On this page
Open Policy Model
Overview
The Open Policy Model (OPM) is Tufin’s device onboarding architecture for adding new devices to TOS. OPM uses device connectors that collect device data and report it into the native TOS architecture. This approach streamlines onboarding and provides a consistent feature set for all supported OPM-based devices.
The connectors can onboard many different kinds of devices, including firewalls, routers, and cloud platforms. They report relevant device information such as interfaces, routes, and policies. After installation on the TOS system, each connector registers automatically so the device can be added and monitored in SecureTrack. OPM device connectors are TOS-version independent. If a specific connector requires a minimum version or has a version-specific dependency, it will be stated in that device’s documentation.
OPM device connectors collect device data and report it to the TOS model. The available feature set depends on the information reported by each connector.
Devices can be added through the UI or by using the API. For API-based onboarding, see Add an OPM Device Using the API.
Supported OPM devices
Use the links below to view monitoring instructions and feature support in SecureTrack and SecureChange.
| Vendor | Related Links |
|---|---|
|
Arista |
|
|
Aruba |
|
|
Huawei |
|
|
Illumio |
|
|
Versa |
OPM feature support matrix
The table shows the TOS features that are supported depending on what is implemented in the OPM device connector.
For technical issues, contact Tufin Support.
|
Tier |
Use Case |
Feature |
Supported |
|---|---|---|---|
|
SecureTrack+ |
Device Viewer |
Yes |
|
|
Rule Viewer |
Yes |
||
|
Permissiveness |
Yes |
||
|
Violations |
Yes |
||
|
Rule History |
Yes |
||
|
Revision History |
Yes |
||
|
Rule Usage |
No |
||
|
Shadowing Rules |
No |
||
|
SecureChange+ |
Includes matching rules |
Yes |
|
|
Automatic target identification |
Yes |
||
|
USP risk assessment |
Yes |
||
|
Adding Access |
Yes |
||
|
Ticket to rule mapping |
Yes |
||
|
Decommissioning Access |
No |
||
|
Adding Access |
Yes |
||
|
Decommissioning Access |
No |
||
|
Enterprise |
— |
Yes |
OPM password requirements
General requirements
Passwords can:
-
Either be empty, or include up to 250 alphanumeric and special characters, including spaces.
-
Include special characters, used on their own, anywhere in the password: ! @ # $ ^ & * ( ) _ + - = [ ] { } | ; : , . > ? / ~ \ \ ' "`
-
Include text that resembles SQL syntax, such as OR 1=1--
Limitations
The table lists invalid character combinations in passwords for OPM devices.
A password containing any of these combinations returns this error on save: One or more fields contain invalid characters. Please remove them and try again.
|
Special character/pattern |
Not allowed when |
Example |
|---|---|---|
|
% (percentage) |
|
pa%ssword1 |
|
< (less than) |
|
<ss <pas>ss |
|
> (greater than) |
|
om<it> |
| \ (backslash) |
|
\uword \x41 |
|
= (equal to) |
|
password=" |
|
' (single quote) |
|
'jk;k 'script |
|
[ ] ! + ( ) |
|
pass!!!!!!word pass()()()()()()word |
|
< < &# |
|
pass< word< pass&# |
|
javascript: eval( +ADw- <!ENTITY |
|
passjavascript:123 word12eval( pass+ADw- word<!ENTITY34 |
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague