertification workflows

  • Strengthens audit readiness with consistent recertification coverage across all supported device types

  • Reduces risk of stale rules persisting beyond their certified lifespan

Segmentation Intelligence Configuration Page

You can now configure Segmentation Intelligence analysis directly from a dedicated settings page. Configurable items, including reporting mode, subnet volume limits, and zone, model, and device exclusions, are now accessible without requiring back-end intervention, and apply to the next analysis run.

Benefits:

  • Reduces manual effort to configure segmentation analysis

  • Accelerates time-to-insight by enabling you to tune analysis parameters

  • Strengthens segmentation posture by ensuring the right scope and reporting mode are applied before each run

Support FortiManager VDOMs Renaming and Moves Between ADOMs

You no longer need to manually re-import FortiManager firewalls and VDOMs after device renaming or moves between ADOMs. TOS now automatically detects these changes and follows these moves, preserving revision history, change tracking, and automation continuity.

Benefits:

  • Ensures business continuity after such changes

  • Eliminates time-consuming manual re-import overhead

  • Reduces operational burden for large-scale FortiManager deployments with hundreds of firewalls

  • Preserves continuous revision history to maintain audit and compliance readiness

TQL Query by Violations Count

You can now search for rules in Rule Viewer by USP violations count using TQL, making it faster to identify and prioritize the rules causing the most policy violations. This targeted query capability enables you to address compliance gaps quickly and accurately.

Benefits:

  • Reduces time spent manually identifying high-risk rules

  • Accelerates remediation by surfacing the most violating rules first

  • Improves compliance posture by enabling systematic handling of policy violations

  • Reduces operational effort for policy cleanup prioritization

Topology Support for Source Domain in Path Analysis

When managing networks with overlapping IP address spaces you can now specify a source domain in Path Analysis, ensuring the correct network is targeted. A new optional Source Domain field appears in the Topology Map when overlapping IP mode is enabled and the default domain view is active.

Benefits:

  • Eliminates ambiguous path analysis results caused by duplicate IP address ranges

  • Reduces troubleshooting time for MSSPs and service providers managing multiple customer networks

  • Improves accuracy of path resolution in overlapping IP topologies without disrupting existing workflows

Topology for Illumio & Guardicore - Enforcement Mode Support

Path analysis in SecureTrack now accurately reflects real-world enforcement for Guardicore and Illumio assets, so you can trust whether traffic is actually allowed or blocked. Each microsegmentation asset in the path now shows its enforcement mode (Visibility-only, Monitoring, Selective Enforcement, or Full Enforcement), the resulting allow/block decision, and the specific rule that drove it. Additionally, you can run a what-if analysis that overrides the actual asset state during a path query and treats all microsegmentation assets as managed and fully enforced, so the resulting allow/block decision reflects a fully enforced hypothetical rather than current reality.

Benefits:

  • Reduces risk of misdiagnosed connectivity issues caused by inaccurate enforcement assumptions

  • Improves troubleshooting accuracy across hybrid firewall and microsegmentation environments

  • Accelerates resolution of connectivity problems by surfacing the actual enforcement state and matching rule

  • Reduces risk for enforcement rollouts by simulating fully enforced outcomes before changing any asset's real enforcement mode

USP violations for micro-segmentation rules by asset tags

When using micro-segmentation solutions, you can now enforce the Unified Security Policy against tag-based assets residing inside rules. Additionally, USP security zones that include tag strings can calculate violations by matching zone tags against object tags and tagged assets in security rules.

Benefits:

  • Reduces compliance blind spots when using micro-segmentation tools

  • Strengthens security posture by enforcing USP violations against tag-defined assets

  • Reduces manual effort required to map tag-based workloads into zone-based policy models

  • Improves accuracy of risk assessment on access requests involving tag-annotated assets

Visibility & Topology Support for Panorama Target Field

You can now see exactly which devices a Panorama rule targets, with accurate shadowing analysis and topology calculations that respect the Target field. TOS reads and models the Panorama rule target field across Rule Viewer, Compare Revision, shadowing detection, and traffic path simulation in topology.

