TOS R19-1 ReleaseNotes
TOS R19-1 ReleaseNotes
Release Notes
Version R19-1
Contents
Contents 2
R19-1 HF2 Release Notes 4
Resolved Issues Included From Previous Releases 4
Upgrading Tufin Orchestration Suite 4
Upgrading TufinOS 4
Additional stuff you need to know 4
2
Rule and Object Usage 21
Rule Documentation 22
System Settings 23
TOP 23
Topology 23
User Management 24
Web Interface 24
Zones 25
3
R19-1 HF2 Release Notes
Resolved Issues Included From Previous Releases
Tufin Orchestration Suite R19-1 HF2 includes all resolved issues listed for this release, as well as all resolved issues from the previous releases listed
below.
This release
Upgrading TufinOS
l Installing TOS for the first time on a server running a clean install of TufinOS 2.15 or above, requires TOS R18-1 or above.
l Upgrading or installing on a server after you have upgraded the server to TufinOS 2.15 or above, requires one of the following TOS ver-
sions:
l TOS R17-3 GA or above
l TOS R17-2 HF2.2 or above
l TOS R17-1 HF4.1 or above
l TOS R16-4 HF5.1 or above
l If you are running TOS R16-3 or below you must first upgrade TOS to the desired version using the latest hotfix available, and then upgrade
TufinOS.
4
When you import new matrices after an upgrade, the name of the zone is taken from the CSV without being renamed.
l If you are running a Distributed Deployment architecture, the upgrade will transfer the SSL certificate from the Distribution Server to the Cen-
tral Server. The installation script will prompt for the SecureTrack administrator account credentials, so have the credential information avail-
able prior to beginning the upgrade.
l If you use CA-signed SSL certificates, you must use the SSLCertificateChainFile directive rather than the SSLCACertificateFile dir-
ective. See TufinOS Prerequisites or Non-TufinOS Prerequisites in the Security Essentials section of the Knowledge Center.
l The final supported release of the Tufin Orchestration Suite for the Tufin T500, T1000, and T1000XL appliances will be TOS R19-2. Tufin
announced End of Sales for these appliances in December 2013. The successor appliances are the T510, T1100, and T1100XL.
l From R19-2 and above, Tufin will enforce maximum session duration settings for SecureTrack and SecureChange, including for the REST
APIs.
l Preserve your SSL certificate and configuration customizations during an upgrade to Tufin Orchestration Suite. See Customizing SSL or Vir-
tual Host Configuration for details. (for R17-3 HF3 and above)
l Prior to upgrading to R17-3 or above you must fill in the "Administrator DN" field (SecureTrack > Settings > Configuration > External
Authentication). After the upgrade has completed, the title of the field will be renamed to "LDAP Bind DN".
l If your TOS deployment uses a Distributed Architecture configuration, you may need to upgrade sTunnel. See sTunnel Patch Installation
Instructions in the Customer Portal for details.
l Policy Advisor reached its “end of life” (EOL). Use the expanded and enhanced capabilities provided by SecureChange Designer to plan and
provision changes to device policies.
l For Check Point R80.x devices, when you upgrade from R18-3 and below to R19-1 and above, a new revision is automatically retrieved.
After upgrading, Compare Revisions may show changes for all the existing network objects.
Before you upgrade, make sure you have a recent (from ≤ 3 months) Check Point Jumbo Hotfix version installed on your R80.x device. See
the relevant Check Point Support Center article for more information on how to verify which Jumbo Hotfix version is installed.
5
SecureTrack Release Notes
Resolved Issues in SecureTrack R19-1
SecureTrack version R19-1 HF3 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
Device AUT-20820 For Palo Alto Panorama Next Generation firewall devices, implemented fix to avoid conflicts between old gen-
Monitoring eric NAT rules and new monitored NAT rules *on revision retrieval. (SR47919)
SecureTrack version R19-1 HF2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
Device Mon- AUT-11816 For Fortinet FortiGate version 6 devices both with and without associated
itoring VDOMs, resolved issue affecting revision parsing caused by a new internet ser-
vice in the version. (SR47568)
Device Monitoring AUT-18779 For Cisco FMC Firepower devices, resolved issue of SSH key settings mismatch for imported child
devices. (SR46426)
Device Monitoring AUT-18987 Improved revision retrieval for Cisco FMC version 6.2.3.x devices with large policy configurations (>
120 policies) caused by a Cisco restriction of 120 requests per minute for these devices. (SR47143)
Device Monitoring AUT-19017 For Cisco ASA devices, fixed revision retrieval issue for Cisco ASA devices with auto-enable con-
figured. (SR46560)
Device Monitoring AUT-19018 For Juniper MX devices, resolved issue affecting revision retrieval by improving the configuration
parsing on client devices. (SR43378)
Device Monitoring AUT-19125 For Azure devices, resolved revision retrieval to treat the internet object as the same regardless of
the letter case, for example "internet" and "INTERNET". (SR43547)
Device Monitoring AUT-19141 For Cisco IOS-XR devices, resolved issue where revisions failed to retrieve or display when the run-
ning configuration contained a "port-group" or "net-group" object. (SR46008)
Device Monitoring AUT-19241 Ability to add a Nexus switch that contains destination groups. (SR46572)
Device Monitoring AUT-19350 For Stonesoft SMC, resolved issue where elements that were in the device trash prevented
SecureTrack from retrieving policy revisions. (SR46724)
Device Monitoring AUT-19608 For Check Point devices, improved management of imported cluster firewalls when performing a
Commit in Designer. (SR47625)
Device Monitoring AUT-19745 For Cisco IOS-XR devices, improved revision retrieval after terminal length default was adjusted.
(SR46695)
Device Monitoring AUT-20128 For Fortinet FortiManager devices, improved revision retrieval when interface to zone mapping is
configured. (SR46564)
Device Monitoring AUT-20651 For Fortinet FortiManager devices, using the forward slash character "/" no longer causes a failure
to retrieve a revision. (SR47149)
Display AUT-19138 Improved page loading performance for many SecureTrack pages, including Interactive Map,
Dashboard, USP and Zones, even in systems with many devices and zones. (SR37423)
High Availability AUT-20845 MongoDB HA configuration no longer overridden after TOS upgrade. (SR36924)
LDAP AUT-20267 Altered memory allocation for the LDAP cache service, does not change after upgrade. (SR47625)
Licensing AUT-18225 For management domains without devices (including Palo Alto Panorama Device Groups, Fortinet
Fortimanager ADOMs, and Cisco FMC domains), improved the messaging to inform users to add
a licensed firewall to these management domains to continue receiving revisions for them.
(SR45361)
Licensing AUT-20070 Improved data retrieval in SecureTrack license page after adding SecureApp licenses. (SR47573)
Reports - Rule AUT-18782 For Cisco ASA firewall devices, resolved issue that caused the Rule and Object Usage report to fail
and Object Usage when object-group-search access-control optimization was enabled. (SR45983)
Reports - Rule AUT-19086 Resolved issue where the Rule and Object Usage report incorrectly identified a rules as having
and Object Usage changed, when the actual change occurred prior to the start date selected for the report.
(SR45141)
System AUT-19138 Improved page loading performance for many SecureTrack pages, including Interactive Map,
Dashboard, USP and Zones, even in systems with many devices and zones. (SR37423)
Topology AUT-18482 For Cisco Firepower Management Center devices resolved issue affecting dynamic topology and
revision retrieval related to commands run in the incorrect context. (SR45649)
6
Topology AUT-19605 Improved post-topology violation calculations, which now removes excluded devices from the Viola-
tions browser. (SR37423)
Zones AUT-19677 For Cisco Firepower Management Center devices, selecting "log" in the Logging option within
Designer creates a rule with the appropriate log. (SR47224)
Zones AUT-19686 Improved display of selected zones in zone hierarchy. (SR46972)
SecureTrack version R19-1 HF1.2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
SecureTrack version R19-1 HF1.1 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureTrack version R19-1 HF1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
7
logy tables. (SR45875)
Topology AUT-18139 For Cisco IOS XR router devices, improved performance for revision retrieval as well as reducing time
to retrieve Dynamic Topology. (SR38085)
Topology AUT- 18144 For Cisco router devices, improved vrf parsing of replicated routes for Dynamic Topology path ana-
lysis. (SR44306)
Topology AUT- 18456 For Fortinet FortiManager devices, improved dynamic topology retrieval to include the secondary IP
address of the management interface. (SR46360)
Topology AUT-18653 Improved the efficiency of retrieving topology query results. (SR37423)
Topology AUT-18527 Enhanced security: In MSSP mode, only a Super Administrator /Multi-Domain Administrator user with
the relevant permissions can run all Topology REST APIs. (SR 47577, SR47834)
SecureTrack version R19-1 GA includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
Rule and AUT- For Palo Alto devices, resolved issue of syslog message processors sim-
Object Usage 15263 ultaneously inserting rule usage data into a table. (SR44309)
8
Cleanups AUT-15662 For Check Point R80 CMA devices, a miscalculation in the revision resulted in an increase in the number of
unattached network objects. The miscalculation also affects the Unattached Network Objects report: The
report includes network objects that are actually attached and referenced by rules. (SR43486)
Platform Support
1. SecureTrack SNMP MIB does not support HP OpenView.
2. Red Hat Enterprise Linux versions 3 and 4, and CentOS version 3 and 4 are not supported.
3. On Tufin appliances, make sure you have a supported TufinOS version installed. You can download the latest TufinOS version from the
Tufin User and Partner Center.
4. When disk usage exceeds 90%, log collection for rule and object usage is stopped. When disk usage exceeds 95%, all SecureTrack pro-
cesses are stopped. To resolve this problem, perform database maintenance.
Make sure that the cleanup settings in Settings > Administration > Maintenance are set for a
longer period than the usage period for the cleanup.
The cleanup is shown in the Dashboard only if the amount of time configured for the usage period
has passed since the upgrade to R13-4 or higher.
The cleanup is shown only if there are hits for every day in the usage period, meaning that the
device will show no results if there was a connectivity problem that resulted in at least one day
9
without getting traffic logs.
AUT-6390 From R18-2, revisions for FortiManager ADOMs record the ADOM version: Thus, after upgrading
from 18-1 (and below) to 18-2 (and above), a new revision is added to each ADOM (even if no
policy change occurred on the ADOM). When comparing the existing revision and the new revi-
sion, it appears as if an ADOM version has been added.
AUT- When upgrading from R18-2 RC1/RC2 to R18-2 GA and above, some saved reports may not
10280 open.
Accountability
1. For Juniper accountability, if changes are made from the NSM, the Administrator and GUI Client are not correctly displayed. This is due to
limitation in Juniper's NSM.
2. For Fortinet accountability, if changes are made from FortiManager, the Administrator and GUI Client are not correctly displayed. This is
due to limitation in FortiManager.
3. For Juniper accountability, if logs are received from the NSM, accountability information and usage analysis for Virtual Systems will not be
supported.
4. For Cisco accountability, hostname and IP address may not always be available. Administrator name is available.
5. For Cisco or Juniper policies, changing the device's logging ID (Cisco), hostname (Netscreen), or log-prefix (JunOS) requires an automatic
revision to take effect. Policy changes made until that revision will not have accountability.
6. Cisco System Contexts in virtual context devices are not supported for accountability. Only automatic revisions are received, according to
automatic revision polling frequency (in the Timing tab).
7. Cisco routers and switches send change logs only when exiting the configuration terminal, not immediately after making the changes. If an
automatic revision occurs before exiting the configuration terminal, the change is recorded without accountability.
Reference Description
ID
5764 If APG crashes with an Out of memory error, run it again with output format: XML or TXT, or use
the APG web interface tool. The TXT output is of similar look-and-feel to the HTML.
5789 When single IP addresses are consolidated into networks, APG may propose redundant
addresses in rules. In Check Point policies the install action will state that these addresses are
shadowed.
6278 The APG may abort when trying to generate a policy for a log file larger than about 1GB.
9592 When you run 'st_apg_collect' on a Check Point CLM with a specific rule_uid, if you see the error
"Note: Rule UID <uid> was not found in the management server's current rulebase", you can
safely ignore the error.
Reference Description
ID
10
6278 Log files larger than about 1GB cannot be uploaded to the APG.
7724 APG supports only TCP, UDP and ICMP protocols.
7480 When creating a new job, very large policies (thousands of rules) are not displayed for rule selec-
tion.
7881 APG jobs need to run for at least 1 hour in order to have results. If you stop the job before an hour
has passed, there will be no results, even if there is a Results link.
8091 If a Check Point rule is changed while an APG log collection job is running, the results will not be
optimal, as traffic hits for the changed objects are not collected for same period as the whole rule.
8091 If a Check Point policy is saved as a new policy while APG collects logs for a rule in the original
policy, the APG continues to collect the logs for the original rule. Installing the new policy can
cause APG to stop collecting logs.
8297 Uploading to APG a file in invalid format produces a message that does not identify the invalid
lines. Please contact Tufin support to identify the problematic lines.
8435 In rare cases, when you have many results in APG, if you expand nodes then you cannot see the
rest of the results. Close the expanded results to see the rest of the results.
9529 Use only alphanumeric characters for APG job names. Other characters are not supported.
9537 When there are many results in APG, not all of the sub-rules are displayed. To see all of the rules
and sub-rules in an exported file, click Save rule set> Replacement rules for export.
13653 If you save a new APG task for a device that is monitored by a Remote Collector and the Remote
Collector is unreachable over the network, the process gets stuck and the task is not saved.
14263 In Settings > Monitoring the name of the SecureTrack server that is monitoring each device is
shown. If you change the name of the SecureTrack server in Settings > System and you see in
Settings > Monitoring that the server name is not changed, you must run this command to set the
server name from the command-line:
Best Practices
Reference Description
ID
11
In general, Best Practices may be affected by issues listed under Policy Analysis.
For Check Point policies, Best Practices does not take User Authentication and VPN settings into
account.
For Juniper and Fortinet policies, Best Practices ignores the VPN settings column.
1652 Check Point Provider-1 global services appear as duplicated services on the CMA’s policy.
9232 When you have multiple objects with the same definition (port / ip), the duplicate objects test in the
Best Practices report shows all possible pairs instead of showing the duplicate objects in the same
line.
10522 If anti-spoofing is disabled for virtual interfaces on VSX clusters, the anti-spoofing check sends an
alerts even though virtual interfaces inherit the anti-spoofing settings.
Change Management
Reference Description
ID
Comments added to JunOS policies (using annotate) do not appear under device configuration,
and changes to them do not trigger new revisions.
JunOS deactivated objects are treated as deleted.
For Cisco ASA version 9.3 or higher devices, SecureTrack does not retrieve revisions if the "for-
ward-reference" option is enabled.
AWS support does not include Amazon’s recently added regions, such as Seoul.
12
9254 If you set rule scheduling on a rule in a Palo Alto policy, SecureTrack records it in its database but
does not display it in the policy. The rule scheduling is taken into account for the Expired Rules
report.
9425 Section titles in Fortinet policies do not display the number of rules in the section.
9854 For Check Point, changes to user IDs and passwords are not included in reporting.
9928 For a large policy, the required memory can exceed 4 GB. To increase the memory used for pro-
cessing a policy, contact Tufin Support.
10763 In Compare, if you do not see the number of retrieved revisions next to each device, click Com-
pare to refresh the page.
10785 When you make a change on a Cisco cluster, username listed for the configuration of the sec-
ondary device is "failover".
11579 For Cisco routers, the "established" option in rules that use TCP is not shown in Compare and it is
not used in policy calculations.
12645 For zone-based Cisco firewalls, when you change the zone assignment of an interface, the
change is shown correctly in Compare but is not shown correctly in the comparison report.
17695 SSL ports that are shown in McAfee devices as SSL_<port> are instead shown in SecureTrack as
TCP_<port>.
23924 If there a problem with the connection between SecureChange and SecureTrack during the pro-
visioning of changes, the new revision is not associated with the ticket.
29739 For Check Point devices, the VPN column is empty for rules with "VPN Match Condition".
30316 Amazon AWS throttles API calls and returns an error when it hits the limit, which is managed by
Amazon. Tufin uses the exponential back-off strategy suggested by Amazon to mitigate this lim-
itation. If you experience delays in Amazon AWS connections, contact aws-support-
pmo@[Link] to increase the limits for your account.
31157 For Check Point devices, a rule with the CDATA tag in the rule comment is only shown in Com-
pare when you compare the revision to another revision.
32234 For devices that allow rules with multiple zones, when you change the zones in a rule the com-
parison shown in Compare is not accurate.
207549 For F5 devices, iApps with pools that are not configured in the same route domain are not shown
in the revision.
211590 After you upgrade a Check Point device to R80 support, a new revision is shown marked with
changes to legacy users, but there are no changes to the users. You can safely ignore this revi-
sion.
213094 When SecureTrack parses a revision, the [Link] file can show an error without an indic-
ation of which revision the error happened on.
Compliance Policies
Reference Description
ID
In general, Compliance Policies may be affected by any of the issues listed under Policy Ana-
lysis.
13
Dashboard
Reference Description
ID
9635 When you add a CLM to SecureTrack, if you run the 'st stat' command and the result for the CLM
is "unknown" license, you can safely ignore this message.
10683 If you import a Check Point gateway with an OS Monitoring license and then reconfigure the gate-
way as a cluster, the new cluster does not have the OS Monitoring license.
10712 If a device license expires, the license is still shown in the Dashboard device tree as active.
10723 If you make a change in your network that effects the topology map, the risk charts are recal-
culated at the scheduled time for Topology synchronization (Settings > Administration > Main-
tenance), or when you synchronize the topology map manually (Network > Topology > Sync).
10805 If you have more than 900 devices, we recommend that you use Firefox.
10810 At resolution 1280x800, the column headings of the Change table in the Dashboard are not prop-
erly aligned.
10845 If you select a domain or vendor group from the device tree, the Risks of devices by severity chart
does not show any data.
11204 For a device that is the parent of other devices (such as virtual contexts and virtual systems), when
you click on the parent device in the Groups device tree you see the Dashboard information for the
device itself and not its children. To see the Dashboard information for the children, click on the
parent device in the Vendors device tree.
11389 You can ignore cleanup instances of shadowing that result from a rule that uses a role access
object in the Source of a rule.
For Check Point policies, when a role access object is used in the source of a rule, the Cleanup
engine considers this as an "Any" value and may determine that the rule shadows another similar
rule.
14279 After you enable or disable risks in Settings > Configuration > Risk, the risk score in the Dash-
board may take some time to update. The risk browser shows the correct score.
Database
Reference Description
ID
The database storage area should not be changed from the default location (/var/lib/p-
gsql/data). If necessary, this path can be pointed to another location with a symbolic link.
If the database package was installed manually rather than as part of the Linux installation, it must
be started before installing the SecureTrack package. To start the database, use either service
rhdb start or service postgresql start , depending on the database type.
Distributed Architecture
Reference Description
ID
Migration from multiple standalone servers to a distributed deployment is not currently supported.
You must migrate before you upgrade. For assistance, contact Tufin Support.
5566 If the clock on a distributed component (Distribution server or Remote Collector) is not syn-
14
chronized with the Central server, revisions from the distributed component are saved with wrong
date and time.
6023 To uninstall TOS from a remote collector or distribution server, you must first uninstall the DA con-
figuration and then run tss uninstall. If the remote collector or distribution server is not con-
nected to the Central server, you can force the uninstall with the command: tss uninstall -
-force
21524 You must install the TOP plugin on the target server before you migrate a TOP device.
Firewall OS Monitoring
Reference Description
ID
2097 The speeds of sub-interfaces and VLAN interfaces are mistakenly reported as 10Mb.
4376 When configuring ignored routes which already appear in the device's previous revisions, a new
revision will arrive in which these routes will appear to have been deleted.
