0% found this document useful (0 votes)
8 views36 pages

TOS R19-1 ReleaseNotes

The document provides release notes for Tufin Orchestration Suite R19-1, detailing resolved issues, upgrade instructions, and additional important information. It includes specific notes for SecureTrack, SecureChange, and SecureApp, along with known issues and improvements made in the latest version. Users are advised to follow specific upgrade paths and to be aware of changes related to SSL certificates and licensing.

Uploaded by

97kwyam
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views36 pages

TOS R19-1 ReleaseNotes

The document provides release notes for Tufin Orchestration Suite R19-1, detailing resolved issues, upgrade instructions, and additional important information. It includes specific notes for SecureTrack, SecureChange, and SecureApp, along with known issues and improvements made in the latest version. Users are advised to follow specific upgrade paths and to be aware of changes related to SSL certificates and licensing.

Uploaded by

97kwyam
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

by

Release Notes
Version R19-1
Contents
Contents 2
R19-1 HF2 Release Notes 4
Resolved Issues Included From Previous Releases 4
Upgrading Tufin Orchestration Suite 4
Upgrading TufinOS 4
Additional stuff you need to know 4

SecureTrack Release Notes 6


Resolved Issues in SecureTrack R19-1 6
Known Issues in SecureTrack R19-1 8
Known Issues from Previous Releases 9
Platform Support 9
Installation and Upgrade 9
Accountability 10
Automatic Policy Generator (CLI) 10
Automatic Policy Generator (Web Interface) 10
Backup and Restore 11
Best Practices 11
Change Management 12
Compliance Policies 13
Dashboard 14
Database 14
Distributed Architecture 14
Firewall OS Monitoring 15
External Authentication 15
Licensing 15
Monitoring and Device Configuration 16
Multi-Domain 18
Notifications 18
Object Lookup 18
PCI-DSS Compliance 18
Policy Analysis and Business Ownership 18
Policy View 19
Reports (General) 19
Advanced Change Report 20
Baseline Settings Compliance Report 20
Business Ownership Report 20
Mailed Reports 20
Rule Change Report 20
PDF Reports 21
Security Risk Report 21
Software Version Compliance Report 21
Tufin Device Audit Report 21

2
Rule and Object Usage 21
Rule Documentation 22
System Settings 23
TOP 23
Topology 23
User Management 24
Web Interface 24
Zones 25

SecureChange Release Notes 26


Resolved Issues in SecureChange R19-1 26
Known Issues in SecureChange R19-1 26
Known Issues from Previous Releases 26
Platform Support 27
Installation and Upgrade 27
Access Requests 27
Dashboard and Reports 28
Designer 28
General 29
Licensing 29
Modify Group 29
Multi-Domain 30
Policy Advisor 30
Rule Decommission Limitations 30
SecureChange API 30
System Settings 31
Target Suggestion 31
Tasks 31
User Management 31
Verification 32
Workflows 33

SecureApp Release Notes 34


Resolved Issues in SecureApp R19-1 34
Known Issues in SecureApp R19-1 34
Known Issues from Previous Releases 34

Patents and Trademarks 36

3
R19-1 HF2 Release Notes
Resolved Issues Included From Previous Releases
Tufin Orchestration Suite R19-1 HF2 includes all resolved issues listed for this release, as well as all resolved issues from the previous releases listed
below.

All Resolved Issues

This release

R18-3 HF3.2 and below

R18-2 HF3 and below

R18-1 HF3.2 and below

Upgrading Tufin Orchestration Suite


You can upgrade to Tufin Orchestration Suite (TOS) R19-1 from R18-1, R18-2 or R18-3. To upgrade from earlier versions than shown above, first
upgrade to TOS R18-1, R18-2 or R18-3 and then upgrade to TOS R19-1. Make sure to read the additional notes in the Release Notes for each ver-
sion upgrade.
Upgrading to Tufin Orchestration Suite R18-1 and above requires TufinOS 2.14 or above, RHEL 6, or CentOS 6.
Click here to view the Tufin Orchestration Suite build number history.
The complete Tufin Orchestration Suite documentation can be found in the Tufin Knowledge Center.

Upgrading TufinOS
l Installing TOS for the first time on a server running a clean install of TufinOS 2.15 or above, requires TOS R18-1 or above.
l Upgrading or installing on a server after you have upgraded the server to TufinOS 2.15 or above, requires one of the following TOS ver-
sions:
l TOS R17-3 GA or above
l TOS R17-2 HF2.2 or above
l TOS R17-1 HF4.1 or above
l TOS R16-4 HF5.1 or above
l If you are running TOS R16-3 or below you must first upgrade TOS to the desired version using the latest hotfix available, and then upgrade
TufinOS.

Additional stuff you need to know


l Customers who have customized solutions developed by Tufin Professional Services should upgrade the Tufin PS Support package before
upgrading to R19-1. If you have already upgraded to R19-1, you should upgrade the Tufin PS scripts package right away:
1. Download the latest Professional Services Setup file (setup_tufin_ps_scripts-[Link] or above) from the Tufin Portal.
2. Install the package on your Tufin Orchestration Suite server:
sh setup_tufin_ps_scripts-[Link] -w

l Upgrade behavior for existing zones named "Unassociated Networks"


The predefined Unassociated Networks zone will be added to the Zone Manager during upgrade. If you are upgrading from a system that
already contains a zone with the name “Unassociated Networks”, the existing zones are renamed, as follows:
l The existing zones named “Unassociated Networks” will be renamed copy_of_Unassociated Networks, copy(2)_of_Unas-
sociated Networks, and so on.
l For each domain in multidomain/MSSP mode, any existing zone that is named “Unassociated Networks” will also be renamed.
The existing USP matrices in each domain will change to reflect the renamed zones. They will include the name copy_of_Unassociated Net-
works (and not "Unassociated Networks").

4
When you import new matrices after an upgrade, the name of the zone is taken from the CSV without being renamed.
l If you are running a Distributed Deployment architecture, the upgrade will transfer the SSL certificate from the Distribution Server to the Cen-
tral Server. The installation script will prompt for the SecureTrack administrator account credentials, so have the credential information avail-
able prior to beginning the upgrade.
l If you use CA-signed SSL certificates, you must use the SSLCertificateChainFile directive rather than the SSLCACertificateFile dir-
ective. See TufinOS Prerequisites or Non-TufinOS Prerequisites in the Security Essentials section of the Knowledge Center.
l The final supported release of the Tufin Orchestration Suite for the Tufin T500, T1000, and T1000XL appliances will be TOS R19-2. Tufin
announced End of Sales for these appliances in December 2013. The successor appliances are the T510, T1100, and T1100XL.
l From R19-2 and above, Tufin will enforce maximum session duration settings for SecureTrack and SecureChange, including for the REST
APIs.
l Preserve your SSL certificate and configuration customizations during an upgrade to Tufin Orchestration Suite. See Customizing SSL or Vir-
tual Host Configuration for details. (for R17-3 HF3 and above)
l Prior to upgrading to R17-3 or above you must fill in the "Administrator DN" field (SecureTrack > Settings > Configuration > External
Authentication). After the upgrade has completed, the title of the field will be renamed to "LDAP Bind DN".
l If your TOS deployment uses a Distributed Architecture configuration, you may need to upgrade sTunnel. See sTunnel Patch Installation
Instructions in the Customer Portal for details.
l Policy Advisor reached its “end of life” (EOL). Use the expanded and enhanced capabilities provided by SecureChange Designer to plan and
provision changes to device policies.
l For Check Point R80.x devices, when you upgrade from R18-3 and below to R19-1 and above, a new revision is automatically retrieved.
After upgrading, Compare Revisions may show changes for all the existing network objects.
Before you upgrade, make sure you have a recent (from ≤ 3 months) Check Point Jumbo Hotfix version installed on your R80.x device. See
the relevant Check Point Support Center article for more information on how to verify which Jumbo Hotfix version is installed.

5
SecureTrack Release Notes
Resolved Issues in SecureTrack R19-1
SecureTrack version R19-1 HF3 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Device AUT-20820 For Palo Alto Panorama Next Generation firewall devices, implemented fix to avoid conflicts between old gen-
Monitoring eric NAT rules and new monitored NAT rules *on revision retrieval. (SR47919)

SecureTrack version R19-1 HF2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference ID Description


Cleanup AUT-20418 For devices with over 17000 attached objects, improved accuracy of cleanup calculations.
(SR43207)

