On this page
Microsoft Azure
Azure Resource Manager
- Dashboard Widgets
-
General (General overview of the system)
-
USP Compliance (The number of rules with violations, according to their severity level)
-
Audit (The number of rules with expired access or will have access expire within the next month)
- Browsers
-
Rule Viewer (see Rule Viewer)
-
Rule Optimizer (see Rule Optimizer)
-
Object Lookup (See Object Lookup)
-
USP Viewer (see USP Viewer)
-
USP Alert Manager Viewer (see USP Alerts Manager)
-
USP Exceptions Viewer (see USP Exceptions)
-
Changes (see Change Browser)
-
Device Viewer (see Device Viewer)
- Change Management
-
Change Management (Policy and Side-by-Side policy change comparison in the Compare tab, Comparison report, and New Revision report)
-
Graphical Policy (Policies are displayed in SecureTrack as they are shown in the vendor's management software)
- Topology
-
Azure Virtual WAN
-
Dynamic Topology
-
Calculate impact of NSGs
-
Connectivity between VNets
-
ExpressRoute
-
VNet peering
-
Connectivity via VPN
-
Internal load balancer
Supported devices
The following devices are supported on Microsoft Azure:
- Fortinet
- FortiManager
- FortiGate
- Check Point
- Management Devices (MDS) CloudGuard Network Security - Firewall & Threat Prevention
- Check Point Gateway with dynamic routes
- Palo Alto
- Panorama
Notes for Azure Resource Manager
Supported device type
-
Azure Resource Manager is the supported device type.
-
Azure Classic (Azure Service Management API): Support for this device has reached its "end of life" (EOL).
Account import
-
Cloud organization based automatic account import
When automatic account import is enabled for the cloud organization, member accounts are automatically imported to the central cluster. After automatic import, you can migrate the member accounts to a remote collector.
-
Account onboarding to remote collector
To onboard an account directly to a remote collector, add the account individually.
Members of Application Security Groups (ASGs) in Rule Viewer
To view members of ASGs in the Rule Viewer, the Virtual Machines (VMs) associated with the ASGs must be connected to the same Virtual Network (VNET) as the Network Security Group (NSG) that contains the ASG.
VirtualWan
You can import secured virtual hubs to Tufin when the Routing Intent and Routing Policies setting points to the Azure firewall in the configuration.
VNETs without NICs
By default, Azure Virtual Networks (VNETs) without attached network interfaces (NICs) are not imported.
To allow importing VNETs without NICs, see Enabling import of Azure VNETs without NICs.
Rule and object usage collection and analysis
-
Azure subscription for usage collection and analysis for rules and objects
Supported only when the Azure subscription is monitored on the central cluster, and not on the remote collector.
-
To populate information for the Last Hit field in the Rule Viewer:
-
Configure Azure to allow TOS to pull traffic information.
-
To identify unused rules, search by timeLastHit.
-
For NSGs, to identify unused objects within rules, also search by object.timeLastHitand object.notHit .
For details, see TQL queries in the Rule Viewer.
-
Reports on unused rules (and objects, for NSGs)
Schedule and run reports on unused rules (and objects, for NSGs) using the Rule Analytics report in SecureTrack Reporting Essentials. The data is not supported in the Rule and Objects Usage report.
Azure firewall and firewall policy
- Dashboard Widgets
-
General (General overview of the system)
-
USP Compliance (The number of rules with violations, according to their severity level)
- Change Management
-
Change Management (Policy and Side-by-Side policy change comparison in the Compare tab, Comparison report, and New Revision report)
- Topology
-
Path Analysis
-
Calculate impact of Azure Firewall policies
- Browsers
-
Rule Viewer (see Rule Viewer)
-
USP Viewer (see USP Viewer)
-
USP Alert Manager Viewer (see USP Alerts Manager)
-
USP Exceptions Viewer (see USP Exceptions)
Notes for Azure firewall and firewall policy
Account import
-
Cloud organization based automatic account import
When automatic account import is enabled for the cloud organization, member accounts are automatically imported to the central cluster. After automatic import, you can migrate the member accounts to a remote collector.
-
Account onboarding to remote collector
To onboard an account directly to a remote collector, add the account individually.
Rule history
- In some cases, this device creates new rules for requested changes rather than updating the existing rules. In these cases, rule history might not be available.
Classic rules
Classic rules, configured on the firewall directly and not included in Azure firewall policies, are not supported.
Azure firewall
-
When a new Azure firewall is added to TOS, zones are mapped after the policy is received for the first time and therefore violations can be calculated only after receiving a subsequent revision. See Monitoring Microsoft Azure Cloud Platform.
-
Azure firewall in a secured virtual hub is supported when Routing Intent and Routing Policies is set on the hub.
Rule usage collection and analysis
-
Azure subscription for usage collection and analysis for rules and objects
Supported only when the Azure subscription is monitored on the central cluster, and not on the remote collector.
-
To populate information for the Last Hit field in the Rule Viewer:
-
Configure Azure to allow TOS to pull traffic information.
-
To identify unused rules, search by timeLastHit.
-
For NSGs, to identify unused objects within rules, also search by object.timeLastHitand object.notHit .
For details, see TQL queries in the Rule Viewer.
-
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague