AWS Device Monitoring

Overview

Add AWS accounts to TOS as devices to monitor and manage them. TOS monitors the AWS devices for configuration and policy changes, providing ongoing visibility into configuration and compliance.

Based on the onboarding model of your choice, configure the settings for the AWS account to monitor TOS and add it as a device. See AWS device settings and adding AWS devices.

After adding the device, you can manually import additional AWS resources, migrate domains and servers, and update the device configuration. See Managing monitored devices.

AWS device settings

The table describes the settings you can configure for an AWS device in TOS.

Device Setting

Description

Device Type

Automatically populated.

Name for Display

The name to display for the device in SecureTrack.

Domain

  • Available only if you have configured your system for managing multi-domains and All Domains is currently selected.

    The domain to which to add the device.

    To change the domain after adding the device, you must migrate the device.

  • Usage Analysis

     

    • Collect traffic logs for rule usage analysis: Enable SecureTrack to analyze flow log data and identify the last hit date for rules.
      When selected, uses AWS CloudWatch (the default). To use S3 flow logs instead, select Enable S3 storage explicitly for the device and configure the storage credentials.

    • Enable Rule Optimizer Recommendations: Collect and save traffic usage data for Rule Optimizer recommendations.

    Enable Topology

    Collect routing information to build the network Map.
    Topology options for Advanced management mode are configured when you import managed devices.

    VPC Import

    Determines how to import VPCs into TOS:

    • Automatic ImportAutomatically detect updated, deleted, and new VPCs in the AWS account, and reflect the updates in SecureTrack. VPCs are automatically imported at 10-minute intervals. For more information, see Automatic VPC import.

    • Manual Import: Manually import VPCs after you add the AWS device, using the Import Virtual Private Cloud option.

    Cloud Organization

    Applies to Organization-based access.

    • Use Cloud Organization: Select the predefined cloud organization in TOS to which to associate this device.

      When associated with a cloud organization, other connection mechanisms and credentials are automatically disabled. The Access Key ID and the Secret Access Key are automatically populated from those configured for the cloud organization.

    • Account ID: Mandatory when Use Cloud Organization is selected. The ID of the account to associate with the device.

    Connection

    Applies to single- and cross-account access.

    The Access Key ID and Secret Access Key for the account from the AWS Identity and Access Management (IAM) console.

    ARN

    Applies to cross-account access only.

    The Amazon Resource Name (ARN) identifier required to use AssumeRole permissions. This allows you to request temporary security credentials to make AWS requests for account configuration information that is not available by default, and to access VPCs that are not part of your account configuration.

    For more information, see Amazon AWS AssumeRole Support.

    Proxy

    Applies to single- and cross-account access.

    Connect to AWS through a proxy that requires authentication, and define the following:

    • IP address or Hostname

    • Port: Port to connect to on the proxy.

    • Username: For indentification.

    • Password / Confirm Password: Password to use for authentication.

      If SSL decryption is enabled on the proxy server and applied to the traffic from SecureTrack to AWS, you must configure a whitelist on the proxy server, allowing that traffic to bypass SSL decryption and authentication.

    Enable S3 Flow Logs

    Applies to single- and cross-account access.

    Use S3 flow logs for usage analysis instead of the default CloudWatch, and define the Region and S3 Bucket name.

    S3 Centralized Account

    Applies to cross-account access only.

    Seelect and define the Access Key ID and Secret Access Key as the credentials for the centralized account access.

    Use Hashicorp Vault

    Applies to single-account access only.

    Store your AWS authentication credentials in Hashicorp Vault.

    NOTE: Use the KV secret engine version 1. Not supported together with a proxy or Cross-Account Access (ARN).

    • Server host name: Name of the server used to host the Hashicorp Vault.

    • Port: TCP/UDP port that SecureTrack uses to communicate with the Hashicorp Vault.

    • Secret path: Path to the AWS authentication details within the Hashicorp Vault.

     

    • Vault Token Authentication

      Add the Vault token required for SecureTrack to authenticate AWS using Hashicorp Vault.

     

    • App Role:

      Select this option to add the App Role fields.

      For example:

      • Role ID: Vault server RoleID that SecureTrack uses to authenticate the Hashicorp Vault server.

      • Secret ID: Hashicorp Vault server SecretID that SecureTrack uses to authenticate the Hashicorp Vault server.

      • Approle Login URL: Path to AppRole login details within the Hashicorp Vault.

        Tufin does not support using the Hashicorp Vault with a proxy or Cross-Account Access (ARN)

    Monitoring Settings > Custom

    Define the polling frequency for SecureTrack to retrieve the configuration from each device.