Device Mon- AUT-11816 For Fortinet FortiGate version 6 devices both with and without associated
itoring VDOMs, resolved issue affecting revision parsing caused by a new internet ser-
vice in the version. (SR47568)
Device Monitoring AUT-18779 For Cisco FMC Firepower devices, resolved issue of SSH key settings mismatch for imported child
devices. (SR46426)
Device Monitoring AUT-18987 Improved revision retrieval for Cisco FMC version 6.2.3.x devices with large policy configurations (>
120 policies) caused by a Cisco restriction of 120 requests per minute for these devices. (SR47143)
Device Monitoring AUT-19017 For Cisco ASA devices, fixed revision retrieval issue for Cisco ASA devices with auto-enable con-
figured. (SR46560)
Device Monitoring AUT-19018 For Juniper MX devices, resolved issue affecting revision retrieval by improving the configuration
parsing on client devices. (SR43378)
Device Monitoring AUT-19125 For Azure devices, resolved revision retrieval to treat the internet object as the same regardless of
the letter case, for example "internet" and "INTERNET". (SR43547)
Device Monitoring AUT-19141 For Cisco IOS-XR devices, resolved issue where revisions failed to retrieve or display when the run-
ning configuration contained a "port-group" or "net-group" object. (SR46008)
Device Monitoring AUT-19241 Ability to add a Nexus switch that contains destination groups. (SR46572)
Device Monitoring AUT-19350 For Stonesoft SMC, resolved issue where elements that were in the device trash prevented
SecureTrack from retrieving policy revisions. (SR46724)
Device Monitoring AUT-19608 For Check Point devices, improved management of imported cluster firewalls when performing a
Commit in Designer. (SR47625)
Device Monitoring AUT-19745 For Cisco IOS-XR devices, improved revision retrieval after terminal length default was adjusted.
(SR46695)
Device Monitoring AUT-20128 For Fortinet FortiManager devices, improved revision retrieval when interface to zone mapping is
configured. (SR46564)
Device Monitoring AUT-20651 For Fortinet FortiManager devices, using the forward slash character "/" no longer causes a failure
to retrieve a revision. (SR47149)
Display AUT-19138 Improved page loading performance for many SecureTrack pages, including Interactive Map,
Dashboard, USP and Zones, even in systems with many devices and zones. (SR37423)
High Availability AUT-20845 MongoDB HA configuration no longer overridden after TOS upgrade. (SR36924)
LDAP AUT-20267 Altered memory allocation for the LDAP cache service, does not change after upgrade. (SR47625)
Licensing AUT-18225 For management domains without devices (including Palo Alto Panorama Device Groups, Fortinet
Fortimanager ADOMs, and Cisco FMC domains), improved the messaging to inform users to add
a licensed firewall to these management domains to continue receiving revisions for them.
(SR45361)
Licensing AUT-20070 Improved data retrieval in SecureTrack license page after adding SecureApp licenses. (SR47573)
Reports - Rule AUT-18782 For Cisco ASA firewall devices, resolved issue that caused the Rule and Object Usage report to fail
and Object Usage when object-group-search access-control optimization was enabled. (SR45983)
Reports - Rule AUT-19086 Resolved issue where the Rule and Object Usage report incorrectly identified a rules as having
and Object Usage changed, when the actual change occurred prior to the start date selected for the report.
(SR45141)
System AUT-19138 Improved page loading performance for many SecureTrack pages, including Interactive Map,
Dashboard, USP and Zones, even in systems with many devices and zones. (SR37423)
Topology AUT-18482 For Cisco Firepower Management Center devices resolved issue affecting dynamic topology and
revision retrieval related to commands run in the incorrect context. (SR45649)

6
Topology AUT-19605 Improved post-topology violation calculations, which now removes excluded devices from the Viola-
tions browser. (SR37423)
Zones AUT-19677 For Cisco Firepower Management Center devices, selecting "log" in the Logging option within
Designer creates a rule with the appropriate log. (SR47224)
Zones AUT-19686 Improved display of selected zones in zone hierarchy. (SR46972)

SecureTrack version R19-1 HF1.2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference Description


ID
High Avail- AUT- Resolved issue of missing Cluster HA failover timeout value leading to corrupted data in the HA
deployment. (SR A-13116)
ability 20032
High Avail- AUT- Resolved issue of Cluster HA timeout value not being updated to new value after TOS upgrade.
(SR A-13116)
ability 20028

SecureTrack version R19-1 HF1.1 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureTrack version R19-1 HF1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference Description


ID
Cleanup AUT-17540 Improved object calculation when adding new revisions which contain up to 25,000 attached objects.
(SR43207)
Distributed Archi- AUT- 18216 For Cisco router devices in a Distributed Server environment, connection analysis calculations oper-
tecture ate correctly.
Device Mon- AUT-17623 For Cisco 2801 IOS devices, improved revision retrieval due to a rectified device configuration issue.
itoring (SR46543)
Device Mon- AUT-17780 For Cisco routers, non-routed traffic is no longer being passed directly to the security step. (SR45954)
itoring
Device Mon- AUT- 17954 For Check Point devices, improved accuracy for inline layer link when comparing two revisions.
itoring (SR45648)
Device Mon- AUT-18009 For Cisco IOS-XR devices, improved support for revisions that includes IP addresses written in CIDR
itoring format. (SR46008)
Device Mon- AUT - For Forcepoint (Stonesoft) SMC devices, improved memory usage when parsing large XML tables
itoring 18088 during revision retrieval. (SR46354)
Device Mon- AUT - For Fortinet Fortimanager devices, improved performance and results filtering when retrieving mem-
itoring 18194 ber information for a device. (SR45875)
Device Mon- AUT - For Cisco FMC devices from version 6.3 and above, enabled text-only FQDN support for source and
itoring 18357 destination. This resolved the issue affecting retrieval of revisions that include FDQN objects in the rule
source or destination. (SR45736)
Device Mon- AUT - Improved performance of the SecureTrack Monitoring page. (SR44237)
itoring 18383
AUT -
18384
Display AUT-18628 For all the pages accessed via the Settings and Compare tabs, improved performance of the page dis-
play. (SR46080, SR44237)
High Availability AUT-18485 Improvement to the sync process by enabling a change owner command for each file within the dir-
ectory. This applies when performing the initial sync of directories for the standby server during HA
configuration/recovery(SR46382)
LDAP AUT-18649 For rules that include more than 3000 users, improved Last Hit calculation performance, as well as
new revision indexing and visibility in Policy Browser. (SR43258)
REST API AUT-17826 Improved performance for Policy Browser REST API calls. (SR45974)
REST API AUT-18669 Improved topology retrieval time by using a single API query to retrieve all communities for the latest
module version and the network object lists. (SR45425)
Risk AUT-17214 Improved accuracy in risk calculation, when running a calculation on a zone that contained an object
which no longer exists. (SR43995)
Ticketing AUT- 18467 For Forcepoint SMC devices, resolved issue related to parsing of ticket ID patterns which impacted
revision retrieval.(SR46354)
Topology AUT-18003 Improved Interactive Map topology output due to amended processing of the database locks on topo-

7
logy tables. (SR45875)
Topology AUT-18139 For Cisco IOS XR router devices, improved performance for revision retrieval as well as reducing time
to retrieve Dynamic Topology. (SR38085)
Topology AUT- 18144 For Cisco router devices, improved vrf parsing of replicated routes for Dynamic Topology path ana-
lysis. (SR44306)
Topology AUT- 18456 For Fortinet FortiManager devices, improved dynamic topology retrieval to include the secondary IP
address of the management interface. (SR46360)
Topology AUT-18653 Improved the efficiency of retrieving topology query results. (SR37423)
Topology AUT-18527 Enhanced security: In MSSP mode, only a Super Administrator /Multi-Domain Administrator user with
the relevant permissions can run all Topology REST APIs. (SR 47577, SR47834)

SecureTrack version R19-1 GA includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference Description


ID
Audit Trail AUT- For Check Point devices, improved audit trail recording for added and removed
12808 firewalls.
Automatic AUT- For Cisco ASA devices configured with Periodic Polling, resolved issue of
Policy Gen- 12780 delayed log retrieval caused by prolonged APG calculations. (SR42247)
erator (Web
Interface)
Device Mon- AUT- For Check Point R77 devices, resolved issue affecting revision retrieval that
itoring 15523 occurred when a unit separator character was included in a rule comment and cus-
tom encoding (not default UTF-8 encoding) was configured for SecureTrack.
(SR43751)
Device Mon- AUT- Improved capability to receive configuration revisions from Cisco Firepower.
itoring 16549 (SR44108)
Distributed AUT- For CheckPoint devices during collection server (CS) migration, optimized the
Architecture 13404 device version query and improved the migration process. (SR42597)
REST API AUT- For the REST API Unified Security Policy - Exceptions, resolved issue affect-
14092 ing the use of pre-defined service names in the GET and POST requests.
(SR43624)
Rule and AUT- For Cisco router devices, increased the count range for features based on rule_
Object Usage 15145 usage hit counters (for example: Last_Hit column in Policy Browser and "Rule &
Object Usage" Report). (SR44307)

Rule and AUT- For Palo Alto devices, resolved issue of syslog message processors sim-
Object Usage 15263 ultaneously inserting rule usage data into a table. (SR44309)

Known Issues in SecureTrack R19-1


SecureTrack version R19-1 has these known issues:
Interactive sessions in multiple tabs of the same browser, the Back button in the web browser, and Internet Explorer prior to version 11 are not sup-
ported.

Category Reference Description


ID
Upgrade AUT-9624 For Check Point R80 devices, when you upgrade from R18-3 and below to R19-1 and above, a new revi-
sion is automatically retrieved. After upgrading, Compare Revisions may show changes for all the existing
network objects

8
Cleanups AUT-15662 For Check Point R80 CMA devices, a miscalculation in the revision resulted in an increase in the number of
unattached network objects. The miscalculation also affects the Unattached Network Objects report: The
report includes network objects that are actually attached and referenced by rules. (SR43486)

Known Issues from Previous Releases


SecureTrack version R19-1 has the following known issues and limitations from previous releases.

Platform Support
1. SecureTrack SNMP MIB does not support HP OpenView.
2. Red Hat Enterprise Linux versions 3 and 4, and CentOS version 3 and 4 are not supported.
3. On Tufin appliances, make sure you have a supported TufinOS version installed. You can download the latest TufinOS version from the
Tufin User and Partner Center.
4. When disk usage exceeds 90%, log collection for rule and object usage is stopped. When disk usage exceeds 95%, all SecureTrack pro-
cesses are stopped. To resolve this problem, perform database maintenance.

