Tufin SecureApp User's Guide R19-1
Tufin SecureApp User's Guide R19-1
Version R19-1
For additional technical information, please see our support website, at:
[Link]
Document Version Information
This document is relevant for all R19-1 releases up to HF2.
Contents
• Browser: Microsoft Internet Explorer 11; Mozilla Firefox 58, 59, 60; Google Chrome 67
SecureApp contains a number of views, accessed from the main tabs at the top of the
SecureTrack screen:
When you first login, you see the Home or Dashboard view. You can configure the initial view
and other personal preferences in Settings option.
2. Logout of SecureChange/SecureApp.
What can I do on this page? - Opens context-sensitive help from the Tufin
Knowledge Center ([Link] From the Knowledge
Center you can view and search additional TOS topics, including API documentation
and technical notes.
If you do not have an internet connection, the link opens context-sensitive help from
the local server. The local help files contain the same content as the User Guide.
Tufin Academy Online Training - Opens the Tufin Academy, where you can take
online courses based on your role and expertise.
At the bottom of SecureApp the status bar shows the license status:
Decommissioning Applications...................................................................................... 50
Check Point
Cisco
Juniper
Fortinet
Palo Alto
Networks
McAfee
F5 VMware NSX Amazon AWS Cisco ACI
Application Inventory
Application\Connection Status
Connection Analysis
Application History
Application Compliance
Application Decommission
Create Ticket
VMware NSX Application connectivity status and discovery is available for North-South traffic.
Chapter 1
The servers that an application uses are usually spread across the network and rely on rules
in multiple firewalls to make sure that communication can pass through the network. In
SecureApp, even a business owner with no network management experience can
define the servers and services that the application requires and track the progress of
the implementation. Based on the topology of the network and the policy revisions retrieved
from the network devices, SecureApp can translate those requirements into specific changes
that the network and security teams must make in all of the relevant firewall policies.
SecureApp gives you an intuitive interface to define your application critical connections. You
can see a list of your applications, the connectivity that those applications rely on, and the
status of the connectivity. SecureApp also lets you see at a glance if the connections for your
application are blocked and lets you send a request to repair the connectivity.
a web server that is located in your internal network. Both web servers send queries to a
database server ([Link]) that is located in a separate internal segment of your network.
In order to create the firewall rules to allow traffic for this application, you need to add rules to
two different firewalls. After you do that, you still need to monitor the rules to make sure that
no changes in the firewalls disrupt the traffic for the application. Because this web application
is the core of your business, you cannot afford to have any downtime.
With SecureApp, you can build this connection with the information that you know about the
application.
When you integrate with SecureChange, then you can create a SecureChange ticket that
includes all of the information that the network and security teams need to approve and
implement the changes.
SecureApp sends you a notification if there is any disruption to this traffic so you can correct
it immediately.
Chapter 2
Setting up SecureApp
Tufin Orchestration Suite (TOS) includes SecureTrack, SecureChange Basic and SecureApp
Basic. The functionality of the products is defined by the license (see "SecureChange and
SecureApp Licensing" on page 17) that is installed in SecureTrack. To setup SecureApp, you
must:
• Assign roles (see "Assigning Roles to Users" on page 34) with SecureApp permissions
to users
Installing TOS
Tufin Orchestration Suite (TOS) includes SecureTrack, SecureChange, and SecureApp (see
"Managing Application Connections with SecureApp" on page 10). The latest version is
available for download from our support site ([Link]
overview/). After you install the TOS package, you can enable or disable the products.
Note: Changes to the locale configuration of the operating system can cause errors when
you install or upgrade TOS. Make sure that the LANG value of the locale is set to
en_US.UTF-8.
Prerequisites
• Verify that your locale variable is set to en_US.UTF-8:
# locale
LANG=en_US.UTF-8
...
LC_ALL=en_US.UTF-8
LC_ALL=en_US.UTF-8
LANG=en_US.UTF-8
b. Logout and log back in, and confirm the locale settings are correct.
LANG="en_US.UTF-8"
SYSFONT="latarcyrheb-sun16"
d. Logout and log back in, and confirm the locale settings are correct.
• If your server is behind a NAT, the NAT device must be configured to send one of the
following headers for each request:
HOST
The header should also contain the remote host DNS name or IP.
If a request does not include one of these headers, users will not be able to log in to
SecureTrack. Installing TOS on a server
To install Tufin Orchestration Suite on a server:
Note: Do not login with a different account and use the sudo command.
3. From the command line on the TOS server, verify package integrity with the command:
sha1sum <filename>
tos-<TOS_version>-<release_level>-<TOS_build>-final-
[Link]
/bin/sh <filename>
tos-<TOS_version>-<release_level>-<TOS_build>-[Link]
8. To install a valid license (see "SecureChange and SecureApp Licensing" on page 17):
c. Click Install to browse to the license file on your computer and click Open.
When you login to SecureChange and click on SecureApp you will see the application
inventory page.
The TOS products are now installed and ready for you to login with your web browser.
Then, the next steps to get started with SecureChange or SecureApp are to configure:
Then you are ready to build your applications and create workflows to manage your change
requests, according to your product license (see "SecureChange and SecureApp Licensing"
below).
order). Any additional application you want to create or access requires a separate license,
which is installed through the SecureTrack licensing mechanism.
SecureChange Basic is the version of SecureChange that is included when you purchase
SecureTrack. SecureChange Basic lets you use the pre-defined workflows (see "Basic
Workflow Configuration" on page 31) to manage network requests for your organization with
all of the SecureChange features, except workflow customization. All other workflows and the
SecureChange provisioning capabilities are only available for fully licensed SecureChange
users.
When you purchase SecureChange and install the license, you can customize the workflows
to match the processes that your organization uses to handle network requests, including
conditional workflows and automatic actions. SecureChange is then integrated with
SecureApp so that you can open change requests directly from SecureApp with the precise
access requests to implement the SecureApp connections.
To install a license:
In SecureTrack, go Settings > Administration > Licensing view your current TOS license
status. To install a new license, click Install to browse to your license file.
Available Licenses shows the number of licenses you have and their names.
License Status shows the total number of applications you have, and specifies the
sub-total number of applications in each status: Licensed, Plug-and-Play and
Unlicensed.
2. In SecureApp, go to the Applications view to see the license status in the applications
list:
The bottom left status bar indicates your license status. After you install a new
license in SecureTrack, go to SecureApp's status bar and click Refresh license
status to retrieve the updated data.
• Browser: Microsoft Internet Explorer 11; Mozilla Firefox 58, 59, 60; Google Chrome 67
1. Go to: [Link]
<server> is the IP address or DNS name of the SecureChange and SecureApp server.
If the browser warns you that it is not familiar with the site's security certificate, allow
the browser to continue to the site. You can prevent the certificate warning from
appearing in the future ([Link]
Password: admin
a. You must change the administrator password when you login for the first time.
After the initial password change, the administrator password can be reset from the
command line.
b. You can enter an email address that administrative email notifications are sent to.
We recommend that you enter the address of an email list so that you can easily edit
the list of people who receive messages.
This administrator can only configure the Settings in the Settings tab. Then, the next steps to
get started with SecureChange or SecureApp are to configure:
Then you are ready to build your applications and create workflows to manage your change
requests, according to your product license (see "SecureChange and SecureApp Licensing"
on page 17).
Connecting to SecureTrack
SecureChange and SecureApp must be configured to integrate with SecureTrack. You can
connect to SecureTrack that is enabled on the same server or installed on a remote server. In
a SecureTrack distributed deployment you must connect to the central server.
Note: To use SecureTrack on a remote server, both servers must have the same version
of TOS. To confirm this, on each server run: st version and scw version. The
information must be the same on both servers.
Prerequisites
Create a dedicated SecureTrack account that SecureChange and SecureApp use to get
SecureTrack information.
• If SecureTrack does not use domains, assign the user Administrator permissions.
Assign the user Super Admin permissions so that in SecureChange and SecureApp
you see the devices in all of the domains.
Assign the user Multi-Domain admin permissions and select the domains that have
the devices that you want to see in SecureChange and SecureApp. You cannot see
in SecureChange and SecureApp the devices in domains that are not selected.
If you are using SecureTrack on the same server with SecureChange and
SecureApp:
3. (optional) Select Show link to SecureTrack to give all users a link to SecureTrack
above their username:
4. (optional) Change the Connection check interval, which configures how often
SecureChange test its connectivity to SecureTrack.
5. Click Save.
1. Get the server and authentication information for your organizational SMTP server.
SMTP Server: SecureTrack can send email notifications and alerts directly (using its
SMTP engine), or act as an email client, and send emails to an organizational SMTP
server. In order to send emails to an SMTP server, configure its IP address in this
option. The default setting for the SMTP Mail Server is localhost, which sends
emails directly.