External Authentication
Reference Description
ID
3623 External users email addresses remain in SecureTrack after being deleted in Active Directory.
5170 Defining a local user with the same username as an external user should be avoided. If there is
external user or administrator with a username that is the same as a local user defined in ST, the
external user / admin should login using the domain (in format: username@[Link]).
Licensing
Reference Description
ID
5716 When an Evaluation license expires, the license status of each device is changed only when
SecureTrack tries to fetch a new revision. If the license status is not changed, click Recalculate
in the Licenses page.
5842 In Legacy licenses (not Simplified licenses issued from February 2011), after adding, deleting,
enabling, or disabling a device, license statuses of some devices may not be updated in the
Licenses page (Configure > Administration > Licenses) and Status page (Configure > Admin-
istration > Status). To update the status, click Recalculate in the Licenses page.
7465 In the Licenses page, a green connection status icon appears for Check Point clusters, despite the
fact that connection status for clusters is meaningless. The icon is correctly not displayed in the
Compare and Status pages.
7505 Attaching a license to a device that should affect the license status of another device (for
example: attaching a license to a parent device of virtual devices) does not immediately cause the
updated status to be displayed. To see the updated status, click Recalculate .
9373 When you use Internet Explorer 7, if you go to Settings > Administration > Licenses, you can-
not go to another page until the device list finishes loading.
9635 When you add a CLM to SecureTrack, if you run the 'st stat' command and the result for the CLM
is "unknown" license, you can safely ignore this message.
15
Monitoring and Device Configuration
Reference Description
ID
Cisco zone-based policy firewalls are supported for change management when its policy-map uses
these class-maps:
l ‘match-all’ and ‘match-any’ with only one ACL, or with match-protocol
l ‘match-all’ with one ACL and one match protocol line, or with one ACL and nested class-map of type ‘match-
any’ with many match-protocol lines
l ‘match-any’ with many match-protocol
Changing SecureTrack’s OPSEC object name in a Check Point management server will cause
SecureTrack to lose its connection with that management server. You must redefine the man-
agement server in SecureTrack.
4025 To monitor Check Point management servers of version R70 (MDSs, CMAs, Security Man-
agement servers, Log servers, and CLMs), you must install the Check Point R70 LEA hotfix to
ensure connectivity with SecureTrack.
6070 If MDS monitoring is configured and an incorrect username and password, no revisions are
retrieved for the MDS but there is no indication of the problem.
7149 Trying to cancel the upload of an offline configuration has no effect.
8066 In Check Point R75, the management server's DN is not displayed in Smart Dashboard or in Pro-
vider-1 MDG. Because of this, when adding a standby management server as described in, the
only way to get the DN is from Check Point's [Link] tool.
8318 If a Fortinet cluster is configured in SecureTrack by its virtual IP, SecureTrack fails to connect after
failover. An ssh host key mismatch error message is sent. It is preferable for each cluster member
to be monitored independently. If the cluster must be monitored via virtual IP, please contact
Tufin support.
8279 To monitor a Check Point UTM cluster, do not use the virtual IP. Add the primary management
server using its own IP address. To add the secondary UTM,
8685 When SecureTrack monitors both primary/active and secondary/passive devices that are in a
JunOS or Fortinet cluster and both devices are configured with same logging identification,
accountability and usage data are collected for only one of devices and not necessarily always the
same device.
16
after the first revision include zone or interface information.
10966 If you change the credentials of a device from Settings > Monitoring > Device Groups, the cre-
dentials on the device are changed immediately, but the credentials in the device configuration in
SecureTrack are updated with the new credentials when SecureTrack tries to connect to the
device to retrieve a revision. The status of the device in the Settings > Monitoring > Status and
in all device trees is incorrect until the new credentials are updated in the device configuration.
11013 SecureTrack does not prevent you from saving two queries with the default query name, New Ana-
lysis Query. Make sure you give each query a unique name.
11509 The duplicate service cleanup does not compare:
l Palo Alto - source port and timeout
l Juniper Netscreen - service timeout
l Check Point - protocol type
11819 When you add a Fortigate device with multiple interfaces, if you select "Collect dynamic topology
information", the secondary IP addresses are not shown in the devices topology.
15511 When you configure an Advanced Change report for a FortiManager device, the report runs on the
policies installed on each of the child devices. You cannot select a specific policy to run the report
on.
15455 SecureTrack polls all CSM, NSM and FortiManager devices added to SecureTrack in this version
once per hour.
15475 For Fortigate, if you make a change to an interface of a vdom that is managed by a physical
FortiManager or Fortigate device, you do not receive a new revision with the change to the inter-
face.
18754, In Cisco ASA devices, :
18843, l Interface names with more than 4 words are not supported
18856, l If you change a name object it may be shown as removed and inserted
19575 l When you upgrade to this version rules with time range configuration are shown as modified
l View Policy and Compare display the rule numbers as they appear in the CLI and not in ADSM
19589 In Compare, Juniper NSM devices do not show the interfaces for virtual routers that it monitors.
24100 For Juniper SSG devices managed by NSM, interfaces using SSG default zones do not show the
associated zone in the revision. For Juniper SSG devices managed by NSM, zones using SSG
default virtual-routers do not show the associated virtual-routers in the revision.
24836 For F5 devices, virtual servers must be configured with UDP, TCP, SCTP or Any Protocols. Vir-
tual servers configured with other protocols are not shown in Compare or Policy Analysis.
25094 For Fortigate 5.x devices that are managed by FortiManager 5.x, if there is only the 'root' vdom
then only the textual configuration (running config) is shown in Compare.
25147 To get a revision from a PANOS device that is managed by Panorama, you must first sync the
device.
25272 For VMware NSX, no new revision is retrieved when you delete a datacenter object.
AUT-3879 Cisco devices have a text string limit of 64 characters for object names. If you use a blank space
within an object name, quotation marks (“) are required at the beginning and end of the object
name. These quotation marks are included in the 64 character limit. (SR36940)
17
AUT-8969 For Cisco devices, monitored firewall interface names cannot include the “<” and “>” characters.
This limitation is enforced by Tufin Orchestration Suite to implement Tufin security policies.
(SR39728)
AUT-18154 For Fortinet FortiManager version 6.0.2 devices using ADOMs version 6.0, the Destination field in Compare Revisions
is not populated as it is currently unable to extract the internet service destination within a rule.
Multi-Domain
Issue Description
ID
9392 A non-admin User with permissions for "Any" device cannot view the Topology tab.
10809 If you login as a super-admin and change the context to a domain, you cannot access Settings > Con-
figuration > Risk.