Installation and Upgrade


Reference Description
ID
Upgrading SecureTrack may require installing additional packages.
After upgrading, it may take several minutes for SecureTrack to reconnect to Check Point man-
agement servers.
If the username "securechange" has been manually configured in SecureTrack, upgrade will fail.
This username should not be used in SecureTrack.
5688 Manual changes to Apache’s configuration file (/etc/httpd/conf/[Link]) are over-
written when upgrading from a previous SecureTrack version. The original file is saved to a backup
file: /etc/httpd/conf/[Link]
9769 For instructions about how to upgrade TOS High Availability servers, see the upgrade instructions
in the Knowledge Center. Do not upgrade TOS on a High Availability server that is active. If you
do, the upgrade fails and corrupts the TOS configuration.
11246 If you use SecureChange, after you upgrade to this version you must go in SecureChange to Set-
tings > SecureTrack and click Save to refresh the communication between SecureChange and
SecureTrack.
11427 To upgrade a High Availability deployment, contact Tufin Support for assistance.
11890 For parent devices of virtual systems, when you upgrade to this release from R12-2 or below you
may retrieve a new revision for the device. You can disregard any differences reported between
this revision and the previous one.
The unused objects cleanup is disabled by default. When you enable it in Settings > Configuration
> Cleanup, you must also select the time period (days, weeks or months) of the usage data.
Objects that have no hits during the usage period are listed as unused.

Make sure that the cleanup settings in Settings > Administration > Maintenance are set for a
longer period than the usage period for the cleanup.

The cleanup is shown in the Dashboard only if the amount of time configured for the usage period
has passed since the upgrade to R13-4 or higher.

The cleanup is shown only if there are hits for every day in the usage period, meaning that the
device will show no results if there was a connectivity problem that resulted in at least one day

9
without getting traffic logs.

The cleanup does not include:


l Traffic hits from the current day because the results are calculated nightly
l Rules that were changed during the period and the objects that are used in the rules
l Rules without logs
l IPv6 objects in devices other than Juniper NSM
l Predefined, implicit and NAT objects or objects of parent devices

AUT-6390 From R18-2, revisions for FortiManager ADOMs record the ADOM version: Thus, after upgrading
from 18-1 (and below) to 18-2 (and above), a new revision is added to each ADOM (even if no
policy change occurred on the ADOM). When comparing the existing revision and the new revi-
sion, it appears as if an ADOM version has been added.
AUT- When upgrading from R18-2 RC1/RC2 to R18-2 GA and above, some saved reports may not
10280 open.

Accountability
1. For Juniper accountability, if changes are made from the NSM, the Administrator and GUI Client are not correctly displayed. This is due to
limitation in Juniper's NSM.
2. For Fortinet accountability, if changes are made from FortiManager, the Administrator and GUI Client are not correctly displayed. This is
due to limitation in FortiManager.
3. For Juniper accountability, if logs are received from the NSM, accountability information and usage analysis for Virtual Systems will not be
supported.
4. For Cisco accountability, hostname and IP address may not always be available. Administrator name is available.
5. For Cisco or Juniper policies, changing the device's logging ID (Cisco), hostname (Netscreen), or log-prefix (JunOS) requires an automatic
revision to take effect. Policy changes made until that revision will not have accountability.
6. Cisco System Contexts in virtual context devices are not supported for accountability. Only automatic revisions are received, according to
automatic revision polling frequency (in the Timing tab).
7. Cisco routers and switches send change logs only when exiting the configuration terminal, not immediately after making the changes. If an
automatic revision occurs before exiting the configuration terminal, the change is recorded without accountability.

Automatic Policy Generator (CLI)


This section relates to the APG CLI tool. For the APG web interface tool, see below.

Reference Description
ID
5764 If APG crashes with an Out of memory error, run it again with output format: XML or TXT, or use
the APG web interface tool. The TXT output is of similar look-and-feel to the HTML.
5789 When single IP addresses are consolidated into networks, APG may propose redundant
addresses in rules. In Check Point policies the install action will state that these addresses are
shadowed.
6278 The APG may abort when trying to generate a policy for a log file larger than about 1GB.
9592 When you run 'st_apg_collect' on a Check Point CLM with a specific rule_uid, if you see the error
"Note: Rule UID <uid> was not found in the management server's current rulebase", you can
safely ignore the error.

Automatic Policy Generator (Web Interface)


This section relates to the APG web interface tool. For the APG CLI tool, see above.

Reference Description
ID

10
6278 Log files larger than about 1GB cannot be uploaded to the APG.
7724 APG supports only TCP, UDP and ICMP protocols.
7480 When creating a new job, very large policies (thousands of rules) are not displayed for rule selec-
tion.
7881 APG jobs need to run for at least 1 hour in order to have results. If you stop the job before an hour
has passed, there will be no results, even if there is a Results link.
8091 If a Check Point rule is changed while an APG log collection job is running, the results will not be
optimal, as traffic hits for the changed objects are not collected for same period as the whole rule.
8091 If a Check Point policy is saved as a new policy while APG collects logs for a rule in the original
policy, the APG continues to collect the logs for the original rule. Installing the new policy can
cause APG to stop collecting logs.
8297 Uploading to APG a file in invalid format produces a message that does not identify the invalid
lines. Please contact Tufin support to identify the problematic lines.
8435 In rare cases, when you have many results in APG, if you expand nodes then you cannot see the
rest of the results. Close the expanded results to see the rest of the results.
9529 Use only alphanumeric characters for APG job names. Other characters are not supported.
9537 When there are many results in APG, not all of the sub-rules are displayed. To see all of the rules
and sub-rules in an exported file, click Save rule set> Replacement rules for export.
13653 If you save a new APG task for a device that is monitored by a Remote Collector and the Remote
Collector is unreachable over the network, the process gets stuck and the task is not saved.
14263 In Settings > Monitoring the name of the SecureTrack server that is monitoring each device is
shown. If you change the name of the SecureTrack server in Settings > System and you see in
Settings > Monitoring that the server name is not changed, you must run this command to set the
server name from the command-line:

#psql securetarck -U<username> -c "update st_servers set display_


name='<Server_Name>'"
14387 When you export a large topology map to PDF, you cannot open the file with Adobe Acrobat
Reader but other PDF viewers can open the file.

Backup and Restore


Reference Description
ID
5001 When using an NFS server, root access is required to the NFS server. On the NFS server side, it is
possible to allow real root access from a list of machines by using a dedicated option ("root-
t=access list" on Solaris share_nfs).
9769 For instructions about how to upgrade TOS High Availability servers, see the upgrade instructions
in the Knowledge Center. Do not upgrade TOS on a High Availability server that is active. If you
do, the upgrade fails and corrupts the TOS configuration.

Best Practices
Reference Description
ID

11
In general, Best Practices may be affected by issues listed under Policy Analysis.
For Check Point policies, Best Practices does not take User Authentication and VPN settings into
account.
For Juniper and Fortinet policies, Best Practices ignores the VPN settings column.
1652 Check Point Provider-1 global services appear as duplicated services on the CMA’s policy.
9232 When you have multiple objects with the same definition (port / ip), the duplicate objects test in the
Best Practices report shows all possible pairs instead of showing the duplicate objects in the same
line.
10522 If anti-spoofing is disabled for virtual interfaces on VSX clusters, the anti-spoofing check sends an
alerts even though virtual interfaces inherit the anti-spoofing settings.

Change Management
Reference Description
ID
Comments added to JunOS policies (using annotate) do not appear under device configuration,
and changes to them do not trigger new revisions.
JunOS deactivated objects are treated as deleted.
For Cisco ASA version 9.3 or higher devices, SecureTrack does not retrieve revisions if the "for-
ward-reference" option is enabled.
AWS support does not include Amazon’s recently added regions, such as Seoul.

Workaround: override com\amazonaws\regions\[Link] coming in the aws-java-sdk-core jar,


and specify path to it, using -[Link] =<path to cus-
tom file>
3654 For some Fortinet firewalls that have the system console output set to: More, some revisions fail
to be retrieved.
4111 If RIP is configured for a Cisco interface (for example, by using the rip receive version command),
then upon upgrading SecureTrack from a version earlier than 4.5 HF2, a new revision is generated
listing the interface as a new object, even though the interface existed beforehand.
7213 Generating a revision of a large Cisco router configuration (tens of thousands rules) consumes a
lot of memory. When there are several such devices it can cause the server to fail due to memory
outage.
7792 Security rules configured in Panorama for specific virtual systems of specific target devices are
considered by SecureTrack to be relevant to all virtual systems with the specified name on all
devices, not just the specified ones.
8060 An object defined in Panorama and then defined in the device with the same object name causes
policy retrieval to fail.
8735 VPN icon is missing in Compare > View Policy of Check Point policies.
9118 Time objects in Check Point global policies are shown as regular objects in Compare > View
Policy.
9248 In Compare > View Policy, tooltips for group objects do not show the IP addresses and ports for
group members. Click on the group to see this information.

