Monitoring Stormshield Devices

Overview

Supported from TOS 5.2.

Add Stormshield SNS (Stormshield Network Security) devices to TOS using the Open Policy Model (OPM). OPM expands device coverage in TOS to additional vendors. Tufin provides device connectors that collect the device's configuration and policy data and import it into SecureTrack.

The Stormshield device connectors support onboarding Stormshield routers and firewalls. SecureTrack connects to these devices over SSH and pulls topology and rule data based on the sync schedule set in Tufin-Integrations.

For supported features, see Features by Vendor in SecureTrack and Features by Vendor in SecureChange.

Prerequisites

  • SSH and HTTPS (for API) access to all devices

  • Customer Portal access to download the OPM package

  • Admin credentials for SecureTrack and SecureChange

  • TOS server:

    • sudo permissions to run the installer

    • File upload permissions to /opt/misc

  • On systems with non-Tufin OS, python3 and bzip2 packages installed

Install the OPM package

Install the OPM package from the shell on the TOS server. The steps are identical for both new installations and upgrades.

If you have existing OPM packages, the OPM installer automatically detects and upgrades older versions.
  1. Go to the Download center.

  2. Select Stormshield.

  3. Click Download to Computer.

  4. Upload the downloaded file to /opt/misc (recommended) on the TOS server:

    sh <package-name>

    where:

    <package-name> is the name of the package you downloaded in the format install-<vendor>-1.0.0.aur.run

  5. When prompted, enter:

    • SecureTrack Username and Password

    • SecureChange Username and Password

  6. Wait for the installation to complete. The installer installs PS Proxy and Tufin Integrations if they don't exist. If an older version is installed, the script upgrades it.

    These credentials are used by the OPM scripts to make API requests. You can always update them later in Tufin Integrations.

Add Stormshield device

Add a Stormshield firewall or router device to TOS.

To allow SecureTrack to retrieve configuration data and run all required commands, the SSH user must have admin (read) access to the device.

For Firewall devices, the user must also be able to switch between virtual systems.
  1. In SecureTrack, go to Monitoring > Devices > Device Viewer.

  2. Click Add Device, and then select Add OPM Device.

  3. In the ADD OPM DEVICE define the device details:

    • Vendor: The vendor with the device to add.

    • OPM agent: The registered agent for the vendor. The agent is displayed only if it was installed successfully.

    • Type: The supported device type, which is Network Security.

    • Display name: The name to display for this device in SecureTrack.

    • IP: The IP address of the device.

  4. Click Next.The Configure Device properties form is displayed.

  5. Configure the device properties:

    • Username: Mandatory. The username of the Stormshield administrator account that TOS uses to connect to the device.
    • Password: Mandatory. The password for the Stormshield administrator account.
    • HTTP Proxy Port: Optional. The port to use when connecting to the proxy server.

    • HTTP Proxy Hostname: Optional. The hostname or IP address of the proxy server that TOS uses to reach the device.

    • HTTP Proxy Protocol: Optional. The protocol used to connect to the proxy server, HTTP or HTTPS.

    • HTTP Proxy Username:  Optional. The username, if the proxy server requires authentication.

    • HTTP Proxy Password: Optional. The password, if the proxy server requires authentication.

  6. To confirm settings and add the device, click Save.

Sync device with SecureTrack

Use Tufin Integrations to configure how SecureTrack syncs with your OPM-managed device. Tufin Integrations is the updated web interface for managing OPM devices, automatically installed by the OPM package if it does not exist.

Configuring SecureTrack to sync with your OPM-managed device includes:

  • Defining user credentials

    For API configuration, define the username and password to connect to SecureTrack and SecureChange.

  • Importing devices

    Run discovery to import the devices for vendors, and selectively enable and start them for monitoring.

  • Assigning the device to a cluster

    You can assign devices to different TOS clusters for monitoring. For example, you can monitor one OPM device from the main cluster and another from a Remote Collector. Remote collectors are available only if they are configured in TOS.

  • Scheduling sync jobs

    Schedule automated syncs or trigger a manual sync on demand when monitoring is enabled for the device.

  • Reviewing job history

    View per-device status, start/end time, and message after each agent run.

When configuration is complete, SecureTrack runs a script that connects to the device, retrieves configuration data (such as interfaces, routes, and rules), and imports the data. This process replaces real-time monitoring with scheduled or manual data collection.

  1. To open Tufin Integrations, do one of the following:

    • Go to https://<tos-vip>/apps/integrations.

    • In SecureTrack , from the list of Tufin Extensions , select Tufin Integrations.

  2. Set the user credentials for Tufin API:

    1. From the DASHBOARD, select Advanced, and then select TUFIN API CONFIGURATION.

    2. Define the username and password credentials for SecureTrack and SecureChange.

    3. Click Save.

      Credentials are automatically validated, and flagged if incorrect.

  3. Return to the Dashboard and select the OPM client or vendor with the devices to monitor.

  4. To import devices, do the following:

    1. Click IMPORT DEVICES and then click RUN DISCOVERY.

      The devices are displayed in the list.

    2. Select the parent management device, or select a specific device.

    3. Right-click and select Enable.

    4. Click Save.

      The enabled devices are added to the vendor list.

  5. To monitor enabled devices, right-click the device and select Start.

  6. From the list of available devices, right-click the required device, and select the cluster from which to monitor the device:

    • Migrate to main: Monitor the device from the primary cluster.

    • Migrate to <remote_collector>: Monitor the device from a Remote Collector, for example, RC4.  Available only if a Remote Collector is configured in TOS. The actual name of the Remote Collector differs by environment.

    For automated or manual sync to run, you must enable monitoring for the device.
  7. In the Configuration section, set the automated sync schedule:

    1. Set Schedule interval, for example: daily, weekly, or monthly.

    2. Choose the Time or Day of execution.

    3. Select the Log Level. The default is INFO.

    4. To enable the script, select Enabled.

    5. Click Save.

  8. To start collecting revisions immediately, click SAVE & RUN.

    If not triggered manually, the sync is triggered as scheduled.
    Every script execution retrieves the configuration from all devices assigned to the vendor’s OPM agent.

  9. Verify the results in the Run Details popup:

    In the Agent Runs table, click the blue information icon information icon in the Run Details column.

    The popup shows the status, start and end time, and a message for each device in the run.

How do I get here?

SecureTrack > Monitoring > Devices > Device Viewer