Skip to Content

Device Onboarding

Each platform connects over its native API or SSH with a read-only / least-privilege account. SAMURAI never makes configuration changes; it polls and reads. SSH device commands are restricted to show.

PlatformConnectionAccount
Cisco ACI (APIC)HTTPS APIRead-only admin
Nexus Dashboard OrchestratorHTTPS APIRead-only
Cisco FMCHTTPS APIRead-only API user
Cisco FTD / ASASSH (CLISH)Read-only
Cisco ISEERS / OpenAPIRead-only ERS admin
Palo AltoXML APIRead-only
FortiGateREST APIRead-only
VMware vCentervSphere APIRead-only
Active DirectoryLDAPBind account (paged read)
Routers / SwitchesSSHPrivileged show access

After adding a device, SAMURAI runs an initial sync and then re-syncs on a schedule (configurable in Settings). For what each platform exposes once connected, see the per-vendor Device Panels.

Credentials are stored encrypted at rest (AES-256-GCM) and used read-only. Grant the account only the access listed above; SAMURAI never needs write or configuration rights.

Last updated on