Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Tufin integrator in Switzerland

We deploy the Tufin Orchestration Suite to keep the filtering policy of a heterogeneous estate under control — visibility, compliance and change request automation.

Why this vendor

A firewall estate ages badly. A rule is added for a project, the project stops, the rule stays. Ten years later the base holds several thousand entries and nobody knows which ones still serve a purpose. Deleting them is risky, keeping them is too, and the subject stays at the bottom of the list until an audit brings it back up.

Tufin attacks the problem through modelling. The platform reads the configurations of several vendors — firewalls of different makes, routers, cloud security groups — and builds one map from them. What becomes possible then is asking a question in business terms: can this server reach that one, and by which path. The answer accounts for every device crossed, which no manufacturer's console can do.

The contribution network teams notice fastest lies elsewhere, in handling change requests. A request to open a flow usually passes through several people, several weeks and a degree of guesswork about which devices are involved. The platform computes the path, proposes the exact rule, checks that it breaks no internal policy, and implements it.

Our contribution is defining what compliance means at your organisation. The platform applies the rules it is given; it does not decide which flows are forbidden, nor which zones must never talk to each other. That matrix is written with your network and security teams, and it is what gives the tool its value.

Tufin
What we bring
  • Writing the matrix of authorised flows
  • Gradual cleanup of inherited rules
  • Automation of change requests
  • A unified view over a multi-vendor estate
  • Compliance evidence produced continuously
Vendor website
Diagram

Three tiers, one platform

Tufin Orchestration Suite: heterogeneous estate, three tiers and compliance evidence BaseTiersOutcome00Heterogeneous estateFortinet, Palo Alto Networks, routers, public cloudT1SecureTrack+Visibility, compliance and rule cleanupT2SecureChange+Automation of change requestsT3EnterpriseZero Trust at scale, across the estate04Compliance evidenceDrift detected continuously, dated history
The tiers add up rather than replace one another: each assumes what the previous one has put in place.

The tiers we integrate

The vendor sells three tiers of one suite, not three separate products. Each assumes what the previous one brings.

Visibility and compliance

SecureTrack+ reads the estate's configurations and builds one map from them. It flags rules never used, rules that overlap, rules that breach your internal policies. It is the tier that finally allows an inherited rule base to be cleaned, relying on observed usage rather than on the memory of the team.

SecureTrack+

Change automation

SecureChange+ handles flow opening requests end to end: computing the network path, proposing the exact rule on the right devices, checking compliance automatically, then implementing it. The gain is measured in weeks on requests that used to take several, and the number of useless rules created out of caution drops.

SecureChange+

Scaling up

Enterprise is the tier for the largest estates, where policy is designed by zones and intent rather than rule by rule. It is also what makes a Zero Trust approach workable on an existing network: segmenting assumes a reliable model of what talks to what, without which the project stays theoretical.

Enterprise
The platform

The Tufin Orchestration Suite does not replace your firewalls: it administers them together. That is what makes it relevant on a heterogeneous estate, where each manufacturer's console sees only its own devices and nobody can answer the one question that matters — does this flow pass, and by which route.

Tufin Orchestration Suite
Our approach

How we proceed

No rule is deleted before we know what it carries. Cleanup comes after observation, never before.

Tufin integration approach, from rule inventory to operations ScopingImplementationDuration01Ruleinventory02Flowmatrix03Gradualcleanup04Automaterequests05ContinuouscontrolOperationsor handover
The flow matrix precedes automation: automating requests without knowing what is forbidden mostly accelerates the mistakes.
Frequently asked questions

Frequently asked questions

Yes, provided you proceed by observation rather than deduction. The platform measures the real usage of each rule over time; those that have carried nothing for months are first disabled, then deleted if nobody speaks up. It is slow, and that is what makes it safe.

That is precisely the use case: administering devices from different manufacturers together, on-premises as well as in the cloud. We verify the coverage of your estate during scoping — the models, the versions, and the cloud environments concerned — before committing to a scope.

Rarely. Most organisations draw the bulk of the value from the first tier, because visibility and cleanup are the most pressing needs. Automation comes when the volume of requests justifies it, and the upper tier when policy is designed by zones rather than rule by rule.

Yes, and it is a frequent use. The platform keeps a dated history of changes and continuously flags drift from the compliance matrix. An ISO 27001 auditor does not ask for a screenshot: they ask who approved what, when, and how the gaps are handled.

Thousands of rules, and nobody knows

Describe your estate — an inventory of the rules actually in use is the first deliverable.