Source Email Address: The email address chosen by SecureTrack in the SMTP
email messages sent (for example: securetrack@[Link]). This can be
used for easy identifications of email messages coming from SecureTrack.
SMTP server requires authentication: Select this if your SMTP server requires
authentication for sending email, and type the username and password that will be
used by SecureTrack to communicate with the SMTP server.
Enable SMTP over SSL: Select if your SMTP requires certificate encryption when
sending and receiving emails. If you require encryption then select to trust all
certificates or list specified certificates.
Note: The option Trust only the certificate below requires TufinOS 2.15 or
above. For non-TufinOS users, this option requires PHP version 5.6 or
above.
4. Click Save.
• Retry interval (in minutes) to resend messages: How long a failed message waits
until SecureChange and SecureApp try again to send it.
• Expiration interval (in days) for unsent messages: How many days SecureChange
and SecureApp attempt to send the message until SecureChange and SecureApp
stops attempting to send it.
• Server Name: The name syntax for IP addresses not associated with a server (that
were discovered by connection discovery).
• ACI Configuration: Select the user that is assigned as the owner of added Cisco ACI
applications (see "Building the Application Inventory" on page 46).
To set the server name to use for IP addresses not associated with a server (that were
discovered by connection discovery):
2. In the two text boxes enter the text that is appended before and/or after the IP address.
3. Select the Use the resolved DNS name, if available option if you want to use the
DNS server that is configured in the operating system to resolve the DNS name listed
for the IP address.
Rejected tickets: Select to allow a user to ignore rejected changes (see "Handling
Rejected Tickets" on page 126).
Connection Discovery: The default duration days to run connection discovery (see
"Discovering Application Connections and Resources" on page 56).
Adding Users
SecureChange and SecureApp permissions are based on users, groups and roles.
SecureChange and SecureApp let you use, either:
We recommend that you assign roles to groups so that the role applies to any user that is a
member of the group. Predefined roles are:
• Security Administrator - Can create and manage workflows, handle requests, and
can configure SecureChange and SecureApp settings in the Settings tab
• Users with the Requester role for anyone who submits requests
• Users with the Security Administrator role reviews, approves or implements requests.
You can add users and groups to SecureChange and configure their roles and permissions.
You can also configure an alternative authentication method so that the user passwords are
verified with a separate authentication system.
4. Click Done.
The details of the user or group are shown in the Details tab, where you can also edit
the details:
Once users and groups are added, you can manage group membership.
5. To assign the new user permissions, click on the Roles tab and select one or more
roles.
6. Click Save.
Your new user accounts have permission to log into SecureChange and SecureApp. You
now can configure workflows (see "Basic Workflow Configuration" below).
• Access Request - Submit request with specified access > Business approval >
Technical design > Security review > Implementation
• Group Object Request - Submit group object change request > Approval >
Implementation
• Remove Access - Submit remove access request > Approve access removal >
Implement access removal
In SecureChange Basic, you can configure the assignments for these workflows and use
these workflows with their default configurations.
• Make workflows that match the process in your organization by customizing the
workflows and creating new ones.
Server decommissioning
Rule decommissioning
Rule recertification
To activate a workflow:
If you are logged in as a different user, click Logout from the user menu:
c. Select the step that a ticket returns to if the requester reopens it.
After all of the steps in the workflow are complete, the requester is prompted to
confirm that the request is complete. If the requester sees that the request is not
complete, the requester can reopen the ticket. The ticket then returns to the step
selected here so that the work can be redone.
d. Click OK.
b. In the Assignments tab, select the Assignment mode. For a simple workflow, select
Auto-assigned for SecureChange to automatically assign the ticket to a participant.
You can also configure conditions, based on which, the step is skipped.
5. When all steps are marked as valid, set the workflow status to Active.
6. Click Save.
SecureChange is now ready for end-users to login and submit requests. Next, you can:
• Manage requests
• Customize workflows
• Create reports
• View My Requests and create requests - A user with this permission can create
SecureChange tickets (see "Creating SecureChange Tickets" on page 120) and follow
the progress of the ticket in SecureChange > My Requests
• View SecureApp and access SecureApp applications - A user with this permission
can view existing applications (see "Building the Application Inventory" on page 46),
configure application connections (see "Managing Connections" on page 88) for
applications that they own or for applications that they are an editor of.
A user that does not have this permission cannot use SecureApp and does not see the
SecureApp tab in the application bar.
• Run connection status analysis - A user with this permission can click on the
status of a connection and see the analysis of the routing and firewall rules (see
"Managing Connections" on page 88) that impact the traffic in the connection.
Create new applications - A user with this permission can create new applications
(see "Building the Application Inventory" on page 46) that the user is the owner of.
The user can also add other users to the list of editors for the applications.
• Edit all applications and change ownership - A user with this permission can
edit any application and assign another user as the owner of an application.
Tufin Knowledge Center: [Link]/support/kc 34
Tufin™ SecureApp™ User's Guide
Create closed ticket - A user with this permission can create a closed ticket (see
"Creating SecureChange Tickets" on page 120), that is a ticket that does not go
through the workflow process. This can be useful so that:
• A SecureChange ticket exists for connections that are already configured in the
devices so that auditors can see the access request in the ticketing system.
• The next ticket created from the connection does not include any previous
changes.
Note: When you create a closed ticket, revisions that match the ticket are
shown in the Change browser in SecureChange as unauthorized,
because they do not pass through an approval step in SecureChange.
• View application access portal - A user with this permission can use the application
access portal to request access to an application (see "Self-Service Application
Access" on page 68) without logging into SecureApp.
Security compliance
analysis
Connection discovery
Create applications
Configure applications
and owners
Create closed ticket
View application
access portal
Change
system settings
4. In Users:
5. Click Save.
Working with Applications and Connections Logging into SecureChange and SecureApp
Chapter 3
If any of these connections is blocked by a firewall, users cannot access the website. The
business owner can keep a list of all of the required connectivity, but cannot create a detailed
set of instructions for implementing the connectivity in the firewalls. The network and security
teams can analyze the locations of each server to decide which firewalls need to have rules
to allow the connectivity, but they cannot easily manage all of the firewall rules to make sure
they are all maintained correctly.
Working with Applications and Connections Logging into SecureChange and SecureApp
• Server Lookup lets you search for a server and see all the server connections and
groups.
• Cloud Console lets you manage all cloud resources that are not associated with a
SecureApp application.
If multi-domain mode (see "Enabling Multi-Domain in SecureApp" on page 39) is enabled, the
SecureApp menu includes:
• Home displays the inventory of applications and application packs in the default
domain.
• Customers displays the customer list. Select a specific customer to view the inventory
of applications and application packs that belong to the customer.
• Server Lookup lets you search for a server and see all the server connections and
groups.
• Cloud Console lets you manage all cloud resources that are not associated with a
SecureApp application.
Applications
In SecureApp, the business owner keeps a list of all of their applications with the required
connectivity for each application. The connectivity is defined in terms that are easy for the
business owner to provide. SecureApp translates the connectivity into terms that are easy for
the technical teams to implement. The business owner can publish relevant application
connections,making them available for re-use by other users.
1. Define a new application (see "Building the Application Inventory" on page 46).
2. Define the resources (see "Managing Resources" on page 54) (servers, services and
users) that the application requires.
3. Create a new connection (see "Managing Connections" on page 88) and add the
resources to the connection.
• Segregated domains: Customers are separated from each other and each connection
can only include resources from one customer.
• Interconnected domains: Customers are all in one environment and each connection
can include resources from multiple customers. This is helpful if multiple customers use
the same IP addressing scheme. For example, Customer 1 assigns an IP address to a
server and Customer 2 assigns the same IP address for one of its clients. Using multi-
customer mode in SecureApp, you can distinguish between customers and manage
1. Check with the SecureTrack administrator to make sure that there are domains
configured in SecureTrack.
2. Go to Settings > Multi-Domain, and then select one of the following options:
Note: Multi-domain mode applies to both SecureChange and SecureApp, and the
selection cannot be undone.
After you enable multi-domain mode and the list of domains is updated, you can go to
Customers to:
• Create applications and connections (see "Working with Applications and Connections"
on page 37) for each customer
Managing Customers
The Customers window lets you view and manage your customers and their applications.
Customers is only available if multi-customer-mode is enabled.
The information displayed is Status and Name (name of the customer). The status can be
one of the following icons:
• Import Customers (see "Import Customers" on page 42) - Click to import the
customer domains from SecureTrack.
• View a Customer's Inventory - Click a customer name to view the inventory for that
customer.