    • Use timing page settings: See Setting Timing for Monitoring.

    • Custom settings: Select the required polling frequency. If you select 1 day, you can select the exact time (hour and minute) for the daily polling.

    VPC automatic import

    When you add an AWS device, you can enable Automatic Import for Virtual Private Clouds (VPCs). When enabled, SecureTrack automatically detects changes to VPCs in the AWS environment (VPCs which were added, deleted, and updated), and reflects them in the device list and revision history. Changes to the VPCs are also reflected in the Map when a scheduled sync occurs or when you manually Sync the map.

    When enabled, VPCs are automatically imported at 10-minute intervals.

    With Automatic Import enabled, devices that were deleted from AWS are automatically deleted from the list of devices in SecureTrack, and their history is no longer available. Therefore, if your continuous integration/continuous deployment (CI/CD) pipeline regenerates VPCs, the history of the deleted VPC will not be available in the new replacement VPC. To retain revision data in SecureTrack for devices that have been deleted from your Amazon account, manually import the VPCs instead using the Import Virtual Private Cloud option.

    The maximum number of VPCs for Automatic Import depends on your TOS deployment. For more information, contact Tufin Customer Support.

    Add an AWS device

    Add AWS devices to monitor in TOS, one device at a time or multiple devices through management accounts.

    Prerequisites

    Steps

    1. Select SecureTrack > Monitoring > Manage Devices.

    2. To add a cloud organization, select Amazon > AWS Organization, and then configure the settings for the cloud organization. Continue from step 3.

    3. To add the device, either individually or through cross-account, select Amazon > AWS Account.

    4. Define the settings, as described in AWS device settings, and then click Save to add the device.

    Managing monitored devices

    After adding a device, SecureTyou can update its configuration settings or delete the device. Based on your environment, you can also import additional AWS resources such as VPCs, Transit Gateways, and Load Balancers.

    AWS resources fetched with revisions

    Starting in TOS 5.3, SecureTrack automatically fetches AWS resources as part of the standard revision retrieval process, for both new and existing devices.

    This support is generic and applies to all AWS instance types. As part of every revision, SecureTrack automatically fetches the Security Groups associated with your AWS resources, regardless of the resource type they are attached to.

    For example, in addition to EC2 instances and their Security Groups, SecureTrack automatically fetches:

    • Security Groups attached to Network Load Balancers (NLBs) and Application Load Balancers (ALBs)

    • Security Groups attached to VPC Endpoints (both private and public)

    Importing and migrating AWS devices

    After you select the device from the list of Monitored Devices, you can:

    • Import Virtual Private Clouds

      Manually import VPCs for the device.

      Make sure you receive the first policy revision from the device (you can see the revision in Compare view). This may take several minutes.

    • Import Gateway Load Balancers. In multi-domain deployments, select the domain for each load balancer.

    • Import Transit Gateways (supported for Topology only). In multi-domain deployments, select the domain for each Transit Gateway.
      When imported, Transit Gateways with associated attachments are displayed on the topology map.

    • Import Cloud WAN: For AWS accounts, import one or more core networks to monitor and display in the Topology Map.

    • Migrate (ST servers): Available in distributed deployments. Select the server where the device will be monitored and click Migrate.

    • Migrate (Domains): Available in multi-domain deployments. Select the domain where the device will be monitored and click Migrate.

    AWS Cloud WAN import

    After adding an AWS account (not AWS cloud organizations), you can import AWS Cloud WANs into the account. The import mechanism uses the AWS account's credentials and does not require separate authentication.

    AWS cloud WANs require specific permissions as described in Advanced Path Analysis > Cloud WAN.

    • Core networks

      When importing an AWS Cloud WAN, TOS displays all the core networks in the selected AWS account.

    • Domains per core network

      For each core network, you can assign a SecureTrack MSSP (managed security service providers) domain, so MSSPs managing multiple customer organizations from a single TOS instance can keep each customer's core networks separated.

    • Manage Devices

      After import, in the Manage Devices tree, each core network is displayed as a monitored device grouped within the parent AWS account.

    • Topology Map

      After a Full Sync, core networks are displayed in the topology map with attachments, routes, network function groups (NFGs), and service insertions (send-to and send-via actions).

      With segments and NFGs modeled as part of the core network, Path Analysis can trace a flow through the core network hop by hop. When a flow's source and destination segments are configured for service insertion, Path Analysis follows the traffic into the segment acting as the NFG and shows the inspection firewall as an explicit hop in the path.

      For access requests, target suggestions and Verifier can test rules on the actual inspection firewall.

      For details, see Topology Map.

    Related topics

    SecureTrack features for AWS

    SecureChange features for AWS