11660 When you migrate some of the child devices to domain A and then migrate the parent device with all
of its children to domain B, the previously migrated devices will also be migrated to domain B.
Notifications
Reference ID Description
5410 SecureTrack heartbeat by SNMP does not work. SecureTrack does not send its status traps.
Object Lookup
Reference Description
ID
13500 When an Object Lookup search shows more than 100 instances, you can click on the arrows to
show another page of instances but the text incorrectly says that the first 100 instances are shown.
PCI-DSS Compliance
Reference Description
ID
28903 For Amazon AWS, when you set a PCI exception on a rule then the exception is removed when
the rule changes.
18
in which it is displayed and not globally.
By design, Policy Analysis Results no longer appears in the Maintenance page. This is
because SecureTrack does not need to cache Policy Analysis data.
6460 In Cisco policies, implicit rules between interfaces with different security levels are ignored for
Policy Analysis.
7157 Section titles of Fortinet policies do not appear in Policy Analysis results.
8415 In Policy Analysis results, tool-tips for network objects only show the object's management IP
address.
10369 When you select a device or policy for a query, you cannot select a device group or a vendor group,
and you cannot multi-select targets.
10428 Policy Analysis ignores these rules in its calculations: rules with actions other than Accept, Deny or
Reject; rules with non-Any VPN community
Policy View
Reference Description
ID
3983 When a policy contains thousands of rules, some policy views, except View Policy, cannot be dis-
played (an informative message is displayed instead). For comparison of large policies, it is recom-
mended to use Generate Report rather than Compare . You can also set the maximum number
of rules that SecureTrack can display. To do this, contact Tufin Support.
4958 In the services list of a Cisco router’s policy, some TCP services are shown also as UDP, and vice
versa. This is because they are preconfigured this way by Cisco.
5010 ACL numbers for Cisco routers may not match the routers' numbers.
5669 Since support for Fortinet 4.0 has been added, all Fortinet policies are displayed with rule
sequence numbers, which are meaningless for Fortinet 3.x. These numbers in Fortinet 3.x policies
should be ignored.
Reports (General)
Reference Description
ID
6361 For reports and query configuration, only one Check Point policy per installation target is available:
the last policy that was modified, installed, or created on the management server.
6512 When you change the logo, on-demand reports and queries executed soon afterwards sometimes
continue to display the old logo. In this case, refresh the browser.
9647 The SecureTrack server cannot be used as the destination server for Export reports using SCP, in
Settings > Configuration > Reports.
9221 When a device has multiple policy packages and over 1000 NAT rules, reports may fail due to
memory consumption.
10520 When you export reports using user-defined scripts, SecureTrack parameters in the script cannot
include spaces.
10522 For Best Practices, if anti-spoofing is disabled for virtual interfaces on VSX clusters, the Best
Practices anti-spoofing check alerts you even though the virtual interfaces inherit the anti-spoofing
19
settings.
Mailed Reports
Reference Description
ID
Large reports may fail to be sent by email. This may be caused by a mail server limitation or to
SecureTrack limitations. To work around this issue, you can configure the report to be saved in the
Reports Repository and send a link to the report. Sending the report as PDF or MHT may help
overcome potential SecureTrack limitations.
Reports received in Lotus Notes may be improperly formatted. You can send the report in either
PDF or MHT attachment format, or save the report in the Reports Repository.
If SecureTrack is installed on a server with multiple IP addresses, email reports and notifications
may contain links to an incorrect IP address. To resolve this, you can define the server name
under Settings > Configuration > Notifications.
1491 Reports may lose formatting when forwarded. As a result, the report may be incorrectly displayed
in the forwarded message. You can send the report in either PDF or MHT attachment format, or
view the report in SecureTrack's web interface.
1748 Embedded links in MHT reports do not work properly.
1876 When accessing group members or a saved report through a link in a mail report, the user’s start
page may be displayed after login. The correct information will be displayed on the second
attempt.
8237 In mailed reports, Zone tooltips display the zone's internal ID instead of the zone name.
20
ID
6684 The second stage of the Rule Change report fails because policies with thousands of rules cannot
be displayed. To change the number of rules that can be displayed, contact Tufin Support.
PDF Reports
Reference Description
ID
The amount of time for generating PDF reports in SecureTrack depends on the processing load on
the SecureTrack machine.
7291 On rare occasions, reports that are saved in the repository will not open as a PDF because of the
memory limitations of the PDF engine. If this occurs, you can split the report into multiple smaller
reports (for example, per device or policy).
21
Rule Usage is not supported for Cisco PIX of versions lower than 6.3.
By design, no object usage is collected for rule fields (source/destination/service) with Any or Neg-
ate . If the rule field is changed during a usage report period, the number of object hits can be
lower than the total hits on the rule because some hits on the rule where on the previous rule con-
figuration for which object usage data was not collected.
For JunOS devices of version lower than 10.0, hits are not counted for rules with identical names
in different security policies. This may cause used rules to incorrectly appear as unused.
For JunOS policies, ICMP packets are not counted for object usage of rules that permit ICMP
traffic for more than one ICMP type. This may cause inconsistencies between rule usage and
object usage, and may cause used objects to incorrectly appear as unused.
For Fortinet Fortigate devices, FQDN objects are not included in rule and object usage statistics.
2380 In a Cisco usage report, disabled rules are not displayed under unused rules.
7940 Check Point usage collected before a first Install revision may be inaccurate.
9699 Rule Usage data is not collected for Juniper, Check Point or Fortinet devices that are monitored
with periodic polling.
9711 If you run the Rule Usage report on a policy with tens of thousands of rules, the report takes more
than a day to finish and may crash if more than one Rule Usage report is running.
210243 For Panorama devices, if an object is overridden the report may not accurately reflect the actual
number of hits.
Rule Documentation
Reference Description
ID
7333 If in SmartDashboard a Check Point policy is duplicated with Save As, and defined for a different
target installation group, SecureTrack Rule Documentation metadata is correctly carried over to
the new policy. If the Rule Documentation metadata for the new policy is subsequently edited, it
incorrectly changes for the original policy as well.
7465 In the Rule Documentation page, a green connection status icon appears for Check Point clusters,
despite the fact that connection status for clusters is meaningless. The icon is correctly not dis-
played in the Compare and Status pages.
7480 Very large policies fail to be displayed in the Rule Documentation page. To change the number of
rules that can be displayed, please contact support.
7535 Pasting with the mouse (right-click > Paste) into the Business Owner and Rule Comment fields of
the Rule Documentation Filter or Documentation Editor does not enable the Apply button.
Either paste with the keyboard, or subsequently add or delete a character to enable the button.
8087 Tooltips in the Rule Documentation page blink.
9630 When you apply a filter in the Rule Documentation page, the number shown for the number of res-
ults is not updated when there is a new revision. The filtered results show all relevant rules.