12
9254 If you set rule scheduling on a rule in a Palo Alto policy, SecureTrack records it in its database but
does not display it in the policy. The rule scheduling is taken into account for the Expired Rules
report.
9425 Section titles in Fortinet policies do not display the number of rules in the section.
9854 For Check Point, changes to user IDs and passwords are not included in reporting.
9928 For a large policy, the required memory can exceed 4 GB. To increase the memory used for pro-
cessing a policy, contact Tufin Support.
10763 In Compare, if you do not see the number of retrieved revisions next to each device, click Com-
pare to refresh the page.
10785 When you make a change on a Cisco cluster, username listed for the configuration of the sec-
ondary device is "failover".
11579 For Cisco routers, the "established" option in rules that use TCP is not shown in Compare and it is
not used in policy calculations.
12645 For zone-based Cisco firewalls, when you change the zone assignment of an interface, the
change is shown correctly in Compare but is not shown correctly in the comparison report.
17695 SSL ports that are shown in McAfee devices as SSL_<port> are instead shown in SecureTrack as
TCP_<port>.
23924 If there a problem with the connection between SecureChange and SecureTrack during the pro-
visioning of changes, the new revision is not associated with the ticket.
29739 For Check Point devices, the VPN column is empty for rules with "VPN Match Condition".
30316 Amazon AWS throttles API calls and returns an error when it hits the limit, which is managed by
Amazon. Tufin uses the exponential back-off strategy suggested by Amazon to mitigate this lim-
itation. If you experience delays in Amazon AWS connections, contact aws-support-
pmo@[Link] to increase the limits for your account.
31157 For Check Point devices, a rule with the CDATA tag in the rule comment is only shown in Com-
pare when you compare the revision to another revision.
32234 For devices that allow rules with multiple zones, when you change the zones in a rule the com-
parison shown in Compare is not accurate.
207549 For F5 devices, iApps with pools that are not configured in the same route domain are not shown
in the revision.
211590 After you upgrade a Check Point device to R80 support, a new revision is shown marked with
changes to legacy users, but there are no changes to the users. You can safely ignore this revi-
sion.
213094 When SecureTrack parses a revision, the [Link] file can show an error without an indic-
ation of which revision the error happened on.

Compliance Policies
Reference Description
ID
In general, Compliance Policies may be affected by any of the issues listed under Policy Ana-
lysis.

13
Dashboard
Reference Description
ID
9635 When you add a CLM to SecureTrack, if you run the 'st stat' command and the result for the CLM
is "unknown" license, you can safely ignore this message.
10683 If you import a Check Point gateway with an OS Monitoring license and then reconfigure the gate-
way as a cluster, the new cluster does not have the OS Monitoring license.
10712 If a device license expires, the license is still shown in the Dashboard device tree as active.
10723 If you make a change in your network that effects the topology map, the risk charts are recal-
culated at the scheduled time for Topology synchronization (Settings > Administration > Main-
tenance), or when you synchronize the topology map manually (Network > Topology > Sync).
10805 If you have more than 900 devices, we recommend that you use Firefox.
10810 At resolution 1280x800, the column headings of the Change table in the Dashboard are not prop-
erly aligned.
10845 If you select a domain or vendor group from the device tree, the Risks of devices by severity chart
does not show any data.
11204 For a device that is the parent of other devices (such as virtual contexts and virtual systems), when
you click on the parent device in the Groups device tree you see the Dashboard information for the
device itself and not its children. To see the Dashboard information for the children, click on the
parent device in the Vendors device tree.
11389 You can ignore cleanup instances of shadowing that result from a rule that uses a role access
object in the Source of a rule.

For Check Point policies, when a role access object is used in the source of a rule, the Cleanup
engine considers this as an "Any" value and may determine that the rule shadows another similar
rule.
14279 After you enable or disable risks in Settings > Configuration > Risk, the risk score in the Dash-
board may take some time to update. The risk browser shows the correct score.

Database
Reference Description
ID
The database storage area should not be changed from the default location (/var/lib/p-
gsql/data). If necessary, this path can be pointed to another location with a symbolic link.
If the database package was installed manually rather than as part of the Linux installation, it must
be started before installing the SecureTrack package. To start the database, use either service
rhdb start or service postgresql start , depending on the database type.

Distributed Architecture
Reference Description
ID
Migration from multiple standalone servers to a distributed deployment is not currently supported.
You must migrate before you upgrade. For assistance, contact Tufin Support.
5566 If the clock on a distributed component (Distribution server or Remote Collector) is not syn-

14
chronized with the Central server, revisions from the distributed component are saved with wrong
date and time.
6023 To uninstall TOS from a remote collector or distribution server, you must first uninstall the DA con-
figuration and then run tss uninstall. If the remote collector or distribution server is not con-
nected to the Central server, you can force the uninstall with the command: tss uninstall -
-force
21524 You must install the TOP plugin on the target server before you migrate a TOP device.

Firewall OS Monitoring
Reference Description
ID
2097 The speeds of sub-interfaces and VLAN interfaces are mistakenly reported as 10Mb.
4376 When configuring ignored routes which already appear in the device's previous revisions, a new
revision will arrive in which these routes will appear to have been deleted.

External Authentication
Reference Description
ID
3623 External users email addresses remain in SecureTrack after being deleted in Active Directory.
5170 Defining a local user with the same username as an external user should be avoided. If there is
external user or administrator with a username that is the same as a local user defined in ST, the
external user / admin should login using the domain (in format: username@[Link]).

Licensing
Reference Description
ID
5716 When an Evaluation license expires, the license status of each device is changed only when
SecureTrack tries to fetch a new revision. If the license status is not changed, click Recalculate
in the Licenses page.
5842 In Legacy licenses (not Simplified licenses issued from February 2011), after adding, deleting,
enabling, or disabling a device, license statuses of some devices may not be updated in the
Licenses page (Configure > Administration > Licenses) and Status page (Configure > Admin-
istration > Status). To update the status, click Recalculate in the Licenses page.
7465 In the Licenses page, a green connection status icon appears for Check Point clusters, despite the
fact that connection status for clusters is meaningless. The icon is correctly not displayed in the
Compare and Status pages.
7505 Attaching a license to a device that should affect the license status of another device (for
example: attaching a license to a parent device of virtual devices) does not immediately cause the
updated status to be displayed. To see the updated status, click Recalculate .
9373 When you use Internet Explorer 7, if you go to Settings > Administration > Licenses, you can-
not go to another page until the device list finishes loading.
9635 When you add a CLM to SecureTrack, if you run the 'st stat' command and the result for the CLM
is "unknown" license, you can safely ignore this message.

15
Monitoring and Device Configuration
Reference Description
ID
Cisco zone-based policy firewalls are supported for change management when its policy-map uses
these class-maps:
l ‘match-all’ and ‘match-any’ with only one ACL, or with match-protocol
l ‘match-all’ with one ACL and one match protocol line, or with one ACL and nested class-map of type ‘match-
any’ with many match-protocol lines
l ‘match-any’ with many match-protocol

Changing SecureTrack’s OPSEC object name in a Check Point management server will cause
SecureTrack to lose its connection with that management server. You must redefine the man-
agement server in SecureTrack.
4025 To monitor Check Point management servers of version R70 (MDSs, CMAs, Security Man-
agement servers, Log servers, and CLMs), you must install the Check Point R70 LEA hotfix to
ensure connectivity with SecureTrack.
6070 If MDS monitoring is configured and an incorrect username and password, no revisions are
retrieved for the MDS but there is no indication of the problem.
7149 Trying to cancel the upload of an offline configuration has no effect.
8066 In Check Point R75, the management server's DN is not displayed in Smart Dashboard or in Pro-
vider-1 MDG. Because of this, when adding a standby management server as described in, the
only way to get the DN is from Check Point's [Link] tool.
8318 If a Fortinet cluster is configured in SecureTrack by its virtual IP, SecureTrack fails to connect after
failover. An ssh host key mismatch error message is sent. It is preferable for each cluster member
to be monitored independently. If the cluster must be monitored via virtual IP, please contact
Tufin support.
8279 To monitor a Check Point UTM cluster, do not use the virtual IP. Add the primary management
server using its own IP address. To add the secondary UTM,
8685 When SecureTrack monitors both primary/active and secondary/passive devices that are in a
JunOS or Fortinet cluster and both devices are configured with same logging identification,
accountability and usage data are collected for only one of devices and not necessarily always the
same device.

For Cisco clusters, this affects accountability.