Benefits:

  • Eliminates manual cross-referencing of Panorama to determine actual rule scope

  • Reduces false positives in shadowing and cleanup analysis for Panorama Device Group policies

  • Improves accuracy of topology and path simulations across Panorama-managed environments

  • Lowers risk of incorrect policy decisions caused by unmodeled Target-scoped rules

  • Reduces MTTR

  • Increases operational efficiency

5.3.01

Bug fix only. See 5.3.00 for feature enhancements.

5.3.00

To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.

Feature

Description

EntraID user identify

TOS now supports Microsoft Entra ID as a user identity provider, alongside on-prem Active Directory - so Entra ID user groups can be used for topology-based troubleshooting and end-to-end access request automation. Currently supported for Panorama and Strata Cloud Manager.

Benefits:

  • Improved user identity-based topology troubleshooting

  • Shorter SLA times for access requests using Entra ID groups

  • Fewer manual changes, reducing errors

See Configuring User Identity - EntraID.

Strata Cloud Manager dynamic routes

Dynamic routes are incorporated into the topology map alongside static routes, enabling accurate end-to-end path analysis, troubleshooting, and automated change target selection in SCM NGFW environments that use dynamic routing protocols.

Benefits:

  • More accurate network troubleshooting for SCM NGFW environments - reduced MTTR

  • No more manual topology reconciliation efforts - time saving

  • Streamlined change automation accuracy - improved SLA

NSX RFC-5424 syslog format

TOS now supports the RFC-5424 syslog format for NSX devices, ensuring traffic hit logs are correctly parsed and revisions are accurately tracked.

Benefits:

  • Reduced attack surface

  • Accurate policy cleanups

  • Increased security

PAN Shared gateways

The topology map now retrieves shared gateway interfaces and correctly maps them to their policy zones as defined on the Palo Alto device. This ensures accurate network map, correct firewall target selection in Designer, and full policy evaluation for Shared GW-connected network segments.

Benefits:

  • More accurate topology for Palo Alto Shared GW environments

  • No more false positives in path analysis

  • Improved change automation accuracy and SLA

  • Reduced manual effort

User identity USP violations

When calculating USP violations, rules which include User Identity (and no subnet specification), are now validated against a dedicated, pre-defined User Network Zone.

Benefits:

  • Reduced cost of preparations and readiness for compliance audits for NGFW devices

See Rule Violations - Additional info for NGFW rules.

NSX-T DFW access request without topology

Access request tickets involving NSX-T DFW can now be submitted with topology mode off, including Verifier, Designer, and Provisioning.

Benefits:

  • A more streamline automation process

  • Increased operational efficiency

Strata Cloud Manager IP-based access request automation

Tufin extends the access request automation workflow to Strata Cloud Manager (SCM) NGFW Folders, operating in topology mode. Verifier checks whether IP-based traffic is already permitted by existing SCM rules. Designer suggests rule creation or modification against the correct SCM folder in the policy hierarchy, respecting snippet visibility (read-only). Provisioning automatically commits approved changes directly to SCM.

Benefits:

  • Reduced SLA through fully automated access requests for SCM devices

  • Automated change process, reduced errors

  • Reduced attack surface

  • Saving in time and money

See SecureChange features by vendor - Strata Cloud Manager.

AWS Network Firewall

TOS now provides policy visibility and topology support for AWS Network Firewall. Support includes AWS Firewall Policies, their rulesets, and associated firewalls.

Search for rules in Rule Viewer for troubleshooting purposes, identify USP violations for rules that do no comply with internal and industry regulations, and troubleshoot network access in the topology map to see if it is allowed or blocked.

Benefits:

  • Continuous compliance

  • Reduced MTTR for network issues

  • Increased operational efficiency

See SecureTrack features by vendor - AWS Network Firewalls and AWS Network Firewall import.