9805 When SecureTrack receives an error from a device that the policy is unreadable, the rule doc-
umentation details for the policy cannot be shown. For more information, contact Tufin Support.
10664 If you select a technical owner with a name that is more than 20 characters, you cannot filter rule
22
documentation for technical owner.
10863 If you filter rule documentation by a field and edit that field in a rule, the field is unselected in the
filter.
Rule Documentation only lists policy rules that match SecureChange access requests with the
"Accept" action.
If you change the name of an application in SecureApp that has rules associated with it in rule doc-
umentation, the name is not updated in rule documentation.
18108 When you change the comment in rule documentation for a rule that was added as an exception
to a PCI DSS profile, the rule is still in the list of exceptions even though it no longer violates that
PCI DSS test.
18343 If SecureTrack receives a new revision while rule documentation is open, you must refresh the
page to see the new data.
System Settings
Issue Description
ID
9511 When you change the hostname of the server with the hostname CLI command, make sure that the
/etc/hosts file is also updated.
22742 You can only turn off the browser autocomplete setting for these browser versions or lower: Mozilla
Firefox 29, Google Chrome 33, Microsoft Internet Explorer 10
TOP
Reference Description
ID
7007 Some TOP plugins available on the Tufin TOP plugin download page are based on RANCID.
These do not support passwords with special characters such as dollar sign ($). The plugins that
are prepackaged in SecureTrack are not affected by this issue.
Topology
Reference Description
ID
There may be problems with Topology for Nokia/Check Point IP appliance gateways. If this
occurs, please contact Tufin Support.
For Check Point devices, Topology is only supported for version NGX R60 or above.
6920 Manual topology changes to Check Point management servers are not reflected in SecureTrack
topology.
7427 When both a primary and secondary Check Point management server (SmartCenter or CMA) are
monitored, managed gateways appear twice in Topology. They appear once under each man-
agement server.
7670 SecureTrack does not correctly calculate topology for VSX advanced routing configuration.
Source addresses are ignored.
7808 Topology information is not collected for VSX gateways configured in bridged mode.
8606 Topology information is not shown for Check Point offline analysis. Check Point offline files do not
23
include topology data.
8741 When a device has a LAN interface and a WAN interface, if you add a route that its next hop is in
the WAN interface then you must manually set the network type for that network to External.
8830 After you click Synchronize to collect the latest topology data, the duration of the synchronization
process depends on the size of your deployment. When the synchronization process finishes, click
the Topology tab to refresh the topology map.
8991 Topology is disabled by default during the upgrade if you have more than 25 devices because it
requires more system resources than in 5.3.
You can enable topology for each device or contact Tufin Support to enable topology on many
devices from the CLI.
9085 If the default gateway for a NetScreen device is configured in the interface's configuration instead
of in the device's routing table, enable dynamic routing for the device to get the correct default
gateway.
9102 When you do synchronization for the topology map, any changes that you make before the syn-
chronization is finished are not saved.
9105 Topology does not use route precedence for topology calculations.
9755 Topology information is not gathered for Check Point clusters on non-ClusterXL appliances.
10855 After you delete an interface from a VSX cluster and click Synchronize in Topology, the interface
is shown in the topology map.
30381 Changes made to the Topology are shown in the interactive map only after you synchronize the
topology.
User Management
Reference Description
ID
623 Some special characters are not supported for user account details.
2005 When you give SecureTrack users (not Administrators) access to "Any" device, the user will not
have access to devices added later on. To work around this problem, once new devices have been
added, open the user's settings and select "Any" again.
29954 When a super admin views the list of users of a specific context, multi-domain users are not shown
in the list of users.
Web Interface
Reference Description
ID
If you add SecureTrack's certificate to the browser to prevent the non-signed certificate warning,
changing SecureTrack's IP address or hostname may cause the warning to begin appearing again.
In this case, renew the certificate in SecureTrack and in Internet Explorer.
6316 When generating a SecureTrack diagnostic file (Settings > Administration > Diagnostics), the
download may take a long time (depending on the amount of data, sometimes more than an
hour).
7852 After logout or the browser session expires, if you use a direct URL or link to SecureTrack
24
([Link] instead of the login link, an error message is displayed. The message can be
safely ignored.
9770 The IP address of the SecureTrack server that is shown in Settings > Administration > Status
can be an IP address other than the primary IP address of the server.
Zones
Reference Description
ID
8069 If all zones are deleted while some subnets are selected, Delete selected subnets and Change
selected subnets are enabled, even though no change can be made.
8075 Editing a subnet may cause its location in the list to change, and as a result it may disappear from
the display. Scroll down and/or advance pages to find it.
8109 Trying to change the parent zone of multiple subnets, when one of the subnets already exists in
the target zone, results in a message that does not specify which subnet(s) are causing the prob-
lem.
8119 In the SecureTrack zones list located in various report and query configurations, the zones are not
listed alphabetically. You can still browse the list using the first letter of the zone name.
8123 Changing a zone in the Zone Hierarchy tab may cause its location in the list to change, and as a
result it may disappear from the display. Scroll down to find it.
8136 Zone management is supported for screen resolution 1280x1024 and above.
8190 In Network > Zones, if you change the size of the browser window you cannot use the zone list.
8199 If a zone in an imported CSV file does not contain subnets (only zones), subnets that already exist
in the zone in SecureTrack are not deleted.
8202 When selecting all zones and deleting them, All zones is selected and disabled. If the user
imports a CSV file at this stage, all the imported zones appear as selected but no subnet/zone is
displayed in the right pane. To resolve the problem, clear All zones and then select zones.
8283 Zones with no subnets are not exported.
18439 In Internet Explorer, you cannot import zones from a CSV file.
32124 When you enter 0::0/0 or [Link]/24 for the source or destination of an access request, the Secur-
ity Zones tool matches the entry to all IPv4 and IPv6 addresses.
AUT-3955 A rule with a host object configured with NAT is treated as a USP violation for host-to-host flows.
25
SecureChange Release Notes
Resolved Issues in SecureChange R19-1
SecureChange version R19-1 HF3 includes these resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureChange version R19-1 HF2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureChange version R19-1 HF1.2 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureChange version R19-1 HF1.1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
SecureChange version R19-1 HF1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
SecureChange version R19-1 GA includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
26
Platform Support
1. Red Hat Enterprise Linux versions 3 and 4, and CentOS version 3 and 4 are not supported.
2. On Tufin appliances, make sure you have a supported TufinOS version installed. You can download the latest TufinOS version from the
Tufin User and Partner Center.
Access Requests
Reference Description
ID
8200 Individual VSX cluster members (virtual routers or virtual FW) are available in the target browser,
even though you are not allowed to use individual members. Verification will fail.