9347 It takes some time to delete a device that has many revisions. Until the device is deleted, you can-
not add or delete users.
9453 If a non-Check Point device contains virtual systems the policy on the root device is not monitored
by SecureTrack.
10018 For NSM policies shown in View Policy, the rule numbers are not the same as the rule numbers in
the NSM Central Manager.
10434 When you change a device monitored by NSM from the device's user interface, SecureTrack
retrieves a revision in which the <devdirtybit> field changes from true to false.
10478 When SecureTrack retrieves a policy from NSM for an NSM offline device, only revisions received

16
after the first revision include zone or interface information.
10966 If you change the credentials of a device from Settings > Monitoring > Device Groups, the cre-
dentials on the device are changed immediately, but the credentials in the device configuration in
SecureTrack are updated with the new credentials when SecureTrack tries to connect to the
device to retrieve a revision. The status of the device in the Settings > Monitoring > Status and
in all device trees is incorrect until the new credentials are updated in the device configuration.
11013 SecureTrack does not prevent you from saving two queries with the default query name, New Ana-
lysis Query. Make sure you give each query a unique name.
11509 The duplicate service cleanup does not compare:
l Palo Alto - source port and timeout
l Juniper Netscreen - service timeout
l Check Point - protocol type

11819 When you add a Fortigate device with multiple interfaces, if you select "Collect dynamic topology
information", the secondary IP addresses are not shown in the devices topology.
15511 When you configure an Advanced Change report for a FortiManager device, the report runs on the
policies installed on each of the child devices. You cannot select a specific policy to run the report
on.
15455 SecureTrack polls all CSM, NSM and FortiManager devices added to SecureTrack in this version
once per hour.
15475 For Fortigate, if you make a change to an interface of a vdom that is managed by a physical
FortiManager or Fortigate device, you do not receive a new revision with the change to the inter-
face.
18754, In Cisco ASA devices, :
18843, l Interface names with more than 4 words are not supported
18856, l If you change a name object it may be shown as removed and inserted
19575 l When you upgrade to this version rules with time range configuration are shown as modified
l View Policy and Compare display the rule numbers as they appear in the CLI and not in ADSM

19589 In Compare, Juniper NSM devices do not show the interfaces for virtual routers that it monitors.
24100 For Juniper SSG devices managed by NSM, interfaces using SSG default zones do not show the
associated zone in the revision. For Juniper SSG devices managed by NSM, zones using SSG
default virtual-routers do not show the associated virtual-routers in the revision.
24836 For F5 devices, virtual servers must be configured with UDP, TCP, SCTP or Any Protocols. Vir-
tual servers configured with other protocols are not shown in Compare or Policy Analysis.
25094 For Fortigate 5.x devices that are managed by FortiManager 5.x, if there is only the 'root' vdom
then only the textual configuration (running config) is shown in Compare.
25147 To get a revision from a PANOS device that is managed by Panorama, you must first sync the
device.
25272 For VMware NSX, no new revision is retrieved when you delete a datacenter object.
AUT-3879 Cisco devices have a text string limit of 64 characters for object names. If you use a blank space
within an object name, quotation marks (“) are required at the beginning and end of the object
name. These quotation marks are included in the 64 character limit. (SR36940)

17
AUT-8969 For Cisco devices, monitored firewall interface names cannot include the “<” and “>” characters.
This limitation is enforced by Tufin Orchestration Suite to implement Tufin security policies.
(SR39728)
AUT-18154 For Fortinet FortiManager version 6.0.2 devices using ADOMs version 6.0, the Destination field in Compare Revisions
is not populated as it is currently unable to extract the internet service destination within a rule.

Multi-Domain
Issue Description
ID
9392 A non-admin User with permissions for "Any" device cannot view the Topology tab.
10809 If you login as a super-admin and change the context to a domain, you cannot access Settings > Con-
figuration > Risk.
11660 When you migrate some of the child devices to domain A and then migrate the parent device with all
of its children to domain B, the previously migrated devices will also be migrated to domain B.

Notifications
Reference ID Description
5410 SecureTrack heartbeat by SNMP does not work. SecureTrack does not send its status traps.

Object Lookup
Reference Description
ID
13500 When an Object Lookup search shows more than 100 instances, you can click on the arrows to
show another page of instances but the text incorrectly says that the first 100 instances are shown.

PCI-DSS Compliance
Reference Description
ID
28903 For Amazon AWS, when you set a PCI exception on a rule then the exception is removed when
the rule changes.

Policy Analysis and Business Ownership


Reference Description
ID
In general, Business Ownership reports may be affected by any of the Policy Analysis issues
below.
For Check Point policies, Policy Analysis User Authentication causes shadowing to be ignored.
Policy Analysis ignores Check Point global X11 settings.
For Juniper, Fortinet, and Check Point policies, VPN settings cause shadowing to be ignored.
Policy Analysis supports only destination port. For example, a rule with: Any Any Any (src=25) is
considered as: Any Any Any .
Match patterns for 'other' service objects in Check Point policies are not supported. SecureTrack
ignores these for Policy Analysis.
For non-Check Point policies that include Global rules, Policy Analysis shows the global rules for
each interface/zone. The shadowing information for these rules is correct only for the specific zone

18
in which it is displayed and not globally.
By design, Policy Analysis Results no longer appears in the Maintenance page. This is
because SecureTrack does not need to cache Policy Analysis data.
6460 In Cisco policies, implicit rules between interfaces with different security levels are ignored for
Policy Analysis.
7157 Section titles of Fortinet policies do not appear in Policy Analysis results.
8415 In Policy Analysis results, tool-tips for network objects only show the object's management IP
address.
10369 When you select a device or policy for a query, you cannot select a device group or a vendor group,
and you cannot multi-select targets.
10428 Policy Analysis ignores these rules in its calculations: rules with actions other than Accept, Deny or
Reject; rules with non-Any VPN community

Policy View
Reference Description
ID
3983 When a policy contains thousands of rules, some policy views, except View Policy, cannot be dis-
played (an informative message is displayed instead). For comparison of large policies, it is recom-
mended to use Generate Report rather than Compare . You can also set the maximum number
of rules that SecureTrack can display. To do this, contact Tufin Support.
4958 In the services list of a Cisco router’s policy, some TCP services are shown also as UDP, and vice
versa. This is because they are preconfigured this way by Cisco.
5010 ACL numbers for Cisco routers may not match the routers' numbers.
5669 Since support for Fortinet 4.0 has been added, all Fortinet policies are displayed with rule
sequence numbers, which are meaningless for Fortinet 3.x. These numbers in Fortinet 3.x policies
should be ignored.

Reports (General)
Reference Description
ID
6361 For reports and query configuration, only one Check Point policy per installation target is available:
the last policy that was modified, installed, or created on the management server.
6512 When you change the logo, on-demand reports and queries executed soon afterwards sometimes
continue to display the old logo. In this case, refresh the browser.
9647 The SecureTrack server cannot be used as the destination server for Export reports using SCP, in
Settings > Configuration > Reports.
9221 When a device has multiple policy packages and over 1000 NAT rules, reports may fail due to
memory consumption.
10520 When you export reports using user-defined scripts, SecureTrack parameters in the script cannot
include spaces.
10522 For Best Practices, if anti-spoofing is disabled for virtual interfaces on VSX clusters, the Best
Practices anti-spoofing check alerts you even though the virtual interfaces inherit the anti-spoofing

19
settings.

Advanced Change Report


Reference ID Description
6983 When you rename an object or group, its link is not active in the Advanced Change report.

Baseline Settings Compliance Report


Reference Description
ID
The Baseline Settings Compliance report does not support SmartDefense profiles (R65 and
above).
1126 When configuring a Baseline Settings Compliance report, users should select management serv-
ers with compatible Check Point versions. If you select management servers from different ver-
sions, the report may contain redundant information.
1732 Excluding certain attributes may cause this report to fail with an error. If this happens, remove the
exclusion.

Business Ownership Report


Issue ID Description
9931 A changed object that is used in more than one policy is only highlighted in one of the policies.

Mailed Reports
Reference Description
ID
Large reports may fail to be sent by email. This may be caused by a mail server limitation or to
SecureTrack limitations. To work around this issue, you can configure the report to be saved in the
Reports Repository and send a link to the report. Sending the report as PDF or MHT may help
overcome potential SecureTrack limitations.
Reports received in Lotus Notes may be improperly formatted. You can send the report in either
PDF or MHT attachment format, or save the report in the Reports Repository.
If SecureTrack is installed on a server with multiple IP addresses, email reports and notifications
may contain links to an incorrect IP address. To resolve this, you can define the server name
under Settings > Configuration > Notifications.
1491 Reports may lose formatting when forwarded. As a result, the report may be incorrectly displayed
in the forwarded message. You can send the report in either PDF or MHT attachment format, or
view the report in SecureTrack's web interface.
1748 Embedded links in MHT reports do not work properly.
1876 When accessing group members or a saved report through a link in a mail report, the user’s start
page may be displayed after login. The correct information will be displayed on the second
attempt.
8237 In mailed reports, Zone tooltips display the zone's internal ID instead of the zone name.

Rule Change Report


Reference Description

20
ID
6684 The second stage of the Rule Change report fails because policies with thousands of rules cannot
be displayed. To change the number of rules that can be displayed, contact Tufin Support.

PDF Reports
Reference Description
ID
The amount of time for generating PDF reports in SecureTrack depends on the processing load on
the SecureTrack machine.
7291 On rare occasions, reports that are saved in the repository will not open as a PDF because of the
memory limitations of the PDF engine. If this occurs, you can split the report into multiple smaller
reports (for example, per device or policy).

Security Risk Report


Reference Description
ID
7500 Changes in zones, risk report configuration, or compliance policy configurations, do not change
the old security score correctly. As a result, when a revision is retrieved after such a change, the
displayed score change may not be due to a real security change.

Software Version Compliance Report


Reference Description
ID
We recommends that you reconfigure Software Version Compliance reports that were configured
before version 5.0 to resolve the issue where sometimes the OS version was shown instead of the
firewall version.
Check Point hotfixes (HFA) have limited support because of version naming conventions.
Read-only users can receive Software Version Compliance reports for a Check Point gateway only
if they have permissions for the management servers that manage the gateway.

Tufin Device Audit Report


Issue Description
ID
9232 When you have multiple objects with the same definition (port / ip), the duplicate objects test in the
Best Practices report shows all possible pairs instead of showing the duplicate objects in the same line.