• Delete a Customer (see "Delete a Customer" on page 43) - Select the customer, click
, and select Decommission.
• Filter - Enter text in the filter box to list only the customers that match the text you
enter.
Import Customers
After enabling multi-domain mode (see "Enabling Multi-Domain in SecureApp" on page 39),
in either segregated or interconnected mode, you must import the customers from
SecureTrack before you can work with the customers.
To import customers:
3. From the Import Customers window, select each customer that you want to import,
and click Add.
4. Click OK.
For each customer, you can click on the customer name and then create applications and
connections (see "Working with Applications and Connections" on page 37) for the customer.
Delete a Customer
When you delete a customer all applications associated with the customer are removed, and
the history of the application will no longer be available.
Note: A decommissioned application can remain in the system without affecting the
application license quota. If you wish to maintain the history, you can decommission
the customer instead.
To delete a customer:
4. Click .
The customer is removed from the list, and all applications associated with the
customer are removed from SecureApp.
Decommission a Customer
When you decommission a customer:
• All resources of the selected customer become unavailable for use in new connections
or applications.
Note: Open every application belonging to decommissioned customer and create a ticket
to close all of the access associated with the customer.
To decommission a customer:
5. Click .
Navigate To Customers
Applications
An application has properties, including name, owners, editors, and viewers. You configure
the connectivity requirements that include all of the connections the sources, protocols and
destinations of network traffic. If you have more than one customer, you can enable multi-
customer (see "Enabling Multi-Domain in SecureApp" on page 39) mode to create
applications for each customer and have data segregation (segregated) or IP address
differentiation (interconnected).
Cloud Applications
You can import applications from cloud platforms and monitor them in SecureApp. Cloud
applications are marked in the applications inventory with the icon of the cloud vendor, and
cloud servers are marked in the resources with the icon of the cloud vendor.
• Amazon AWS - Use the Cloud Console (see "Managing Cloud Resources" on page
81) to add AWS applications.
• Cisco ACI - When you add a Cisco ACI Platform to SecureTrack, the application are
automatically shown in SecureApp as read-only. Connections are not created for
contracts with only a filter from the common tenant, or without a provider, consumer, or
filter. SecureApp imports applications from up to 10 tenants and up to 50 application
profiles per tenant. The ACI applications are created with the owner selected in
SecureApp Settings (see "Configuring SecureApp Settings" on page 26). The ACI
applications are created with these properties imported from Cisco ACI:
• Filter - View only your applications or all applications, and enter text in the filter box to
list only applications that matched the text.
• Build Connections - Click on the application or application pack name to manage its
connectivity requirements.
• Change Properties - Select the application and click to change the name, owner or
editors of the application.
Select Delete to remove all application or application pack data from SecureApp.
Applications
An application has properties, including name, owners, editors, and viewers. You configure
the connectivity requirements that include all of the connections the sources, protocols and
destinations of network traffic.
Application Packs
When multi-customer (see "Enabling Multi-Domain in SecureApp" on page 39) mode is set to
interconnected, the business owner can create applications packs, which are a set of
published connections to applications that are grouped together. Application packs let a
business owner manage a related set of connections through a single group. For example, a
business owner can bundle the connections to a DNS server, an authentication server, an
Exchange mail server, and an internal database into an application pack. After the application
pack is published, the customer connects to the application pack and gets connections that
include all of the required connectivity.
• - application
• - application pack
4. Click .
The new application or application pack opens. You can now manage its resources (see
"Managing Resources" on page 54) and connections (see "Managing Connections" on page
88).
4. (optional) Publish the application pack to make it available for reuse by other users.
Decommissioning Applications
Managing firewall rules in the context of an application also gives you a simple solution for
removing all access that is used by an application. Because SecureApp has a list of all of the
connections that an application uses, you can decommission an application and request to
remove all access associated with the application from the firewall policies. This process
cleans up the firewall policies from unused access to prevent unnecessary security or
performance risks.
• All access changes are entered into the next ticket that you create.
To decommission an application:
A SecureChange ticket opens with access requests to remove all access that was
requested for the application. If no tickets were opened for the application, you do not
need to open a ticket to remove any access.
Managing Tags
Tags are labels that name a connection to an application pack. The tag can be used to
identify the functionality of the connection for users. Every connection to application pack
Tufin Knowledge Center: [Link]/support/kc 51
Tufin™ SecureApp™ User's Guide
must be associated with a tag before it can be published. A single tag can be associated with
multiple connections, letting you group related connections with a single, meaningful name.
Tags are unique to a specific customer.
To manage tags:
Click SecureApp > Home to display the inventory for the default customer, or
• Associate a tag with a connection - Select a connection for a tag and click
to associate the tag with the connection.
Use the <CTRL> and <SHIFT> keys while clicking to select the multiple interfaces.
4. Click .
3. Click .
Managing Resources
Network applications require that software components in different locations connect to each
other and transfer data using specific services. The resources defined in SecureApp are:
• Source and Destination: Define where the software components for your applications
are installed:
Servers and server groups: Can be hosts, IP ranges, subnets, load balancers and
virtual servers.
• Services/Application identities:
Application identities: The application level protocol used to connect sources and
destinations, such as Facebook Apps. When creating your connections, you can
select application identities from a predefined list in SecureApp.
• Import resources (see "Importing and Exporting SecureApp Data" on page 79) from an
external database or file
• Manually create individual or groups of servers (see "Creating Servers" on page 62),
users (see "Creating Users" on page 65) or services (see "Creating Services" on page
67)
Note: Application identities are not created but selected from a comprehensive list
available in SecureApp.
Once you define these resources, you can use them to build the required connections (see
"Managing Connections" on page 88).
Note: If a server is already defined for another application, you can use that server in the
connection without defining a new server for your application (see "Managing
External Applications" on page 104).
If you edit the IP address of a resource or a member of a resource group, you can save the
change and open a ticket to update the firewall rules that use the resource. The ticket
includes "Drop" access requests for the connections that use the old details of the resource
and "Accept" access requests for the same connections with the new details of the resource.
Note: To run connection discovery, you must be the owner or an editor of the application.
For example, you know that your CRM application requires connections to the CRM database
server, but you don't know where those connections come from and what services they use.
To help you define the connections that the CRM requires:
• Manually create a resource for the CRM database server with its IP address and add it
to the destination of the connection.
• When you click to start connection discovery, SecureApp reviews the actual allowed or
denied network traffic that was sent to the CRM database server and was logged by
your firewalls.
• The discovery results show you the sources and services that were in the traffic to that
server.
• To complete the connection, you just have to add the relevant sources and services
from the list of discovered resources to the connection.
Note: Connection discovery is not supported for connections that have AWS servers in the
source or destination. To discover AWS connections, go to the connectivity map
(see "View Connectivity Map" on page 134) and click Discover.
The traffic that you want to discover is routed through a firewall device and does not
use IPv6 addresses
The firewall device has an accept or deny rule (for example, a cleanup rule) that logs
traffic hits
2. Login to SecureApp.
Server Name - The syntax that is used as the name for discovered IP addresses
that are not associated with a server.
• You can add text that is appended before and/or after the IP address.
• You can use the DNS server that is configured in the operating system to resolve
the DNS name listed for the IP address.
4. Go to SecureApp and click on the application for which you want to discover
connections.
5. Identify a connection for which you want to discover connections, or create a new
connection and add at least one server from your application to the source or
destination field of a connection.
Because connection discovery lets you discover connections for your application, the
field that the discovery is based on must only include servers that belong to your
application. It cannot include servers from another application, users or ANY.
Unless you stop the discovery, it runs for the number of days set in Settings >
SecureApp Settings at the time the discovery starts.
8. Select the fields that you want to discover for the connection.
The field that the discovery is based on is locked and you cannot change it or the
resources in it while discovery is running.
As the discovery continues, the number of discovered resources is shown. You can
open the list of discovered resources while discovery is running or you can stop the
discovery. After you stop the discovery, before you can run discovery again you must
clear all of the discovered resources.
The results show up to 100 servers with their IP addresses, and 100 services with their
protocol and timeout.
Note: Some reasons a connection may not be discovered are: the traffic is not
routed to pass through a monitored firewall policy, the traffic was not logged
by a firewall rule, the firewall is not configured to send syslogs to SecureTrack,
the IP address or service is translated with NAT
10. To edit the name of a server, or the name and timeout of a service, you can select it
and edit the name and timeout value.
11. To add discovered resources to the connection, select the resources and click Save.
For any discovered resource that does not already exist in SecureApp, the resource is
added to SecureApp.
