> Source: https://docs.nometa.az/v4.8.0/introduction

# SAMURAI Networks

**Network security monitoring and management, in one platform.** A single pane of glass
for multi-vendor network and security infrastructure. SAMURAI Networks continuously syncs
configuration and state from your devices, discovers endpoints, traces traffic paths,
analyzes firewall policy, detects changes, and scores compliance.

![Dashboard](https://docs.nometa.az/img/01-overview/dashboard.webp)

## How it works

SAMURAI Networks is **agentless and read-only**. It connects outbound to each platform's
management API or SSH interface with a least-privilege account, syncs configuration and
state on a schedule, and keeps versioned snapshots so every change can be diffed over
time. It never pushes configuration to a device. The entire platform ships as one Docker
container; see [Deployment](https://docs.nometa.az/md/v4.8.0/deployment.md) and
[Device Onboarding](https://docs.nometa.az/md/v4.8.0/device-onboarding.md).

## Supported platforms

| Category | Platforms |
| --- | --- |
| Cisco data center | ACI (APIC), Nexus Dashboard Orchestrator (NDO) |
| Cisco security | FMC, FTD/ASA, ISE |
| Firewalls | Palo Alto, Fortinet FortiGate, Juniper SRX |
| Virtualization | VMware vCenter |
| Identity | Microsoft Active Directory (LDAP) |
| Network | Routers & switches (IOS / IOS-XE / NX-OS / IOS-XR / Junos) via SSH; VyOS via HTTPS API or SSH |

## What you can do

- **Discover endpoints** across switches, routers, and controllers: MAC to IP to identity.
- **Trace traffic** hop by hop with policy, zone, and NAT awareness.
- **Detect changes** with a unified timeline and per-vendor change attribution.
- **Analyze firewall policy** across vendors: per-rule risk, shadowed and redundant rules, zone segregation, and cleanup recommendations.
- **Score compliance** against security benchmarks, per device and fleet-wide.
- **Visualize topology** of the network and data center fabric.
- **Explain changes with AI** using your own model: local Ollama, any OpenAI-compatible endpoint, Claude, or Amazon Bedrock.

## How SAMURAI Networks compares

SAMURAI Networks overlaps with network security policy management (NSPM) tools like AlgoSec
and Tufin on visibility, path analysis, policy analysis, change tracking, and compliance.
The difference is scope. AlgoSec and Tufin are firewall-policy platforms built around
change orchestration (pushing rule changes through approval workflows); SAMURAI Networks is
a broader multi-vendor visibility layer that also covers endpoints, identity, and
virtualization, includes a multi-vendor
[Policy Analyzer](https://docs.nometa.az/md/v4.8.0/features/policy-analyzer.md) (rule risk, anomalies, segregation
baselines, compliance packs), and deploys as a single container.

| Capability | SAMURAI Networks | AlgoSec | Tufin |
| --- | --- | --- | --- |
| Multi-vendor firewall visibility | Yes | Yes | Yes |
| Traffic-path tracing (policy, zone, NAT) | Yes | Yes | Yes |
| Topology mapping | Yes | Yes | Yes |
| Change-detection timeline | Yes | Yes | Yes |
| Compliance scoring | Yes | Yes | Yes |
| Firewall rule risk, shadowing and cleanup analysis | Yes | Yes | Yes |
| Endpoint and identity discovery (MAC to IP to identity, ISE/AD) | Yes | No | No |
| Virtualization (VMware vCenter) visibility | Yes | No | No |
| Policy change automation and push (approval workflow) | No | Yes | Yes |
| Deployment | Single Docker container | Enterprise suite (appliance/VM) | Enterprise suite (appliance/VM) |

AlgoSec and Tufin remain the stronger choice when automated firewall change orchestration
is the goal. This summary reflects each product's primary focus; vendor capabilities change
over time. For how SAMURAI relates to log-centric tools like ManageEngine Firewall
Analyzer, see the [Firewall Analyzer](https://docs.nometa.az/md/v4.8.0/firewall-analyzer.md) overview.

Continue to [Getting Started](https://docs.nometa.az/md/v4.8.0/getting-started.md) to deploy and sign in.