Rule and Object Usage


Reference Description
ID
Object Usage analysis requires a lot of free disk space. If disk space is limited, you can go to Set-
tings > Administration > Maintenance and configure SecureTrack to limit the number of days
that data is kept for. You can also change the Database update frequency to a larger value in
Settings > Configuration > Timing .
Object Usage hit count values may not add up to the rule total hit count value. This can happen
when the clean up schedule is different for object and rule usage data so that rule usage and
object usage are calculated over different time periods. For assistance, contact Tufin Support.

21
Rule Usage is not supported for Cisco PIX of versions lower than 6.3.
By design, no object usage is collected for rule fields (source/destination/service) with Any or Neg-
ate . If the rule field is changed during a usage report period, the number of object hits can be
lower than the total hits on the rule because some hits on the rule where on the previous rule con-
figuration for which object usage data was not collected.
For JunOS devices of version lower than 10.0, hits are not counted for rules with identical names
in different security policies. This may cause used rules to incorrectly appear as unused.
For JunOS policies, ICMP packets are not counted for object usage of rules that permit ICMP
traffic for more than one ICMP type. This may cause inconsistencies between rule usage and
object usage, and may cause used objects to incorrectly appear as unused.
For Fortinet Fortigate devices, FQDN objects are not included in rule and object usage statistics.
2380 In a Cisco usage report, disabled rules are not displayed under unused rules.
7940 Check Point usage collected before a first Install revision may be inaccurate.
9699 Rule Usage data is not collected for Juniper, Check Point or Fortinet devices that are monitored
with periodic polling.
9711 If you run the Rule Usage report on a policy with tens of thousands of rules, the report takes more
than a day to finish and may crash if more than one Rule Usage report is running.
210243 For Panorama devices, if an object is overridden the report may not accurately reflect the actual
number of hits.

Rule Documentation
Reference Description
ID
7333 If in SmartDashboard a Check Point policy is duplicated with Save As, and defined for a different
target installation group, SecureTrack Rule Documentation metadata is correctly carried over to
the new policy. If the Rule Documentation metadata for the new policy is subsequently edited, it
incorrectly changes for the original policy as well.
7465 In the Rule Documentation page, a green connection status icon appears for Check Point clusters,
despite the fact that connection status for clusters is meaningless. The icon is correctly not dis-
played in the Compare and Status pages.
7480 Very large policies fail to be displayed in the Rule Documentation page. To change the number of
rules that can be displayed, please contact support.
7535 Pasting with the mouse (right-click > Paste) into the Business Owner and Rule Comment fields of
the Rule Documentation Filter or Documentation Editor does not enable the Apply button.
Either paste with the keyboard, or subsequently add or delete a character to enable the button.
8087 Tooltips in the Rule Documentation page blink.
9630 When you apply a filter in the Rule Documentation page, the number shown for the number of res-
ults is not updated when there is a new revision. The filtered results show all relevant rules.
9805 When SecureTrack receives an error from a device that the policy is unreadable, the rule doc-
umentation details for the policy cannot be shown. For more information, contact Tufin Support.
10664 If you select a technical owner with a name that is more than 20 characters, you cannot filter rule

22
documentation for technical owner.
10863 If you filter rule documentation by a field and edit that field in a rule, the field is unselected in the
filter.
Rule Documentation only lists policy rules that match SecureChange access requests with the
"Accept" action.
If you change the name of an application in SecureApp that has rules associated with it in rule doc-
umentation, the name is not updated in rule documentation.
18108 When you change the comment in rule documentation for a rule that was added as an exception
to a PCI DSS profile, the rule is still in the list of exceptions even though it no longer violates that
PCI DSS test.
18343 If SecureTrack receives a new revision while rule documentation is open, you must refresh the
page to see the new data.

System Settings
Issue Description
ID
9511 When you change the hostname of the server with the hostname CLI command, make sure that the
/etc/hosts file is also updated.
22742 You can only turn off the browser autocomplete setting for these browser versions or lower: Mozilla
Firefox 29, Google Chrome 33, Microsoft Internet Explorer 10

TOP
Reference Description
ID
7007 Some TOP plugins available on the Tufin TOP plugin download page are based on RANCID.
These do not support passwords with special characters such as dollar sign ($). The plugins that
are prepackaged in SecureTrack are not affected by this issue.

Topology
Reference Description
ID
There may be problems with Topology for Nokia/Check Point IP appliance gateways. If this
occurs, please contact Tufin Support.
For Check Point devices, Topology is only supported for version NGX R60 or above.
6920 Manual topology changes to Check Point management servers are not reflected in SecureTrack
topology.
7427 When both a primary and secondary Check Point management server (SmartCenter or CMA) are
monitored, managed gateways appear twice in Topology. They appear once under each man-
agement server.
7670 SecureTrack does not correctly calculate topology for VSX advanced routing configuration.
Source addresses are ignored.
7808 Topology information is not collected for VSX gateways configured in bridged mode.
8606 Topology information is not shown for Check Point offline analysis. Check Point offline files do not

23
include topology data.
8741 When a device has a LAN interface and a WAN interface, if you add a route that its next hop is in
the WAN interface then you must manually set the network type for that network to External.
8830 After you click Synchronize to collect the latest topology data, the duration of the synchronization
process depends on the size of your deployment. When the synchronization process finishes, click
the Topology tab to refresh the topology map.
8991 Topology is disabled by default during the upgrade if you have more than 25 devices because it
requires more system resources than in 5.3.

You can enable topology for each device or contact Tufin Support to enable topology on many
devices from the CLI.
9085 If the default gateway for a NetScreen device is configured in the interface's configuration instead
of in the device's routing table, enable dynamic routing for the device to get the correct default
gateway.
9102 When you do synchronization for the topology map, any changes that you make before the syn-
chronization is finished are not saved.
9105 Topology does not use route precedence for topology calculations.
9755 Topology information is not gathered for Check Point clusters on non-ClusterXL appliances.
10855 After you delete an interface from a VSX cluster and click Synchronize in Topology, the interface
is shown in the topology map.
30381 Changes made to the Topology are shown in the interactive map only after you synchronize the
topology.

User Management
Reference Description
ID
623 Some special characters are not supported for user account details.
2005 When you give SecureTrack users (not Administrators) access to "Any" device, the user will not
have access to devices added later on. To work around this problem, once new devices have been
added, open the user's settings and select "Any" again.
29954 When a super admin views the list of users of a specific context, multi-domain users are not shown
in the list of users.

Web Interface
Reference Description
ID
If you add SecureTrack's certificate to the browser to prevent the non-signed certificate warning,
changing SecureTrack's IP address or hostname may cause the warning to begin appearing again.
In this case, renew the certificate in SecureTrack and in Internet Explorer.
6316 When generating a SecureTrack diagnostic file (Settings > Administration > Diagnostics), the
download may take a long time (depending on the amount of data, sometimes more than an
hour).
7852 After logout or the browser session expires, if you use a direct URL or link to SecureTrack

24
([Link] instead of the login link, an error message is displayed. The message can be
safely ignored.
9770 The IP address of the SecureTrack server that is shown in Settings > Administration > Status
can be an IP address other than the primary IP address of the server.

Zones
Reference Description
ID
8069 If all zones are deleted while some subnets are selected, Delete selected subnets and Change
selected subnets are enabled, even though no change can be made.
8075 Editing a subnet may cause its location in the list to change, and as a result it may disappear from
the display. Scroll down and/or advance pages to find it.
8109 Trying to change the parent zone of multiple subnets, when one of the subnets already exists in
the target zone, results in a message that does not specify which subnet(s) are causing the prob-
lem.
8119 In the SecureTrack zones list located in various report and query configurations, the zones are not
listed alphabetically. You can still browse the list using the first letter of the zone name.
8123 Changing a zone in the Zone Hierarchy tab may cause its location in the list to change, and as a
result it may disappear from the display. Scroll down to find it.
8136 Zone management is supported for screen resolution 1280x1024 and above.
8190 In Network > Zones, if you change the size of the browser window you cannot use the zone list.
8199 If a zone in an imported CSV file does not contain subnets (only zones), subnets that already exist
in the zone in SecureTrack are not deleted.
8202 When selecting all zones and deleting them, All zones is selected and disabled. If the user
imports a CSV file at this stage, all the imported zones appear as selected but no subnet/zone is
displayed in the right pane. To resolve the problem, clear All zones and then select zones.
8283 Zones with no subnets are not exported.
18439 In Internet Explorer, you cannot import zones from a CSV file.
32124 When you enter 0::0/0 or [Link]/24 for the source or destination of an access request, the Secur-
ity Zones tool matches the entry to all IPv4 and IPv6 addresses.
AUT-3955 A rule with a host object configured with NAT is treated as a USP violation for host-to-host flows.

25
SecureChange Release Notes
Resolved Issues in SecureChange R19-1
SecureChange version R19-1 HF3 includes these resolved or updated issues, and all resolved or updated issues from earlier versions.

Category Reference ID Description


Access AUT-20742 Updated the workflow to include the User ID information for automatic steps. A fter an upgrade, resave the
Request workflow to make the User ID field available in automatic steps. (SR47887)

SecureChange version R19-1 HF2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions.