All discovered server resources are single hosts. If you find that there are many
discovered hosts in a subnet, consider manually creating a subnet and add it to the
connection. If you find that there are many server or service results, you can also select
the resources to create them, add them to a resource group and add the resource
group to the connection.
Select the resources that you want to add to the connection and click Save.
Delete resources that are not relevant to your application and click Save.
Any new resources are saved and the connection is saved with the selected resources.
You can create a ticket for changes that you make while connection discovery is running or
after it is stopped.
Note: Application identities are selected from a predefined list in SecureApp and therefore
cannot be created manually.
Creating Servers
Servers are network resources that you can add to the source or destination of a connection
to define the connection traffic. When you define a server or server group, it is associated
with your application. Other application owners can add these servers to connections for their
applications from the Applications resources, or they can connect to your application
interfaces (see "Building Interfaces to an Application" on page 106). (The application
interface defines the connections that other application owners must use to connect to your
application.)
IP range - A range of IPv4 or IPv6 addresses defined by start and end addresses
Subnet - A subnet of IP
When you add a virtual server to the source of a connection, tickets opened for that
connection allow traffic from the IP addresses of the virtual server group members.
When you add a virtual server to the destination of a connection, tickets opened for
that connection allow traffic to the virtual IP address of the virtual server.
• A server group that contains a list of server members that are already defined in
SecureApp
In order to make changes to connections, it may be easier to add server groups to the
connections. In this way:
• You can change a list of group members without adding or removing the group object
from the connections that use it.
• When you create a ticket, the ticket includes all firewall changes that need to be
implemented as a result.
After you add a server to connections, you can also replace that server with a group (see
"Changing a Connection by Editing Server Group Membership" on page 103).
1. From the list of applications, click on the application that the server is associated with.
Note: To define a new server for a different application, you can click on Applications and
select the application that the server is associated with.
Server - Select the type of server (IP range, Host, Subnet or Virtual server).
• Host - a single IP address. You can enter the DNS name as the Name and click
to automatically fill in the IP address, or you can enter the IP address and click
to automatically fill in the DNS name.
If you do not have DNS configured, the name is filled in automatically based on
the Server Name syntax in Settings > SecureApp Settings.
• Virtual server - a server, or load balancer, with a virtual IP address that reroutes
traffic to a group of servers, or virtual-server group members, that can equally
process that traffic. You can search for the virtual IP or the IP address of one of
the virtual-server group members and select the virtual server to add.
Server group - Enter the name and description of the group. You can select the
servers to include in the group, or you can click New Server to create a new server
and automatically add the new server to the group, or save the group without any
servers and add the servers later.
After you create a group, to search for members within the group, you can:
• View a connection where the group is used and click on the name of the group.
Note: When you create a server without an IP address, the new server can be used
as a "place holder" to be filled in later by another user. A server without an IP
address is shown in SecureApp with the icon, and a server with an IP
address is shown with the icon.
You can then assign the IP address by editing the server details at another
time, or copy the IP of another server when you deploy an application (see
"Migrating an Application to a Different Environment" on page 110).
6. Click Save.
You can now add the server or server group to a connection, or select the server or server
group and click to change the details.
VM instances are added as server resources when they are associated with an application.
See Auto-Associate Cloud Resources (see "Auto-Associate Cloud Resources" on page 83) or
Manually Associate a Cloud Resource (see "Manually Associate a Cloud Resource" on page
85) for details. Cloud resources associated with an application display as server resources
• - Instance is active
• - Instance is inactive. If the name of the instance is shown with strikethrough font,
then the instance has been terminated in the cloud or monitoring of that instance was
removed from SecureTrack.
Note: The icon does not identify connectivity status. It identifies only the state of the
instance.
Creating Users
You can add users to the source or destination of a connection.
2. In the list of resources, click on Users to open the list of users available to all
applications.
New local user - a user that you can associate with a specific IP address
Note: Because SecureApp does not connect to an LDAP server in this version,
the LDAP user is not associated with an IP address. Therefore, in
SecureChange, if the access request has been configured in the workflow
to show User from Palo Alto Networks devices then when you open a
ticket for a connection that uses an LDAP user, the LDAP user name is
shown in the User field of the access request. If not, then the LDAP user is
not included in the ticket.
New user group - a group that can include users and LDAP users
User group - Enter the name and description of the group, and select the local or
LDAP users to include in the group. You can also click New Local User or New
LDAP User to create a new user and automatically add the new user to the group.
After you create a group, to search for members within the group you can either:
• View a connection where the group is used and click on the name of the group.
5. Click Save.
You can now add the user or user group to a connection, or select the user or user group and
click to change the details.
Creating Services
SecureApp includes a comprehensive list of pre-defined services. You can also add your own
custom services to add to connections. These custom services can be added to the global list
of services available to all applications, or to the local list available only to the current
application.
For example, often you have an application that uses a specific port. This port is not used by
other applications. You are going to need to create a custom service for this specific
application. However, there is no need to have it listed as an available service when creating
connections for other applications. Therefore, you can create the new service as a local
service. You can also create a service group to be included in the application's local list. After
creating your new local service/service list, you can then easily select from it when defining a
connection for this application. However, when creating connections for other applications,
these custom local services are not included in the full list of services (global) that can be
used by all applications.
Note: Application identities are also used to connect sources and destinations, but are
selected from a predefined list in SecureApp and not created manually.
2. In the resources list, click on Services to open the list of services available to all
applications.
3. Click the Global or Local tab, depending if you want the new service/service group to
be available to all applications or just to the current application.
4. Click and select either New to create a new service or New group to create a
new service group.
New service - Enter the name, protocol, port number, timeout value in seconds
(optional) and description of the service.
New service group - Enter the name and description of the group, and select the
services to include in the group. You can also click New Service to create a new
service and automatically add the new service to the group.
Note: If you are adding a new local service group, both global and local services
are listed and can be selected for your new group. When you are adding a
new global service group, only global services are listed and can be
selected for your new group.
After you create a group, to search for members within the group you can either:
• View a connection where the group is used and click on the name of the group.
6. Click Save.
Note: Global user defined services can be edited when they are not part of a connection of
any application. Local services can always be edited. Global predefined services
cannot be edited.
• An end user may require web access to sensitive applications that have access control
on the network level.
• Developers who use an external API may need to pull data from servers that are
protected by firewalls.
• A system administrator who is not on the application team may need to access an
application server to perform maintenance operations.
The types of access users need are usually known in advance. The application owner can
define this connectivity using SecureApp, and then allow users to submit application access
requests through a designated portal – the Application Access Portal.
2. Adding this server group to connections that are part of the requested application.
For example, users may request access to the Email Access application. In this case, the
application owner defines a group called Email Users, to which users can be added.
Next, the owner adds this group to the Source field of the Email Access connection that has
the company’s email server in its Destination field.
• Create a new server group: Click and select New group from the menu.
Note: The details you define here will be displayed in the Application Access
Portal. This information helps users to choose the type of access to
request.
• Name – Enter the name that you want users to see in the Application Access
Portal as the Access Type.
• Comment – Enter the text that you want users to see in the Application Access
Portal as the Access Type Description.
• Options – Check Allow requests to join this group from the Application
Access Portal. Through the Application Access Portal, users will be able to
request access to connections that include this group.
Note: Place a link to the Application Access Portal on an intranet site that
requesters use to submit requests, or send them the link by email.
[Link]
cationAccess/[Link]?clear=1
This URL is also found in the Application Access Portal link in the New Group or
Edit Group windows.
c. Click Save. The list of servers shows this group as a group icon that has a black
arrow, indicating that users can ask to join this group:
2. Add the new group to the Source fields of connections you want to make available to
users, and then click Save Connections.
3. Make sure that all requesters have a SecureApp user account. If not, create these
users (see "Adding Users" on page 28).
4. Allow users to view the Application Access Portal, used to submit access requests:
Go to Settings > Users > Permissions, and select View application access
portal.
5. To customize the automatic email notifications that SecureApp sends when application
access requests are submitted and processed, go to Settings > Mail Notifications and
edit these templates as needed:
Requested access to application (to owner) – sent to the application owner once
a user submits a new application access request through the Application Access
Portal. The application owner is required to review the request and either approve or
reject it.
If the owner approves the application access request, the next step is to open a
ticket that specifies the required firewall updates.
The connections to which you added the group are now available through the Application
Access Portal, and users can submit requests to access the application.
Note: External users go to the Application Access Portal using a URL. Place a link to the
Application Access Portal on an intranet site that requesters use to submit requests,
or send them the link by email.
[Link]
tionAccess/[Link]?clear=1
This URL is also found in the Application Access Portal link in the New Group or Edit
Group windows.