Segmentation insights

Analyzes existing zone and subnet data, identifies zone configuration errors, and recommends actionable fixes and next steps.

Benefits:

  • Instant visibility into zone and subnet configurations

  • Identifying misconfigurations before they become risks

  • Time saving - hours of manual review can be avoided

  • Clear, actionable fixes ready to implement

Search rules by date added

View and search for rules in Rule Viewer by the date they were added to TOS, using the timeAdded TQL field.

Benefits:

  • Improved rule visibility

  • Reduced costs preparing for audit

See TQL fields for Rule Viewer - timeAdded and Rule Viewer Overview.

Search rules by vendor name

Search for 3rd party OPM rules in Rule Viewer by vendor name.

Benefits:

  • Improved rule visibility - time saving and improved efficiency

Search rules by network zone

Search for rules in Rule Viewer by the network security zone(s) containing their source or destination.

Benefits:

  • Improved rule visibility - reduced cost of audit preparation

AWS Cloud WAN

Tufin extends AWS Cloud WAN support to retrieve and model Network Function Groups (NFGs) and their service insertion configuration in the Topology Map - including the NFGs defined in the core network, the segments and attachments associated with them, and the send-to / send-via actions that steer traffic through inspection VPCs. This lets TOS represent the security appliances inserted into the Cloud WAN path, so path analysis reflects the actual inspection hop and SecureChange identifies the correct enforcement target for access requests that traverse NFGs across AWS regions.

Benefits:

  • Faster resolution of connectivity issues

  • Safer automation changes

  • Reliable representation of inspection and enforcement points in Cloud WAN topology

See AWS Cloud WAN import.

Cisco Meraki Provisioning

You can now provision approved changes from SecureChange Access Requests directly onto Meraki MX devices, the same way other supported firewall platforms work today. Approved access requests are translated into the correct Meraki construct, depending on rule type — Site-to-Site VPN rules at the organization level, Layer 3 firewall rules at the per-network level, and group policy rules at the per-group-policy level — and pushed to the target MX devices. Implicit IPv4 hosts and subnets are supported as sources and destinations for all three rule types and provisioning is gated by topology being on to make sure each rule lands in the right place.

Benefits:

  • Fully automated, consistent, auditable change process

  • Reduced manual effort on changes

  • Reduced risk of human error

See SecureChange features by vendor - Meraki.

Cisco L3 Switch bulk API

You can now onboard Cisco L3 switches into SecureTrack via the bulk device API, the same way routers and other L3 devices are onboarded today.

Benefits:

  • Reduced manual effort and time spent on device management tasks

NSX' applied to' field in path analysis

For path analysis involving NSX devices, the rule-matching logic now considers traffic associated with Security Groups (SGs) specified in the NSX rule's Applied To field.

Benefits:

  • Reduced MTTR

  • Improved SLA times

See SecureTrack Features by Vendor - VMWare.

NSX SG VM name, tag and scope

Visibility added for two additional NSX Security Group (SG) types:

  • Virtual machine name = value criteria.

  • Virtual machine tag AND scope membership criteria.

These SGs are now fully supported across Rule Viewer and topology, and can be leveraged by automation workflows, enabling traffic associated with these groups to be accurately analyzed.

Benefits:

  • Increased Security

  • Reduced attack surface

Panorama last hit via API

A new feature flag for Palo Alto Panorama-managed firewalls that retrieves rule last-hit data using the Panorama API instead of syslogs. When enabled, the Rule Viewer’s last hit indication is based on the timestamp returned by the API.

Benefits:

  • More accurate cleanup process for PAN rules

  • Reduced attack surface

  • Reduced manual effort

See Configuring TOS - Collect rule last hit information from Panorama devices.