10717 After a request is assigned, the requester cannot see the labels of the ticket in My Requests.
11240 If you name a device in the format of an IP address (x.x.x.x), you cannot use the format
device_name/object to enter an object in the source, destination or service fields of an
Access Request. To work around this, you can change the name of the device or use a different
format.
11241 If you have two devices with the same name, you cannot use the format device_name/ob-
ject to enter an object in the source, destination or service fields of an Access Request. To work
around this, you can change the name of the device or use a different format.
15131 If an access request with a Fortigate target uses the IP address of an object instead of the object
name, the advisor doesn't recognize that the IP address already exists in the device as an object.
16272 Netscreen domain objects are not shown in the list of objects.
16542 When there is no firewall between the requested source and the destination, no target can be sug-
gested.
16670 An object from a device with an IPV6 address is not referenced in SecureChange.
23447 Access Request will always run with "ANY" in the users field on next-generation firewalls.
30850 When you create two requests, submit save or submit one and save the second request, if you
leave the page of the second request without saving changes and then cancel the first request,
the name of the second request changes to the name of the first request.
30944 You cannot open the automation tool results that were calculated before upgrading to this
release.
215546 When you request more information, the settings for finding LDAP users apply to all
27
SecureChange users.
Designer
Reference Description
ID
When you update the policy of a Cisco device, the changes are saved to the running-config. If you
want to make the changes persistent, save the running-config to the startup-config.
When the device is connected to SecureTrack by SSH, it is not possible to perform Update
Designer commands.
It is not possible to do Update Device in step 1 of the ticket.
Designer does not suggest to replace a source, destination, or service from a rule.
15478 When you configure an access request with the Designer and Allow update only, the user can
incorrectly also edit the Designer suggestions.
15494 If the data in the Topology map is not up-to-date, you can get incorrect Designer suggestions. To
make sure you Topology data is up-to-date, click Synchronize in the Topology section of
SecureTrack.
15579 You cannot run Designer for an access request that contains a subnet with a non-continuous net-
mask.
16479 For Juniper Netscreen devices, the Designer may suggest to add a VIP or DIP object when the
access request includes the IP address of the object.
16512 The Designer indicator on the left side of each access request field shows the result for all access
requests in the ticket, instead of the result for each individual access request.
16800 The Designer can suggest changes to a policy that only has global rules, but it cannot implement
the changes.
17626 After you run and save Designer results, you cannot change the fields that specify the rule loc-
ation.
17972 When you have the Designer enabled for the first step in a workflow, after you run the Designer
you must save it as a draft before you submit the request in order to save the Designer results.
18539 When you have an access request that specifies traffic that matches an existing rule that has a
range object, the Designer suggests creating a new rule instead of editing the existing rule.
19494 If you add a Palo Alto device to SecureTrack without its Vsys, an exception occurs when you run
the designer on a topology that contains the Palo Alto device.
29425 A ticket opened in Designer for a connection that contains a group name that contains a space are
28
not implemented for Cisco ASA devices running version 8.3 or below. Support for spaces in a
name was added by Cisco in ASA 8.4.
Workaround : Use names that do not include a space if you are running Cisco ASA 8.3 or below.
Replace the space with an underscore or another supported non-blank character.
31279 When you create a new request and run Designer before you submit the request, the Designer res-
ults are deleted when you submit the request.
30846 You cannot search for tickets by an IPv6 address that contains a double-colon (::).
213023 For Cisco ASA 9 or higher, when you have a rule with an inline group containing IPv4 and IPv6
addresses in the source and destination and you create a matching access request with an addi-
tional IPv4 source and an additional IPv6 destination, Designer suggests to create a new rule
instead of editing the source and destination of the existing rule.
AUT- For Palo Alto Panorama NG devices in a server decommission task, when Designer suggests over-
13742 riding local network object properties from a local rule in the upper level of a hierarchy, the same
modifications are suggested as manual changes for objects in lower levels.
General
Reference Description
ID
8368 When the IP address or URL of SecureChange is changed, change the URL in email notifications
at Settings > Miscellaneous > Server DNS name .
15334 In Internet Explorer 9, if you open a hyperlink from a ticket, the window opens without a scrollbar
and maximize is disabled.
You can only select network objects of these types in SecureChange ticket fields: gateway_ckp,
host_ckp, connectra, interspect, gateway_cluster, cluster_member, sofaware_gateway,
sofaware_gateway_profile, vsx_box, vs_cluster_member, vs_cluster_netobj, vsx_cluster_mem-
ber, vsx_cluster_netobj, vs_netobj, mygw_EVR, vsx_netobj, embedded_device, host_plain, inter-
face, network, network_object_group, group_with_exception, gsn_handover_group, address_
range, multicast_address_range
You can see the type of a device in the “class_name” field of the REST APIs that return network
object details, for example: /network_object/search
Licensing
Reference Description
ID
9541 SecureChange shows the Not Licensed status when SecureChange cannot connect to the
SecureTrack server, even if SecureChange is licensed.
Modify Group
Reference Description
ID
AUT- Limitation: In the Modify Group workflow, Designer is unable to prevent the mutual inclusion of
11311 groups in the case of overridden or overriding groups.
AUT- Resolution: An error message is displayed stating that Designer failed to run and to which groups
29
13102 the mutual inclusion applies.
12939 If you configure a step with both Modify Group and dynamic assignment, the Modify Group field
does not show the group selected in a previous step.
13384 You cannot modify Check Point global objects.
Multi-Domain
Reference Description
ID
You cannot configure the logo and background for domains, and the Domain field is not shown in
the ticket details page.
13734 In Multi-Domain segregated mode, when you send an email to SecureChange in order to open a
ticket, the ticket is opened in the Default domain.
13837 When Multi-Domain mode is enabled, you cannot configure a dynamic assignment condition
based on a specific target. You can configure the condition based on the target containing or not
containing a target.
Policy Advisor
Reference Description
ID
4709 In some cases the Policy Advisor may suggest implementation that will fail verification in Check
Point SmartDashboard. This happens when the suggestion creates unnecessary shadowing in the
policy. This can be fixed by removing the redundant traffic.
9556 Policy Advisor suggests changes to the Global rules of the device. Warning: the changes will also
change other policies on the device.
15131 If an access request with a Fortigate target uses the IP address of an object instead of the object
name, the advisor doesn't recognize that the IP address already exists in the device as an object.
SecureChange API
Reference Description
ID
8752 Make sure you enter unique names for Scripts and Mailboxes. Entering unique names for Scripts
and Mailboxes is not enforced.
8766 When you run multiple SecureChange API tasks that are dependent and one of the tasks fails,
only one task shows that it is stopped. The other dependent tasks are stopped, but they are listed
in Tasks handler without a status.