Category Reference ID Description


Designer AUT-18783 For an Access Request ticket generated in SecureApp for a Forcepoint Stonesoft device, when the source or
destination is a mixed (IPv4 and IPv6) group and the target is an IPV4 or IPV6 policy, Designer uses existing
groups instead of creating a new group. (SR45742)
Designer AUT-18861 Improved Designer suggestions to better identify rules that are used by 2 or more connections in SecureApp:
Designer was incorrectly returning an error when removing a server from a rule that was only mapped to a
single connection. (SR44097)
General AUT-19073 For Juniper SRX devices, resolved issue of SecureChange overwriting the logging preferences on a rule due to
the configuration in st_conf (session-init or session-close). (SR46569)
Rest API AUT-20214 For Panorama devices, improved results with the GET key string. (SR47453)
Risk Ana- AUT-19404 Improved risk analysis calculations enabling improved collection of statistical data. (SR42368)
lysis
Workflow AUT-20564 Copying a Rule Decommission ticket that contains a text field in the first step, no longer fails. (SR47260)

SecureChange version R19-1 HF1.2 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureChange version R19-1 HF1.1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference ID Description


Security AUT-19309 Security fix. For more information, see here.(SR47296)

SecureChange version R19-1 HF1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference ID Description


Designer AUT-18681 If an object name contains unsupported special characters, Designer will create a new object
with the same name without the illegal character. For example, "obj!test" will convert to
"objtest". (SR46422)

SecureChange version R19-1 GA includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference Description


ID
LDAP - User AUT- Resolved issue of SC LDAP user not associated with "Any User" group as a res-
Management 15158 ult of changes to the user in the LDAP server. (SR43973)

Known Issues in SecureChange R19-1


SecureChange version R19-1 GA has these known issues:
Interactive sessions in multiple tabs of the same browser, the Back button in the web browser, and Internet Explorer prior to version 11 are not sup-
ported.

Category Reference Description


ID
Display AUT- For the relevant devices, negated objects on security rules are displayed as regular
15707 objects. All Risk, Designer, and Verifier calculations are performed correctly. The issue is
only cosmetic and does not impact the logic or data in the system.

Known Issues from Previous Releases


SecureChange version R19-1 contains these known issues from previous releases:

26
Platform Support
1. Red Hat Enterprise Linux versions 3 and 4, and CentOS version 3 and 4 are not supported.
2. On Tufin appliances, make sure you have a supported TufinOS version installed. You can download the latest TufinOS version from the
Tufin User and Partner Center.

Installation and Upgrade


Reference Description
ID
You must have an active and valid license before you upgrade.
If the username "securechange" has been manually configured in SecureTrack, upgrade will fail.
This username should not be used in SecureTrack.
8185 After upgrade and after database restore, SecureChange performance may be poor for a while
(about 20 minutes for each 5000 tickets on a server-grade appliance).
9769 For instructions about how to upgrade TOS High Availability servers, see the upgrade instructions
in the Knowledge Center. Do not upgrade TOS on a High Availability server that is active. If you
do, the upgrade fails and corrupts the TOS configuration.

Access Requests
Reference Description
ID
8200 Individual VSX cluster members (virtual routers or virtual FW) are available in the target browser,
even though you are not allowed to use individual members. Verification will fail.
10717 After a request is assigned, the requester cannot see the labels of the ticket in My Requests.
11240 If you name a device in the format of an IP address (x.x.x.x), you cannot use the format
device_name/object to enter an object in the source, destination or service fields of an
Access Request. To work around this, you can change the name of the device or use a different
format.
11241 If you have two devices with the same name, you cannot use the format device_name/ob-
ject to enter an object in the source, destination or service fields of an Access Request. To work
around this, you can change the name of the device or use a different format.
15131 If an access request with a Fortigate target uses the IP address of an object instead of the object
name, the advisor doesn't recognize that the IP address already exists in the device as an object.
16272 Netscreen domain objects are not shown in the list of objects.
16542 When there is no firewall between the requested source and the destination, no target can be sug-
gested.
16670 An object from a device with an IPV6 address is not referenced in SecureChange.
23447 Access Request will always run with "ANY" in the users field on next-generation firewalls.
30850 When you create two requests, submit save or submit one and save the second request, if you
leave the page of the second request without saving changes and then cancel the first request,
the name of the second request changes to the name of the first request.
30944 You cannot open the automation tool results that were calculated before upgrading to this
release.
215546 When you request more information, the settings for finding LDAP users apply to all

27
SecureChange users.

Dashboard and Reports


Reference Description
ID
8261 Drill-down from a Dashboard graph bar displays only the first 100 tickets.
8726 The users listed in the Task Load widget are selected when you add the widget to the Dashboard.
You can edit the widget to change the list of users. To see the current users with the highest ticket
load, add the widget to the dashboard again.
13126 After you add a widget to the Dashboard you cannot change its location in the Dashboard.

Designer
Reference Description
ID
When you update the policy of a Cisco device, the changes are saved to the running-config. If you
want to make the changes persistent, save the running-config to the startup-config.
When the device is connected to SecureTrack by SSH, it is not possible to perform Update
Designer commands.
It is not possible to do Update Device in step 1 of the ticket.
Designer does not suggest to replace a source, destination, or service from a rule.
15478 When you configure an access request with the Designer and Allow update only, the user can
incorrectly also edit the Designer suggestions.
15494 If the data in the Topology map is not up-to-date, you can get incorrect Designer suggestions. To
make sure you Topology data is up-to-date, click Synchronize in the Topology section of
SecureTrack.
15579 You cannot run Designer for an access request that contains a subnet with a non-continuous net-
mask.
16479 For Juniper Netscreen devices, the Designer may suggest to add a VIP or DIP object when the
access request includes the IP address of the object.
16512 The Designer indicator on the left side of each access request field shows the result for all access
requests in the ticket, instead of the result for each individual access request.
16800 The Designer can suggest changes to a policy that only has global rules, but it cannot implement
the changes.
17626 After you run and save Designer results, you cannot change the fields that specify the rule loc-
ation.
17972 When you have the Designer enabled for the first step in a workflow, after you run the Designer
you must save it as a draft before you submit the request in order to save the Designer results.
18539 When you have an access request that specifies traffic that matches an existing rule that has a
range object, the Designer suggests creating a new rule instead of editing the existing rule.
19494 If you add a Palo Alto device to SecureTrack without its Vsys, an exception occurs when you run
the designer on a topology that contains the Palo Alto device.
29425 A ticket opened in Designer for a connection that contains a group name that contains a space are

28
not implemented for Cisco ASA devices running version 8.3 or below. Support for spaces in a
name was added by Cisco in ASA 8.4.

Workaround : Use names that do not include a space if you are running Cisco ASA 8.3 or below.
Replace the space with an underscore or another supported non-blank character.
31279 When you create a new request and run Designer before you submit the request, the Designer res-
ults are deleted when you submit the request.
30846 You cannot search for tickets by an IPv6 address that contains a double-colon (::).
213023 For Cisco ASA 9 or higher, when you have a rule with an inline group containing IPv4 and IPv6
addresses in the source and destination and you create a matching access request with an addi-
tional IPv4 source and an additional IPv6 destination, Designer suggests to create a new rule
instead of editing the source and destination of the existing rule.
AUT- For Palo Alto Panorama NG devices in a server decommission task, when Designer suggests over-
13742 riding local network object properties from a local rule in the upper level of a hierarchy, the same
modifications are suggested as manual changes for objects in lower levels.

General
Reference Description
ID
8368 When the IP address or URL of SecureChange is changed, change the URL in email notifications
at Settings > Miscellaneous > Server DNS name .
15334 In Internet Explorer 9, if you open a hyperlink from a ticket, the window opens without a scrollbar
and maximize is disabled.
You can only select network objects of these types in SecureChange ticket fields: gateway_ckp,
host_ckp, connectra, interspect, gateway_cluster, cluster_member, sofaware_gateway,
sofaware_gateway_profile, vsx_box, vs_cluster_member, vs_cluster_netobj, vsx_cluster_mem-
ber, vsx_cluster_netobj, vs_netobj, mygw_EVR, vsx_netobj, embedded_device, host_plain, inter-
face, network, network_object_group, group_with_exception, gsn_handover_group, address_
range, multicast_address_range

You can see the type of a device in the “class_name” field of the REST APIs that return network
object details, for example: /network_object/search

Licensing
Reference Description
ID
9541 SecureChange shows the Not Licensed status when SecureChange cannot connect to the
SecureTrack server, even if SecureChange is licensed.

Modify Group
Reference Description
ID
AUT- Limitation: In the Modify Group workflow, Designer is unable to prevent the mutual inclusion of
11311 groups in the case of overridden or overriding groups.

AUT- Resolution: An error message is displayed stating that Designer failed to run and to which groups

29
13102 the mutual inclusion applies.
12939 If you configure a step with both Modify Group and dynamic assignment, the Modify Group field
does not show the group selected in a previous step.
13384 You cannot modify Check Point global objects.

Multi-Domain
Reference Description
ID
You cannot configure the logo and background for domains, and the Domain field is not shown in
the ticket details page.
13734 In Multi-Domain segregated mode, when you send an email to SecureChange in order to open a
ticket, the ticket is opened in the Default domain.
13837 When Multi-Domain mode is enabled, you cannot configure a dynamic assignment condition
based on a specific target. You can configure the condition based on the target containing or not
containing a target.

Policy Advisor
Reference Description
ID
4709 In some cases the Policy Advisor may suggest implementation that will fail verification in Check
Point SmartDashboard. This happens when the suggestion creates unnecessary shadowing in the
policy. This can be fixed by removing the redundant traffic.
9556 Policy Advisor suggests changes to the Global rules of the device. Warning: the changes will also
change other policies on the device.
15131 If an access request with a Fortigate target uses the IP address of an object instead of the object
name, the advisor doesn't recognize that the IP address already exists in the device as an object.