Check Point FQDN last hit

Extends the existing Check Point object-usage (last-hit) collection and Rule Viewer display to include FQDN/domain-based objects. FQDN objects are now processed by the same object-usage analysis pipeline used for other Check Point objects, so their last-hit data is collected and surfaced consistently in the Rule Viewer. Supported across Check Point CMA, SMC, and Smart-1.

Benefits:

  • More accurate cleanup process for Check Point FQDN rules

  • Reduced attack surface

  • Reduced manual effort

See SecureTrack Features by Vendor - Check Point.

AWS SG modeling on all resource types

SecureTrack discovers and models security groups applied to any AWS resource type (generic resources) - NLBs, ALBs, private/public VPC endpoints, and more, in addition to EC2 instances, representing them as network entities in the revision, topology map, and path analysis.

Benefits:

  • Complete, accurate AWS topology across all resource types

  • Elimination of blind spots and false positives in path analysis and matching rules.

  • Faster troubleshooting and reduced MTTR

  • Improved change-automation accuracy

  • Shorter SLA times through correct target selection

  • Continuous compliance

  • Reduced manual effort for AWS environments

See AWS resources fetched with revisions.

5.2.02

Bug fix only. See 5.2.00 for feature enhancements.

5.2.01

Bug fix only. See 5.2.00 for feature enhancements.

5.2.00

To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.

Feature

Description

Zone API

A new API to create, update and retrieve SecureTrack zones.

Benefits:

  • Automation of zone maintenance and reporting

  • Reduced time and costs of audit preparation

USP Viewer Scroll Bar

Vertical and horizontal scroll bars appear when needed in the USP Viewer.

Benefits:

  • Improved user experience

View Reports Permissions

SecureChange admins can define for each user whether they can generate reports on all tickets or only their own.

Benefits:

  • Improved control over access

  • Implementation of least-privilege security

Check Point License Consumption API

With this API, you can enable or disable specific Check Point module gateways that have been decommissioned or are standby / test devices, from license counting. You only pay for the devices that deliver value; disabled devices do not consume a license but remain visible in TOS.

Benefits:

  • Reduced TOS licensing costs

PAN IPv6 Support In Topology Map

TOS now supports IPv6 interfaces and routing (static and dynamic) for Palo Alto Networks devices managed by Panorama, across both advanced routing and legacy routing modes. IPv6 traffic is included in topology mapping, path analysis, and rule matching. In addition, SecureChange access requests now support IPv6 for automatic target selection on PAN devices.

Benefits:

  • Improved troubleshooting for IPv6 connectivity.

  • Improved overall automation accuracy.

See Examples of NAT rules.

Push Tufin-Only Changes to Panorama

As part of 'Commit Now' and 'Change Window' in SecureChange, TOS performs two actions in Panorama: 'Commit to Panorama' (can be scoped to Tufin user changes) and 'Push to Devices' (previously always pushed all user changes). The new enhancement lets you configure the 'Push to Devices' scope — either all Panorama users or Tufin user changes only.

Benefits:

  • Reduced risk by ensuring only approved, Tufin-managed changes are pushed.

  • True zero-touch automation — controlled committing and pushing without manual intervention

  • Reduced operational overhead by eliminating the need to manually manage Panorama commits and pushes

See Provisioning Panorama by user and configuration type.

Push changes to DGs only

You can now configure TOS to push only device group policy changes to Panorama-managed firewalls, without pushing Panorama templates.

Benefits:

  • Prevention of unintended template deployments during SecureChange provisioning.

  • Reduced risk of operational errors and application downtime by ensuring only approved, TOS-managed changes are pushed.

  • Zero-touch automation and reduced change SLA by enabling TOS to commit and push without manual intervention.

See Provisioning Panorama by user and configuration type.

Guardicore and Illumio Microsegmentation Topology

TOS topology now includes microsegmentation devices in path analysis. When source/destination is a managed asset, TOS detects and shows the microsegmentation device on the path with its matching rules (including tag-based, tag group, and alert rules). Supports same-subnet and behind-cloud scenarios. You can select Guardicore/Illumio assets as path query endpoints.

Benefits:

  • Reduced MTTR when microsegmentation is part of the path.

  • Fewer manual investigation steps means less engineering time spent per incident.

  • End-to-end path analysis across firewalls, cloud, SASE, and microsegmentation is available in one unified view, so teams identify the blocking rule, whether a firewall or a Guardicore/Illumio tag-based rule.

Zscaler Designer Objects

Designer now suggests updating and creating groups as needed on Zscaler ZIA instead of raw embedded IP addresses or services,

Benefits:

  • Cleaner, more maintainable firewall change suggestions for these OPM-managed devices.

  • Improved policy readabilty and maintinability

Guardicore and Illumio Microsegmentation in Rule Viewer

You can now get deep, tag-aware visibility into Guardicore policies in the Rule Viewer- including resolving tags to assets, filtering rules by asset tags, IPs or names, and tracking rule history changes triggered by asset tag updates.

Benefits:

  • Full transparency into which assets tag-based rules cover.

  • Faster, more accurate policy analysis and auditing.

  • Meaningful change tracking without noise.

  • Accurate permissiveness scoring.

  • Identification and clean up unused Guardicore rules using last hit data which reduces the attack surface and risk. Enterprise-scale support (300K assets).

Palo Alto Strata Cloud Manager

You can now detect USP violations, view topology run path analysis for Strata Cloud Manager NGFW policies.

Benefits:

  • Improved operational efficiency

  • Time saving in troubleshooting and audit preparation

  • Reduced MTTR

  • Improved security

  • Continous compliance.

Static NSX-T Groups

The group modification workflow now lets you add/remove objects from static NSX-T security groups or create new groups, and provision the changes seamlessly.

Benefits:

  • Reduced SLA by using an automated workflow.

5.1.01

Bug fix only. See 5.1.00 for feature enhancements.

5.1.00

This is the first GA release of TOS 5

To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.

Feature

Description

Arista VeloCloud

VeloCloud SD-WAN devices can now be monitored by TOS, bringing them into the unified control plane used to manage and monitor firewalls, routers, cloud resources, and hybrid environments. Security and traffic policies from VeloCloud are visible, validated, and governed like all other network devices.

Benefits:

  • Consistent security policies across the entire hybrid architecture.

  • Faster, safer change implementation.

  • Stronger compliance posture and audit readiness.

  • Reduced operational complexity and misconfiguration risk.

  • Improved incident response through unified path visibility.

See SecureTrack features and SecureChange features for Arista VeloCloud.

TufinAI Executive Dashboard

TOS administrators can now to craft their own dashboards and define charts to present unique and customized aggregations over security rules and SecureChange tickets. Based on specifications given in natural language, AI-generated code fetches filtered data from TOS and renders it into charts and reports.

Benefits:

  • Generate your own dashboards and reports

  • Examples: Daily monitoring, proof of ROI, compliance audit preparation, policy cleanup planning, ticket SLA, policy vulnerabilities.

See Personalize TufinAI Executive Dashboard.

Cisco FMC - FQDN

FQDN objects are now supported for Cisco FMC including visibility, topology, compliance, and access request automation. Visibility into FQDN content is supported in the Rule Viewer and Compare Revisions. You can run path analysis queries by using FMC FQDN objects and identify allowing/blocking rules. You can automate access requests that include FQDN objects where rules have to be changed / added, including target selection, design, verification and provisioning.

Benefits

  • Reduced SLA through fully automated access request handling.

  • Improved accuracy

See SecureTrack and SecureChange features for Cisco FMC.

Azure Usage Analysis

TOS now supports VNet flow logs, and Azure resource specific log analytics collection to provide cleanup and optimization insights for Azure NSGs and firewalls.

Benefits:

  • Reduced attack surface

  • Improved security posture

  • Reduced time spent on manual cleanup/optimization

See Azure configuration for flow logs.