2. To search for the applications that you want to access, enter free text into the Search
Application Name
The Application Access Portal automatically completes the request details in the
bottom pane:
The Access Type and Access Type Description are set by the selected search
result.
IP address shows the name of the computer you are using to submit the request. If
the DNS server configured in the operating system cannot resolve the hostname, it
shows the computer’s IP address.
5. Click Submit.
A confirmation message shows that the access request was submitted and gives you a
Confirmation ID. You also receive an email notification.
6. If you want to request another access type or request access to another application,
click Return to Application Access Portal.
1. In SecureApp, select the application specified in the email notification and display its
Connectivity view.
The Requests for application access window shows all pending requests:
3. To handle a request, select it from the list, review its details and then click to approve
it or click to reject it.
The Action column of the request shows whether it is approved or rejected. To remove
the specified Action, click Clear.
If the request is approved, SecureApp creates a server object that represents the IP
address in the request for application access. This object is shown in the Servers
list and is added to the group indicated by the request Access Type.
If the request is rejected, SecureApp sends the user an email notification that the
request was denied.
5. Click Create Ticket. The ticket is automatically filled with the details of the request for
access.
Tufin Knowledge Center: [Link]/support/kc 75
Tufin™ SecureApp™ User's Guide
6. Click Submit to submit the ticket in order to update the firewall rules and allow this user
to access the requested application.
The ticket now moves through the steps of the selected workflow. After this ticket is closed by
the ticket handler:
• If this ticket is completed, the firewall allows this user to access the application and
SecureApp sends the user an email notification that the request has been approved.
• If this ticket is rejected, SecureApp sends the user an email notification that the
request has been denied.
Decommissioning Servers
When you take a server out of the network, you must also delete it from your network devices
to keep your devices clean and efficient. You can delete the server from your Resources
panel and then create a ticket to remove all firewall access associated with this server.
If you want to review the connectivity that is dependent on the server, you can review the
impact of decommissioning the server (see "Reviewing Impact of Decommissioning Servers"
on page 77) before you delete the server.
To delete a server:
1. In the Resources panel, select the server from the Servers list.
4. Create a ticket to request an update of all firewall rules that include the
decommissioned server.
To decommission a server:
1. In the Resources panel, select the server from the Servers list.
You can click on (Export) to export a list of the dependencies in CSV format,
including: affected connections, depended servers, depended groups, affected
interfaces
4. Click Show Details to see the list of connections and interfaces that use the selected
server.
To filter the connections and interfaces by application, select the application from the
list of applications.
To move the selected server to another application, click Move server and select the
application to move the server to. After you move the server, the list of connections
and interfaces that use the selected server is updated.
To replace the server in all connections with another server or server group, click
Replace server and select a server from another application to replace the selected
server. After you replace the server, the list of connections and interfaces that use
the selected server is updated.
To remove the server from the connections and interfaces, click Decommission.
You can also use the SecureApp REST API to export application data from SecureApp. For
more about the SecureApp REST API, see the TOS Developer's Guide (see TOS
Developer's Guide on the web - developers_guide.htm) (also available for download on the
Knowledge Center Home Page ([Link]
[Link]
pository/import_applications/download_template
2. Enter the server, server group and connection details in the template file as shown
below.
3. Go to this URL to upload the Excel file and its contents into SecureApp:
[Link]
pplications/upload
The template file includes 4 sheets: servers, services, connections, application identities
• Servers - In the servers worksheet you can define servers with IP addresses and
groups with group members. The columns in the worksheet are:
• Connections - In the servers worksheet you can define connections between servers
or server groups. The columns in the worksheet are:
If multi-domain mode (see "Enabling Multi-Domain in SecureApp" on page 39) is enabled, the
cloud console also includes a filter that lets you display cloud resources for a specific
customer.
The page initially displayed is empty. Enter a search term to display the specific cloud
resources you wish to view and manage.
• Filter by customer - (if multi-domain mode is enabled) Select the specific customer in
• View Cloud Console Manager - Click on the hostname of a cloud device to display its
console manager.
• - currently enabled
When auto-associate is first enabled, SecureApp checks all existing instances for the
specified tag. Each existing VM instance with the specified tag will be associated with the
named SecureApp application.
Every server in SecureApp requires a unique name. If you import a server with a name that is
not unique in SecureApp, SecureApp will add a number to the end of the name provided to
ensure uniqueness. When multi-domain is enabled, of a VPC is detached or migrated to a
different domain, the instance will be terminated in SecureApp.
Prerequisites
Note: Make sure that you have enough licenses available in your SecureApp Bundle for
the number of SecureApp applications you plan to use. Contact your Tufin
representative if you have licensing questions.
Procedure
To enable auto-associate:
4. Click .
To disable auto-associate:
3. Click .
4. Click .
Every server in SecureApp requires a unique name. If you import a server with a name that is
not unique in SecureApp, SecureApp will add a number to the end of the name provided to
ensure uniqueness. When multi-domain is enabled, of a VPC is detached or migrated to a
different domain, the instance will be terminated in SecureApp.
Prerequisites
Note: Make sure that you have enough licenses available in your SecureApp Bundle for
the number of SecureApp applications you plan to use. Contact your Tufin
representative if you have licensing questions.
Procedure
To manually associate a single cloud resource:
4. Click .
• " " - Returns VMs with the exact phrase in any field, for example: "dns server"
(case-insensitive)
• <fieldname>:<text> - Returns VMs with the text in the specified field, for example:
tag:key
If you specify more than one field in the search, only VMs matching both field values
are shown
tag:<tag>/<value> - Returns VMs with a tag key matching <key> and a tag
value tag matching <value> (case-insensitive)
You can search for a tag key only (for example: tag:key) or value only (for example:
tag:/value)
For example, the following search will display all VM instances whose hostname contains the
word "dnsapp" and that also contains the word "infrastructure" in any tag.
hostname:dnsapp tag:/infrastructure
Procedure
To search for instances:
2. Click .
Managing Connections
Application connectivity includes each network connection that the application needs. To
build the connectivity requirements for the application, you add connections and then add
resources to the source, service and destination of the connections.
For the Source, you can add: For the Service/Application For the Destination, you can add:
▪ Servers (see "Creating Servers" Identity, you can add: ▪ Servers (see "Creating Servers"
on page 62) and server groups ▪ Pre-defined services on page 62) and server groups
that are defined for the application ▪ Custom services (see that are defined for the application
(hosts, subnets, IP ranges and "Creating Services" on page (hosts, subnets, IP ranges and
load-balancer virtual servers). 67) or service groups load-balancer virtual servers).
▪ Network resources that are ▪ Application Identities ▪ Network resources that are
defined for external applications ▪ Any defined for external applications
(see "Managing External (see "Managing External
Applications" on page 104) Applications" on page 104)
▪ Users or user groups (see ▪ Any
"Creating Users" on page 65)
▪ Any
If you have a large number of connections, you can configure how many connections (see
"Configuring SecureApp Settings" on page 26) are shown on each page. You can enter the
page to go to or click Next or Prev to navigate the connections pages.
Note: To let users create connections that use servers from other applications in both the
source and destination, the administrator must enable this permission in Settings >
SecureApp Settings: Allow users to create connections with external
resources in both source and destination
• Edit the connection - Add resources manually (see "Adding Resources to Connections
Manually" on page 92) or with connection discovery (see "Discovering Application
Connections and Resources" on page 56), remove resources from the connection, or
change the list of members in a group that is used in the connection (see "Changing a
Connection by Editing Server Group Membership" on page 103).
Edit connection name and comment - Select Properties to edit the name or
comment of the connection.
Duplicate connection
Delete connection - Remove the connection and its details from the application
Note: Every connection in the application pack must have a tag associated with it so
it can be published.
• Sort the connections - You can sort the connections by these criteria: Name, Date
created, Date modified, Status, Tickets, Application, Discovered (Discovery status),
Comments. To sort the connections, select from the Sort by dropdown box and click
on the ascending or descending arrow.
• Search in the connections - You can enter one or more application connection search
terms (see "Managing Connections - Search Terms" on page 116) (not case-sensitive)
to show only the matching connections, external connections, application interface,
connections within an application interface, and connections to applications.
• Review the connection status - See if the connection is connected or blocked . This
requires View connection status permission (see "Assigning Roles to Users" on page
34). Click on the status to see a detailed analysis of the routing and firewall rules that
impact the connection. This requires Run connection status analysis permission (see
"Assigning Roles to Users" on page 34).
• Create Ticket - If you have a license for SecureChange (see "SecureChange and
SecureApp Licensing" on page 17), you can create a SecureChange ticket (see
"Implementing Connections with SecureChange" on page 117) to implement the
changes to the ticket that you made since the last time you created a SecureChange
ticket.