30
9142 SecureChange only reads the first 4000 characters of emails sent to a SecureChange API mail-
box.
E-02342 The /devices/excluded REST API will not exclude child devices of a
management device (such as FortiManager from R16-2 above, or Pan-
orama from R16-3 and above) if multi-domain on SecureTrack is
enabled and the child device does not reside on the same domain as
the parent management device. You must explicitly exclude any child
devices that reside on a different MSSP domain.
System Settings
Issue Description
ID
9511 When you change the hostname of the server with the hostname CLI command, make sure that the
/etc/hosts file is also updated.
22742 You can only turn off the browser autocomplete setting for these browser versions or lower: Mozilla
Firefox 29, Google Chrome 33, Microsoft Internet Explorer 10
Target Suggestion
Reference Description
ID
7427 When monitoring both a primary and secondary Check Point management server (SmartCenter or
CMA), managed gateways appear twice in target suggestions.
7808 VSX gateways configured in bridged mode are not suggested as Access Request targets.
Tasks
Reference Description
ID
9301 When an administrator (admin1) completes a task, the ticket goes to another administrator
(admin2). If admin2 sends the ticket back to the previous task (Redo) then the ticket is assigned
back to admin1. When the redo is complete, the ticket is assigned according to the workflow con-
figuration, and is not automatically assigned back to admin2. This behavior is by design.
14175 If you search for the field value "in-to-out", the results also include the field value "out-to-in".
14766 If you open a link to an expired ticket, when you close the window the list of tasks does not show
the correct query.
16460 If you redo a task that was assigned by manual assignment, the task must be assigned again.
17010 When you save a search query that is not valid, an error message is shown when you change tabs.
17012 When you enter a multiple word search value, you must use quotations marks. Otherwise, each
word is processed as a search value.
18950 If you reopen a ticket that has a step that was redone, the Redo and Reopen banner is shown on
every step in the ticket.
User Management
Reference Description
ID
31
9477 When you delete a user, the user is still shown as a member of the groups. Logout and Login to
refresh the display.
13098 When you configure permissions for an LDAP group that has another LDAP group as a member,
the member group is not shown to inherit the permissions from the parent.
13306 If you configure an LDAP server as active and standby such that there are duplicate users in the
SecureChange database, attempting to login as a duplicate user causes an exception that pre-
vents any user from logging into SecureChange. Contact Tufin support for assistance.
16937 If you add or remove LDAP users during LDAP synchronization process, this causes an error.
19901 When a ticket is assigned to a group and the user that accepts the ticket is out of the office, the
out of the office banner is not shown.
212240 When you add an LDAP group or local group as subgroups to a local group, the members of the
subgroups are not shown in the list of users for step assignment and the members of the subgroup
are not included when the group is assigned to a step.
213037 The LDAP servers are shown in alphabetical order
and does not represent that order in which the servers
are checked for new SecureChange logins, which is
done in the order that the LDAP servers are added to
SecureChange.
215517 When you add LDAP groups to the source of an
access request from the Advanced Options menu and
apply the changes, the LDAP groups are not shown in
the access request after you submit the request.
Verification
Reference Description
ID
223488, There is a known issue in Internet Explorer 11, in which extremely large images (>4 MB) are not
223359 displayed properly. If you are running Verifier in Internet Explorer 11, extremely large topology
images for an Access Request may fail to display correctly.
Workaround : Use Firefox or Chrome, or use the REST API to retrieve the image URL reference.
223488, For performance reasons, Verifier does not automatically display large topology images (>400 KB)
223359 for an Access Request. Click the link provided in Verifier to display the image in a separate
browser window.
Cisco zone-based policy firewalls are supported for verification when its policy-map uses these
class-maps:
l ‘match-all’ and ‘match-any’ with only one ACL, or with match-protocol
l ‘match-all’ with one ACL and one match protocol line, or with one ACL and nested class-map of type ‘match-
any’ with many match-protocol lines
l ‘match-any’ with many match-protocol
11916 For large environments, the topology map that is shown for Verify may be blurry.
32
Workflows
Reference Description
ID
11576 For steps that are marked with a warning that the step requires configuration, after you configure
the step you must save the workflow in order to remove the warning mark.
12107 When you configure a dynamic assignment task, if you search for a user that does not exist, when
you close the Select User window then the task is not shown. If this happens, refresh the page to
see the complete task list.
16974 You cannot add a dropdown list or multiple selection field when two of the options in the field are
the same.
17005 You cannot delete an Approve/Reject field from a step when one of the options is selected.
32351 When you add a device to the list of excluded devices, tickets created from workflows that have
the device in the target field of an access request are invalid. To repair the workflow so that you
can open valid tickets from it, you must remove the excluded device from the target field of the
access request in the workflow.
AUT-1894 On occasion, a request based on a workflow using dynamic assignment in an auto step will get
stuck in the auto-step.
Workaround:
2. Modify the workflow step to use an assignment mode that is not dynamic assignment
33
SecureApp Release Notes
Resolved Issues in SecureApp R19-1
SecureApp version R19-1 HF2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
SecureApp version R19-1 HF1.2 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureApp version R19-1 HF1.1 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureApp version R19-1 HF1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:
SecureApp version R19-1 GA includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
Architecture 18216 In very rare instances within a Distributed Server environment the connection analysis
calculations may not complete.
Resolution: Refresh the topology map. A refresh automatically takes place once a day
during the night. To refresh manually, in SecureTrack select Network > Interactive
Map and click the Synchronize button. When the Sync Topology Map screen
appears, select the Fast Topology Sync o ption and click the Sync button.
34
Connection McAfee device policies are not included in connection analysis calculations. If a
Analysis McAfee device is found to be in the path of a connection, connection analysis assumes
that the device policy accepts all traffic.
Connection 14674 You cannot view the connection analysis after a user starts SecureTrack topology syn-
Analysis chronization, until the synchronization is complete.
Connection 22424 SecureApp does not currently support application identities in connection definitions
Status and therefore the application field value is assumed to be "Any" for connection status
calculations.
Connection 208140 When you enable Multi-Domain segregated mode, connection status and analysis are
Status not accurate.
Display 12483 In Internet Explorer 8, the SecureApp user interface may respond slowly to your
actions.
35
Patents and Trademarks
See [Link]/patents for patent details.
Trademarks
Tufin, SecureChange, SecureTrack, Automatic Policy Generator, and the Tufin logo are trademarks of Tufin Software Technologies Ltd. All other
product names mentioned herein are trademarks or registered trademarks of their respective owners.
Some TOP plugins include software developed by Terrapin Communications, Inc. and its contributors for RANCID.
36