RHEL 9 / Rocky Linux 9

TOS can now be installed on Red Hat Enterprise Linux 9 and Rocky Linux 9 operating systems

Benefits:

  • Addresses market demand to install TOS on more recent operating system versions

  • Improves security and compliance posture

  • Streamlines deployment

See TOS release history.

Monitor AWS using SDK2

Amazon's AWS SDK v1 has reached end of support, and will not receive further security or new region updates. Therefore, for all new installations, TOS will monitor AWS using SDK v2. For upgrades, from older installations, TOS will continue using SDK v1.

By the end of the year, SDK v2 will become the default both for clean installs and upgrades from previous versions.

All TOS enhancements for AWS added in TOS 5 and later will require AWS SDK v2.

Therefore, we recommend moving to AWS SDK v2.

Benefits:

  • Ensures latest AWS security and other updates

  • Access to the latest TOS features for AWS (RDS, prefix lists and opt-in regions)

See Use AWS SDK v2 for AWS monitoring.

AWS RDS Visibility & Policy Support

AWS RDS instances are now visible in TOS. Security Group policies applied to RDS endpoints can be viewed, searched by IP, and included in topology and path analysis.

TOS retrieves AWS RDS instances and associates their security groups, modeling them as network entities. RDS instances are counted as licensed VM entities.

This feature requires AWS SDK v2.

Benefits:

  • Full visibility of policies protecting AWS databases.

  • Accurate path analysis to RDS endpoints.

  • Improved compliance posture for AWS environments.

See SecureTrack Features by Vendor > Amazon.

AWS Opt-in Regions By Assume Role

TOS now supports monitoring AWS opt-in regions using assume role authorization. TOS can monitor the accounts and resources deployed in the opt-in regions by AWS using assume role authorization. Requires enablement of AWS SDK2. Otherwise, a local user must be used for authentication and authorization.

This feature requires SDK v2.

Benefits:

  • Full visibility of policies protecting AWS databases.

  • Accurate path analysis for resources deployed in opt-in regions

See SecureTrack Features by Vendor > Amazon.

Cisco IOS-XE SDWAN (cEdge) - GRE Tunnel support

Cisco IOS-XE SDWAN (cEdge) - GRE Tunnel support

  • Accurate topology map including GRE tunnels enables E2E automated change process

  • Facilitates shorter SLAs

  • Fewer manual errors

See SecureTrack Features by Vendor > Cisco.

5.0.00

This is the initial release, not for production.

To filter the results, enter text in one or more of the filter fields. Clear the fields to see all items.

Feature

Description

Initial Release

5.0.00 is the first version of the TOS 5 platform version. It is not for production deployment but rather meant to test and verify that the new TOS infrastructure deploys and runs smoothly in a lab environment. Generally first versions of platform versions contains infrastructure updates and bug fixes, but little or no new features. Subsequent versions starting with 5.1.00 will contain new features.

New Naming Convention

Starting with 5.0.00, we are introducing a new naming convention for TOS. Platform version replaces major version and feature version replaces minor versions of type PGA and PHF. As new features and bug fixes are made available, they are released as new feature versions within that platform version.

The previous naming convention (e.g. R25-2 PHF3.0.0) will continue be used for R25-2 and earlier versions only.

  • Platform version: Includes many versions - an initial release version, a number of feature versions, and unplanned versions if needed. Platform version examples: TOS 5, TOS6.

  • Initial release version: The first version, not for production deployment. Meant to test and verify that the new TOS infrastructure deploys and runs smoothly in a lab environment. It contains infrastructure updates and bug fixes, but little or no new features. Examples: 5.0.00, 6.0.00.

  • Feature versions: These versions are production-ready. They contain feature enhancements and bug fixes with little or no infrastructure changes. They will typically be spaced out around six weeks apart. Updating to a feature version within the same platform version generally takes less time than updating to a new platform version. Examples: 5.1.0, 5.2.0, 6.1.00.

For more information, see the Tufin Customer Portal