If you do not have a license for SecureChange, you can click View Ticket to see the
connections in an access request format. You can then export the ticket contents to a
CSV file so that you can forward the access request details to the team responsible for
implementing firewall changes.
• Handle Rejected Tickets (see "Handling Rejected Tickets" on page 126) - Click to
handle a rejected ticket.
If you already have a connection that uses similar resources to the connection you want to
build, you can duplicate the connection and change it to build the new connection.
1. In Applications, click on the application for which you are defining a connection.
4. Enter a name for the new connection. You can also add a comment to describe the
connection.
5. Click Save.
To duplicate a connection:
3. You can edit the name of the new connection. It has automatically been given a default
name; the original connection's name,"Copy" and a number.
4. Click Save
New connections are always added to the top of the list. You can use the Sort by
menu to sort the list to change the order of the connections.
Tufin Knowledge Center: [Link]/support/kc 91
Tufin™ SecureApp™ User's Guide
• Source or Destination: Drag and drop servers from the Resources panel to the
source and destination of the connection.
Note: When you type in the search box, the list is filtered by name or IP address.
You can add servers from the current application (Servers) or another application
(Applications):
Servers: Drag and drop servers that are defined for the application (see "Managing
Resources" on page 54) or the Internet object from the Servers tab.
The Internet object includes all public IP addresses except for addresses that are
defined in other SecureTrack zones. If you do not have SecureTrack zones defined
then the Internet zone is treated as ANY.
Applications: Add servers that are associated with other applications (see
"Managing External Applications" on page 104).
To allow connections which use servers from the same domain, but are from another
application, an administrator has to set the permissions by going to Settings >
SecureApp Settings and selecting Allow users to create connections with
external resources in both source and destination
• Service/Application Identities: Drag and drop from the Resources panel to the
connection's service.
Note: When you type in the search box, the list is filtered by name or port number.
1. To remove a single resource from the connection, hover over the resource in the
connection and click .
2. To remove all of the resources in a field, hover over the field box and click .
3. To remove the entire connection, click on the status icon of the connection and
click Delete connection.
After you finish editing the connection, you can create a SecureChange ticket (see "Creating
SecureChange Tickets" on page 120) to implement the changes. Also, any firewall rules that
partially match the defined connections are automatically marked in SecureTrack Policy
Browser with the name of the application and the application owner.
1. From the application, click to add a new connection for the application.
3. Enter a Name for the new connection. You can also add a Comment to describe the
connection.
4. For the Interface, click Browse and select the interface from another domain (see
"Building Interfaces to an Application" on page 106).
5. Click Save.
The connection is created with the service and server defined in the other domain. The
server is either in the Source or Destination, depending on how the interface was
configured.
6. Drag and drop from the Resources panel to the Add servers box in the new
Connection.
Add a connection to the SecureApp application right from the info dialog. All cloud instance
connections found during application discovery will be listed in the Add Connection dialog.
Procedure
To add an application connection:
1. Click on a device element in the application map. The Info window appears.
2. Click and select Add Application. The Add Connection dialog appears.
4. Click .
• Fix the connectivity to be compliant before submitting the ticket, and avoid having the
ticket rejected
• Add a note with an explanation when submitting the ticket to justify the request
Note: You need View security compliance violation (see "Assigning Roles to Users" on
page 34) permissions.
If all connections have been successfully analyzed and are compliant with all policies, a
message informing you of this appears in the top right of the window.
If there are one or more connections that are not compliant or could not be analyzed, the
RISK page opens. You can see the result for each connection. The Connection dropdown
box lists them in order of severity. Select the one that you want to view.
The connections are each listed with a square in one of these colors:
• Red: The connection violates at least one policy. A detailed report of the violation(s) is
displayed.
• Yellow: The system cannot run a compliance check on this connection. A security
compliance check cannot be run when:
Repairing Connections
After your connectivity is approved and is already running properly, there may be network
changes that suddenly break a connection or a connection interface. For example, a new
firewall rule might block a specific connection.
Note: You can revert changes made to a server, service or group. Deleting a server,
service, or group cannot be reverted.
Any other user who is an editor of the application and has the following permissions
(see "Assigning Roles to Users" on page 34) may notice the broken connection and
ask to repair it:
• View My Requests and create requests - A user with this permission can create
SecureChange tickets and follow the progress of the ticket in SecureChange >
My Requests.
• View connection status - A user with this permission can view the connection
status icon.
• At least one open ticket that requested access for this connection has been
closed.
• The connection was not edited since the last ticket that allowed it was approved.
• There are no other open tickets for the application that includes this connection
(to verify this, make sure the number of tickets in the ticket icon is zero: ).
a. In the Connectivity tab, choose one of the following depending on the connection
type:
b. In the New Request window, select the Access Request workflow and click
Create.
Accordingly, the Access Request field automatically shows the details of the
connection to be repaired.
The ticket is processed as part of the SecureChange workflow. If it is approved, the broken
connection is restored.
1. Select the server from the list of resources, click and select Replace with
group.
In the Options section, check Allow requests to join this group from the
Application Access Portal to permit users to request access to applications (see
"Self-Service Application Access" on page 68) that use this group.
Select group members – the server you replaced with this group is the group's
default member (you can click Clear remove it from the group).
• Click New Server to define a new server and add it to this group.
• To filter the list of servers you can add to the group, enter the search criteria and
click .
• To add an existing server, hover over it on the list of available servers and click
Add.
• To remove the selected servers from the group, click Clear all.
3. Click Replace to perform the replacement and create the new group of servers.
The Servers list and all connections that included this server are updated to show the
new group, with the server as its member.
4. Click Create Ticket to submit a ticket to implement the changes that result from the
new list of group members.
Note: If you allowed users to request to join this group from the Application Access Portal
(see "Self-Service Application Access" on page 68), the group icon includes a black
arrow:
• You can change a list of group members without adding or removing the group object
from the connections that use it.
• When you create a ticket, the ticket includes all firewall changes that need to be
implemented as a result.
You can also click New Server to create a new server and add it to the group.
3. Click Save.
Interconnecting Applications
When an application has connections with external application you can connect by using the
application as a resource (see "Managing External Applications" below), and also by creating
interfaces to allow other applications to connect (see "Building Interfaces to an Application"
on page 106).
You can do these tasks without even exiting the current application view:
Note: To let users create connections that use servers from other applications in both the
source and destination, the administrator must enable this permission in Settings >
SecureApp Settings: Allow users to create connections with external
resources in both source and destination
2. Next to an application's name, click to view the servers and server groups included
in the application.
d. Click Save.
Moving a Server
If for any reason you find that an existing server is in the wrong application, you can move a
server from one application to another. When you move a server, you keep the server's
original configuration and connections. You do not have to create new tickets because the
server location has no impact on the firewall rules.
• You configured servers in one application, and decide to move them to separate
applications.
• A server was found using discovery and you want to move it to another application.
• The move will put an external server on both the source and destination sides of a
connection, and the Connection Management setting has been configured to not
allow this.
Note: To let users create connections that use servers from other applications in
both the source and destination, the administrator must enable this permission
in Settings > SecureApp Settings: Allow users to create connections with
external resources in both source and destination
1. Select the server from the list of resources, click and select Move server.
2. Click on the application that you want to move the server to and click Select.
• You want to connect to servers that are associated with other applications (see
"Managing External Applications" on page 104). To allow connections which use
servers from the same domain, but are from another application, an administrator has
to set the permissions by going to Settings > SecureApp Settings and selecting
Allow users to create connections with external resources in both source and
destination
You can build an application interface that defines the connections that other application
owners must use to connect to your application. The application interface includes the
servers and services needed to connect to your application. It also shows other application
owners where they need to add their servers in order to build the necessary connections to
your application.
1. Create the application interface (see "Building an Application Interface" on page 107):
Tufin Knowledge Center: [Link]/support/kc 106
Tufin™ SecureApp™ User's Guide
b. Add interface connections to the application interface that include the servers and
services that are needed to access the application.
2. In another application create the connection to the application interface (see "Creating
a Connection to Application" on page 109):
b. Application owners add their servers to the connection to the application and open a
ticket to allow the access.
For example, all websites in your organization must connect to a database. The database
application requires that the web server connect to the database server and to a user
authentication server. As the database application owner, you can build an interface that
includes a connection to the database server with the correct services, and another
connection to the user authentication server. Now any website owner in your organization
can use the interface that you created to add the necessary connections, and the website
owner just needs to add the web servers that are used in the website.
Note: Only users that have a role (see "Assigning Roles to Users" on page 34) with the
Create and edit application interfaces permission can build, change or publish
application interfaces.
2. In the Type list, select Application interface and enter the name of the interface.
Other application owners identify the interface that they need by the name you enter
here. You can click to change the name or comment of the interface later.
3. Click Save.
Note: You are creating a connection for the interface, not connections within the
application.
After you add a server to either the Source or Destination field, Connected Servers is
added to the other side of the connection to show other application owner where to add
their servers.
Note: Every time you change the interface, you must click Publish to update the interface
for all applications that use it.
Now, any application owner with permission to view this application can create a new
connection with this application interface.
After you finish editing the connection, you can create a SecureChange ticket (see "Creating
SecureChange Tickets" on page 120) to implement the changes. Also, any firewall rules that
partially match the defined connections are automatically marked in SecureTrack Policy
Browser with the name of the application and the application owner.
• Use the application lifecycle automation feature to migrate the application (see
"Application Lifecycle Automation" below).
• Starting from the development phase, the connectivity includes most services and
network objects required by the application.
The main difference between these environments is that the same network objects need to
connect to different servers: development, testing or production. Therefore, whenever you
migrate your application to a new environment, you must reassign the IP addresses of all
network objects used in your connections. This process can be time-consuming,
cumbersome and error-prone, especially because you need to repeat it whenever you update
and remigrate your application.
Another challenge of moving between environments is to make sure you enforce the relevant
security approval process. For example: When you move from the testing environment to the
production environment, you need to use a stricter security approval process.
SecureApp helps you handle such challenges by automating the application lifecycle.
SecureApp guides you through the first migration process, and then saves your settings and
automates all subsequent remigrations.
example, this lets you duplicate the relationships between resources for application
deployment in development, testing and production environments.
Prerequisites
• The first time you migrate your application, it is important to carefully configure the
migration settings. SecureApp saves these settings, so you can easily reuse them in all
future remigrations.
• Before you migrate your application, make sure that your application meets these
migration requirements:
All application interfaces are published (so they are available to other applications).
The servers and connections you want to migrate are NOT being edited while you
perform the migration.
• When you migrate an application to a cloud platform, you must create the destination
application with all of the resources required by the new application. We recommend
that you also do this when you migrate an application to a non-cloud platform.
Procedure
To migrate your application in a new environment:
1. In the Applications list, select your application and then click to open the
migration wizard:
Summary
2. To select an application, select the Target application to which you want to copy your
connections. You can either:
Click New to define a new application (see "Building the Application Inventory" on
page 46).
3. Click Next.
4. To define the servers to create in the target application, you can either:
Select a target server manually - For each source application server, select a
server from the target application.
• To create a server group (see "Creating Servers" on page 62), select New > New
group.
• To create a single server (see "Creating Servers" on page 62), select New >
New.
Exclude servers - Select a server from the source application and select Not
Needed from the list of target servers.
• To copy a specific server, select it from the source application and select Copy >
Copy Selected.
• To copy all servers that are not already mapped to servers in the target
application, select Copy > Copy unmapped.
5. Click Next.
6. To define the external connections to create in the target application (if any):
a. Select each item from the external servers list of the source application.
• An external server - Select the external server you want to use in the target
application. You can select the same external server, or replace it with a different
external server.
7. Click Next.
8. To define the connections to application to create in the target application (if any):
a. Select an item from the source application's connection to applications list (on the
left).
Note: You cannot re-use the same interface in different connections to applications.
Map each connection to application to a different interface.
9. Click Next.
SecureApp migrates the source connectivity to the target application according to your
settings. The settings are saved and are used again (see "Remigrating an Application" below)
when you remigrate the application.
Remigrating an Application
When you migrate an application (see "Migrating an Application to a Different Environment"
on page 110), SecureApp remembers the resource mappings. After that, every time you
migrate the application you can easily re-use these mappings when you remigrate your
application.
Prerequisites
Before you remigrate your application make sure that your application meets these migration
requirements:
• All application interfaces are published so that they are available to other applications.
• The servers and connections you want to migrate are NOT being edited while you the
migration the application.
Procedure
To remigrate your application:
1. In the Applications list, select the application you want to remigrate and then click
• Provide other users with the basic process to be used when creating applications.
• Design a baseline to use for creating applications. This is useful when many
applications have a similar structure.
1. Create an application with the basic servers and connections you need. You can even
leave the server IP addresses empty. This is your template.
Note: Servers without an IP address are listed with a different icon ( ) than servers
with an IP ( ).
3. Open the new application, assign IP addresses to the servers, and configure any
changes in the new application (see "Adding Resources to Connections Manually" on
page 92).
Managing Customers
MSSPs and large enterprises commonly must control the provisioning process for many
business entities, such as customers, business partners, or departments. These are defined
as customers in SecureApp. For guidelines on how to create connections in multi-customer
mode, see Building Connections.
"text1 text2" - Shows all connections where the exact text specified is found in any of
the fields listed below (excluding the status and ticket fields)
service:<text> - Shows all connections where the service IP, service port, service
protocol, or service comment of a connection contains the specified text
source:<text> - Shows all connections where the source IP, source name, or source
comment of a connection contains the specified text
ticket:<True/False> - Shows all connections that have open or rejected tickets (true)
or do not have open or rejected tickets (false) in SecureChange, for example:
ticket:false
You can follow the progress of the tickets in SecureChange. After the tasks in the ticket are
completed, the connection status indicates that the connection is connected properly. If the
ticket is rejected, you can choose to revert the requested changes so that the SecureApp
connections match the firewall rules, or you can resubmit the changes in a new ticket and
modify the changes so that the ticket is not rejected.
• Access Request - Submit request with specified access > Business approval >
Technical design > Security review > Implementation
• Group Object Request - Submit group object change request > Approval >
Implementation
• Remove Access - Submit remove access request > Approve access removal >
Implement access removal
In SecureChange Basic, you can configure the assignments for these workflows and use
these workflows with their default configurations.
• Make workflows that match the process in your organization by customizing the
workflows and creating new ones.
Server decommissioning
Rule decommissioning
Rule recertification
To activate a workflow:
If you are logged in as a different user, click Logout from the user menu:
c. Select the step that a ticket returns to if the requester reopens it.
After all of the steps in the workflow are complete, the requester is prompted to
confirm that the request is complete. If the requester sees that the request is not
complete, the requester can reopen the ticket. The ticket then returns to the step
selected here so that the work can be redone.
d. Click OK.
b. In the Assignments tab, select the Assignment mode. For a simple workflow, select
Auto-assigned for SecureChange to automatically assign the ticket to a participant.
You can also configure conditions, based on which, the step is skipped.
5. When all steps are marked as valid, set the workflow status to Active.
6. Click Save.
SecureChange is now ready for end-users to login and submit requests. Next, you can:
• Manage requests
• Customize workflows
• Create reports
• If you create a ticket after you change the source, destination or service of a
connection, the ticket includes "Drop" access requests for the traffic that is no longer
included in the connection and "Accept" access requests for the traffic that is included
in the new connection.
• If you edit the IP address of a resource or a member of a resource group, you can save
the change and open a ticket to update the firewall rules that use the resource. The
ticket includes "Drop" access requests for the connections that use the old details of
the resource and "Accept" access requests for the same connections with the new
details of the resource.
• If you delete a connection, the ticket includes "Drop" access requests for the traffic that
was included in the connection.
Note: You can only create a ticket with a "Drop" access request if the access is not also
required by other connections in SecureApp. If you try to create a "Drop" access
request for access this is in use, SecureApp shows you the connections that use the
access.
SecureApp highlights the workflow that you selected the last time you created a
ticket.
If you do not want the ticket to go through the workflow process, you can select
Create a closed ticket. This can be useful so that:
• You have a SecureChange ticket for connections that are already configured in
the devices so that auditors can see the access request in the ticketing system.
• The next ticket created from the connection does not include any previous
changes.
Note: When you create a closed ticket, revisions that match the ticket are listed
in the Change browser in SecureChange as unauthorized because they
do not pass through an approval step in SecureChange.
The new request is shown with the details of the connections changes already entered
into the Access Request field and comments that show the actions in SecureApp that
created the access request. Click on View original request to see the connections as
they are shown in SecureApp.
To see the context of the ticket, you can click Original Application Change to see the
ticket as it was when it was submitted from SecureApp.
This can be very helpful because while viewing the technicalities of what needs to be
done in the task view, it can be difficult to understand the actual goal of the task. When
you view the SecureApp ticket you see the request as it was sent. For example, the
requester simply changed an IP address, and cannot access certain sites.
5. Click Submit.
The SecureChange request continues through the selected workflow. In SecureApp, the
application and connections have a ticket icon to show that there are open tickets for them.
You can:
• If the ticket icon is marked with a rejection , at least one of the tickets for the
connection was rejected (see "Handling Rejected Tickets" on page 126) and requires
action.
Repairing Connections
After your connectivity is approved and is already running properly, there may be network
changes that suddenly break a connection or a connection interface. For example, a new
firewall rule might block a specific connection.
Note: You can revert changes made to a server, service or group. Deleting a server,
service, or group cannot be reverted.
Any other user who is an editor of the application and has the following permissions
(see "Assigning Roles to Users" on page 34) may notice the broken connection and
ask to repair it:
• View My Requests and create requests - A user with this permission can create
SecureChange tickets and follow the progress of the ticket in SecureChange >
My Requests.
• View connection status - A user with this permission can view the connection
status icon.
• At least one open ticket that requested access for this connection has been
closed.
• The connection was not edited since the last ticket that allowed it was approved.
• There are no other open tickets for the application that includes this connection
(to verify this, make sure the number of tickets in the ticket icon is zero: ).
a. In the Connectivity tab, choose one of the following depending on the connection
type:
b. In the New Request window, select the Access Request workflow and click
Create.
Accordingly, the Access Request field automatically shows the details of the
connection to be repaired.
The ticket is processed as part of the SecureChange workflow. If it is approved, the broken
connection is restored.
• Revert the changes that were made in the connection so that the connection does not
show changes that were not implemented.
• Reapply the changes to the connection so that you can modify the changes and submit
them in the next ticket that you create.
• Ignore the rejected ticket and keep the changes in the connection even though they
were not implemented.
You can revert or reapply changes that impact the connection traffic, including added or
removed resources, group membership, and changed resource details except for the
resource name and comment. You cannot revert or reapply the changes if a resource in the
ticket was deleted, the changes were already reverted manually, or the details of a resource
in the ticket were changed after the ticket was submitted.
1. Click on and select the rejected ticket that you want to handle.
The changes that were requested in the rejected tickets are shown.
2. Review the changes that were requested in the ticket and click Reason to see the
reason for the rejection.
• Ignore rejection - Leaves the change in the connection. Because the change
was rejected and not implemented in the firewalls, the connection does not
accurately show the access allowed by the firewalls.
• Revert changes - Returns the connection to the state it was in before you
submitted the ticket.
• Reapply changes - Reapplies the changes in the ticket to the connection so you
can modify and re-submit the changes in a new ticket.
After you handle the rejected ticket, SecureApp does not notify you again of the rejected
changes from the ticket.
To integrate with Puppet you must install the Tufin SecureApp plugin from Puppet Forge on
the puppet master and configure it for each of the puppet slaves that you manage. Then, the
plugin connects to SecureApp once every 30 minutes to check for changes in the
connections that impact the iptables firewalls. If there are changes, the changes are
implemented automatically through the puppetlabs-firewall module.
1. Download the Tufin SecureApp plugin from Puppet Forge to the puppet master:
[Link]
([Link]
4. For each of the puppet slaves that you want to integrate with SecureApp, add this
class:
class {'secureapp':
secureapp_host => "ip_of_secureapp_host",
secureapp_username => "secureapp_username",
secureapp_password => "secureapp_password"
}
Where:
If you want to manually retrieve the changes from SecureApp for a specific puppet slave, run
this command on the puppet slave: puppet agent --test --debug –verbose
• See the status of the application based on if the traffic defined in the connections is
blocked
Reapply the changes to the connection so you can resubmit the ticket
Note: Connection monitoring is a feature which is currently available to all customers, but
will require a purchased license in the future.
SecureApp monitors the connection from the time the first ticket is created to request that the
connection is implemented. Here you can see:
• Each of the devices that pass the specified traffic and the rules that impact the traffic
Notes:
• To make sure that the status is as accurate as possible, update the topology
information in SecureTrack to match your network topology.
• To see the status of an application, look at the Status column for the application in the
list of applications. If any of the connections is not connected, the status of the
application shows the non-connected status.
• To see the status of a connection, look at the Status column for the connection in the
list of connections.
• When you notice heavy traffic to a particular IP address, and want to find out who owns
this server and which applications use it.
• When you add a new server to SecureApp, and need to check if this IP address
already exists.
• When you inspect specific resources, and need to find all servers that communicate
with these resources.
Server Lookup allows you to search for any server in the SecureApp system. The search
results show all of the servers that match either:
• Text in the Server Name, IP Address or Comment fields - You can also search for
exact matches (case-sensitive) of the search text to narrow the results.
• Subnet defined by IP address and netmask - You can show the servers that contain
the specified subnet, servers that are contained within the specified subnet, or servers
that match the subnet exactly.
For example:
Subnet that contains - If you enter the subnet [Link]/24, the results include
servers such as [Link]/16 and [Link]/24. If you enter the subnet
[Link]/32, the results include hosts that have the IP address [Link].
Contained in subnet - If you enter the subnet [Link]/16, the results include
servers such as [Link]/24 and hosts such as [Link]/32.
After you search for servers, you can select a server from the search results and see the
connections or groups where this server is used, either explicitly or as part of a group object.
To look up a server:
1. Go to Server Lookup:
2. In the Server Lookup view, select the Text or Subnet search and its parameters.
For Text, the parameters are: All, Server Name, IP Address and Comment
• Subnets that contain - Shows all networks that include the specified subnet,
including the subnet itself, even if it is a host.
• Contained in subnet - Shows all objects that have an IP address in the subnet,
including the subnet itself.
• Exact match - Shows only servers that match the exact specified string.
3. Click .
Tufin Knowledge Center: [Link]/support/kc 132
Tufin™ SecureApp™ User's Guide
The top pane lists all servers that match your criteria and specifies their details:
Application (a link to the application details), Name, IP Address and Comment.
5. Select a server from the search results list to view the Connectivity and Groups it is
part of in the bottom panes:
The Connectivity pane shows all the connections this server is part of (the server is
highlighted in orange). If this server is part of a group, you can click the [Info] link to
open the Group Members window and see the other servers contained in this group.
The Groups pane lists all the groups of which this server is a member. You can click
on a group to open the Group Members window and see the other servers
contained in this group.
The Connectivity Map (see "View Connectivity Map" above) lets you see a visual model of all
the connections to the application, including every cloud instance that is associated with the
application and every device that has an explicitly defined connection to the application. The
lines connecting the devices are color-coded, as follows:
• - (solid grey) The connection between the source and destination is modeled
with at least one connection defined
• - (green dashes) Some services are allowed between the source and
destination instances, but have not been modeled
• - (red dashes) Some services are blocked between the source and destination
instances, but have not been modeled
If services that are not modeled are both blocked and allowed, the connection will
display as blocked in the map
Clicking on an element in the map displays information about that element. If the element is a
device, the information displayed is the device name and the IP address. If the element is a
connection, the information displayed is the list of connections, including a color-coded line
identifying if the connection has been modeled.
Application discovery ( ) downloads the most recent log files from the cloud host,
and updates the cloud instances in the connectivity map. The discovery process looks at the
most recent 7 day history in the logs. Discovery results are removed from SecureApp after 30
days.
• Add Connection - Right-click on an edge between two cloud instances and click Add
Connection to a new connection to the application, or add a connection from the Info
window (see "Adding Connections from the Connectivity Map" on page 95).
• Zoom - Zoom in or out with the zoom controls ( ) or with your mouse wheel.
• Rearrange the map - Click and drag to navigate around the map or to move network
objects on the map.
Tufin Knowledge Center: [Link]/support/kc 135
Tufin™ SecureApp™ User's Guide
Each time you open the interactive map, the objects are distributed on the map
according to the network topology. If you have less then 1000 object on the map, you
can drag an object to lock it to a specific location until you leave the map view.
Note: The application discovery process may incur charges from your cloud services
provider for downloading the log files from the cloud host.
Application History
Every change that you make to an application is tracked in SecureApp in the History tab. The
history tab lists who did the action and when. There you can see actions such as:
• Opened ticket - When you create a SecureChange ticket for the changes since the
last ticket was created.
• Resource changed - When you change the details of a resource that is used in a
connection.
For each action, you can hover over the history entry and click on in the Changes column
to see a tabular list of the changes to resource or connection.(empty embedded topic)
Navigate here
To view the application history:
2. Click on History.
Appendix I
PATENTS
See (see [Link] - [Link] .
TRADEMARKS
Tufin, SecureChange, SecureTrack, Automatic Policy Generator, and the Tufin logo are trademarks of Tufin
Software Technologies Ltd.
All other product names mentioned herein are trademarks or registered trademarks of their respective owners.
Some TOP plugins include software developed by Terrapin Communications, Inc. and its contributors for
RANCID.