Rule Decommission Limitations


Reference Description
ID
AUT- For the Rule Decommission workflow, rule names that are part of a ticket should not be changed,
11364 as it may produce incorrect results in Designer.
214560 When the target device is deleted from SecureTrack during the auto step of rule decommission
provisioning, the Designer and the history correctly show that provisioning failed but the com-
mands listed in the history incorrectly show that the commands succeeded.

SecureChange API
Reference Description
ID
8752 Make sure you enter unique names for Scripts and Mailboxes. Entering unique names for Scripts
and Mailboxes is not enforced.
8766 When you run multiple SecureChange API tasks that are dependent and one of the tasks fails,
only one task shows that it is stopped. The other dependent tasks are stopped, but they are listed
in Tasks handler without a status.

30
9142 SecureChange only reads the first 4000 characters of emails sent to a SecureChange API mail-
box.
E-02342 The /devices/excluded REST API will not exclude child devices of a
management device (such as FortiManager from R16-2 above, or Pan-
orama from R16-3 and above) if multi-domain on SecureTrack is
enabled and the child device does not reside on the same domain as
the parent management device. You must explicitly exclude any child
devices that reside on a different MSSP domain.

System Settings
Issue Description
ID
9511 When you change the hostname of the server with the hostname CLI command, make sure that the
/etc/hosts file is also updated.
22742 You can only turn off the browser autocomplete setting for these browser versions or lower: Mozilla
Firefox 29, Google Chrome 33, Microsoft Internet Explorer 10

Target Suggestion
Reference Description
ID
7427 When monitoring both a primary and secondary Check Point management server (SmartCenter or
CMA), managed gateways appear twice in target suggestions.
7808 VSX gateways configured in bridged mode are not suggested as Access Request targets.

Tasks
Reference Description
ID
9301 When an administrator (admin1) completes a task, the ticket goes to another administrator
(admin2). If admin2 sends the ticket back to the previous task (Redo) then the ticket is assigned
back to admin1. When the redo is complete, the ticket is assigned according to the workflow con-
figuration, and is not automatically assigned back to admin2. This behavior is by design.
14175 If you search for the field value "in-to-out", the results also include the field value "out-to-in".
14766 If you open a link to an expired ticket, when you close the window the list of tasks does not show
the correct query.
16460 If you redo a task that was assigned by manual assignment, the task must be assigned again.
17010 When you save a search query that is not valid, an error message is shown when you change tabs.
17012 When you enter a multiple word search value, you must use quotations marks. Otherwise, each
word is processed as a search value.
18950 If you reopen a ticket that has a step that was redone, the Redo and Reopen banner is shown on
every step in the ticket.

User Management
Reference Description
ID

31
9477 When you delete a user, the user is still shown as a member of the groups. Logout and Login to
refresh the display.
13098 When you configure permissions for an LDAP group that has another LDAP group as a member,
the member group is not shown to inherit the permissions from the parent.
13306 If you configure an LDAP server as active and standby such that there are duplicate users in the
SecureChange database, attempting to login as a duplicate user causes an exception that pre-
vents any user from logging into SecureChange. Contact Tufin support for assistance.
16937 If you add or remove LDAP users during LDAP synchronization process, this causes an error.
19901 When a ticket is assigned to a group and the user that accepts the ticket is out of the office, the
out of the office banner is not shown.
212240 When you add an LDAP group or local group as subgroups to a local group, the members of the
subgroups are not shown in the list of users for step assignment and the members of the subgroup
are not included when the group is assigned to a step.
213037 The LDAP servers are shown in alphabetical order
and does not represent that order in which the servers
are checked for new SecureChange logins, which is
done in the order that the LDAP servers are added to
SecureChange.
215517 When you add LDAP groups to the source of an
access request from the Advanced Options menu and
apply the changes, the LDAP groups are not shown in
the access request after you submit the request.

Verification
Reference Description
ID
223488, There is a known issue in Internet Explorer 11, in which extremely large images (>4 MB) are not
223359 displayed properly. If you are running Verifier in Internet Explorer 11, extremely large topology
images for an Access Request may fail to display correctly.

Workaround : Use Firefox or Chrome, or use the REST API to retrieve the image URL reference.
223488, For performance reasons, Verifier does not automatically display large topology images (>400 KB)
223359 for an Access Request. Click the link provided in Verifier to display the image in a separate
browser window.
Cisco zone-based policy firewalls are supported for verification when its policy-map uses these
class-maps:
l ‘match-all’ and ‘match-any’ with only one ACL, or with match-protocol
l ‘match-all’ with one ACL and one match protocol line, or with one ACL and nested class-map of type ‘match-
any’ with many match-protocol lines
l ‘match-any’ with many match-protocol

11916 For large environments, the topology map that is shown for Verify may be blurry.

32
Workflows
Reference Description
ID
11576 For steps that are marked with a warning that the step requires configuration, after you configure
the step you must save the workflow in order to remove the warning mark.
12107 When you configure a dynamic assignment task, if you search for a user that does not exist, when
you close the Select User window then the task is not shown. If this happens, refresh the page to
see the complete task list.
16974 You cannot add a dropdown list or multiple selection field when two of the options in the field are
the same.
17005 You cannot delete an Approve/Reject field from a step when one of the options is selected.
32351 When you add a device to the list of excluded devices, tickets created from workflows that have
the device in the target field of an access request are invalid. To repair the workflow so that you
can open valid tickets from it, you must remove the excluded device from the target field of the
access request in the workflow.
AUT-1894 On occasion, a request based on a workflow using dynamic assignment in an auto step will get
stuck in the auto-step.

Workaround:

1. Reject the original ticket

2. Modify the workflow step to use an assignment mode that is not dynamic assignment

3. Create a new rule decommission request


212217 For Check Point devices, if you add the access request and modify group fields to the same step
and set it to auto-step, handlers cannot use the modify group field in the step.

33
SecureApp Release Notes
Resolved Issues in SecureApp R19-1
SecureApp version R19-1 HF2 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference ID Description


Connection Analysis AUT-19122 Resolved issue with degraded application responsiveness after view-
ing a large list of connected servers. (SR46722)
Connection Status AUT-19353 Improved performance on Distributed Servers by reducing CPU
impact on sTunnel. (SR37423)
User Management AUT-19280 Resolved issue where a new user added to an exsiting group inherits
the "can edit" and "can view" permissions for all users within the group.
(SR46978)

SecureApp version R19-1 HF1.2 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureApp version R19-1 HF1.1 includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.
SecureApp version R19-1 HF1 includes these resolved or updated issues, and all resolved or updated issues from earlier versions:

Category Reference ID Description


Distributed Architecture AUT-18216 For Cisco router devices in a Distributed Server environment, con-
nection analysis calculations operate correctly.

SecureApp version R19-1 GA includes no new resolved or updated issues, and all resolved or updated issues from earlier versions.

Known Issues in SecureApp R19-1


SecureApp version R19-1 HF1 has these known issues:
Interactive sessions in multiple tabs of the same browser, the Back button in the web browser, and Internet Explorer prior to version 11 are not sup-
ported.

Category Reference Description


ID
Distributed AUT- Issue resolved in R19-1 HF1

Architecture 18216 In very rare instances within a Distributed Server environment the connection analysis
calculations may not complete.

Resolution: Refresh the topology map. A refresh automatically takes place once a day
during the night. To refresh manually, in SecureTrack select Network > Interactive
Map and click the Synchronize button. When the Sync Topology Map screen
appears, select the Fast Topology Sync o ption and click the Sync button.

Known Issues from Previous Releases


SecureApp R19-1 has these known issues from previous releases:

Category Reference Description


ID
Applications AUT- To avoid the scenario of an application without an associated owner (for example, if
10329 the application owner was removed from the system, or lost the relevant permissions),
a user with invalid SecureApp permissions may be retained as the application owner.
The application remains active and can be viewed and edited by other users who have
the relevant permissions.
When a valid user attempts to change the application owner, they are notified that the
current owner is not valid.
Installation 13396 To avoid unnecessary load on SecureTrack, before you disable SecureChange (with
SecureApp) make sure you delete all application connections.

34
Connection McAfee device policies are not included in connection analysis calculations. If a
Analysis McAfee device is found to be in the path of a connection, connection analysis assumes
that the device policy accepts all traffic.
Connection 14674 You cannot view the connection analysis after a user starts SecureTrack topology syn-
Analysis chronization, until the synchronization is complete.
Connection 22424 SecureApp does not currently support application identities in connection definitions
Status and therefore the application field value is assumed to be "Any" for connection status
calculations.
Connection 208140 When you enable Multi-Domain segregated mode, connection status and analysis are
Status not accurate.
Display 12483 In Internet Explorer 8, the SecureApp user interface may respond slowly to your
actions.

Internet Explorer 9 or Firefox 12, 13, or 14 are preferred.

35
Patents and Trademarks
See [Link]/patents for patent details.
Trademarks
Tufin, SecureChange, SecureTrack, Automatic Policy Generator, and the Tufin logo are trademarks of Tufin Software Technologies Ltd. All other
product names mentioned herein are trademarks or registered trademarks of their respective owners.
Some TOP plugins include software developed by Terrapin Communications, Inc. and its contributors for RANCID.

Document Version Information


This document is relevant for all R19-1 releases up to HF2.
Published on Thursday, July 11, 2019 5:40 PM.

36

You might also like