SAMURAI Networks
Network security monitoring and management, in one platform. A single pane of glass for multi-vendor network and security infrastructure. SAMURAI Networks continuously syncs configuration and state from your devices, discovers endpoints, traces traffic paths, analyzes firewall policy, detects changes, and scores compliance.

How it works
SAMURAI Networks is agentless and read-only. It connects outbound to each platform’s management API or SSH interface with a least-privilege account, syncs configuration and state on a schedule, and keeps versioned snapshots so every change can be diffed over time. It never pushes configuration to a device. The entire platform ships as one Docker container; see Deployment and Device Onboarding.
Supported platforms
| Category | Platforms |
|---|---|
| Cisco data center | ACI (APIC), Nexus Dashboard Orchestrator (NDO) |
| Cisco security | FMC, FTD/ASA, ISE |
| Firewalls | Palo Alto, Fortinet FortiGate, Juniper SRX |
| Virtualization | VMware vCenter |
| Identity | Microsoft Active Directory (LDAP) |
| Network | Routers & switches (IOS / IOS-XE / NX-OS / IOS-XR / Junos) via SSH; VyOS via HTTPS API or SSH |
What you can do
- Discover endpoints across switches, routers, and controllers: MAC to IP to identity.
- Trace traffic hop by hop with policy, zone, and NAT awareness.
- Detect changes with a unified timeline and per-vendor change attribution.
- Analyze firewall policy across vendors: per-rule risk, shadowed and redundant rules, zone segregation, and cleanup recommendations.
- Score compliance against security benchmarks, per device and fleet-wide.
- Visualize topology of the network and data center fabric.
- Explain changes with AI using your own model: local Ollama, any OpenAI-compatible endpoint, Claude, or Amazon Bedrock.
How SAMURAI Networks compares
SAMURAI Networks overlaps with network security policy management (NSPM) tools like AlgoSec and Tufin on visibility, path analysis, policy analysis, change tracking, and compliance. The difference is scope. AlgoSec and Tufin are firewall-policy platforms built around change orchestration (pushing rule changes through approval workflows); SAMURAI Networks is a broader multi-vendor visibility layer that also covers endpoints, identity, and virtualization, includes a multi-vendor Policy Analyzer (rule risk, anomalies, segregation baselines, compliance packs), and deploys as a single container.
| Capability | SAMURAI Networks | AlgoSec | Tufin |
|---|---|---|---|
| Multi-vendor firewall visibility | Yes | Yes | Yes |
| Traffic-path tracing (policy, zone, NAT) | Yes | Yes | Yes |
| Topology mapping | Yes | Yes | Yes |
| Change-detection timeline | Yes | Yes | Yes |
| Compliance scoring | Yes | Yes | Yes |
| Firewall rule risk, shadowing and cleanup analysis | Yes | Yes | Yes |
| Endpoint and identity discovery (MAC to IP to identity, ISE/AD) | Yes | No | No |
| Virtualization (VMware vCenter) visibility | Yes | No | No |
| Policy change automation and push (approval workflow) | No | Yes | Yes |
| Deployment | Single Docker container | Enterprise suite (appliance/VM) | Enterprise suite (appliance/VM) |
AlgoSec and Tufin remain the stronger choice when automated firewall change orchestration is the goal. This summary reflects each product’s primary focus; vendor capabilities change over time. For how SAMURAI relates to log-centric tools like ManageEngine Firewall Analyzer, see the Firewall Analyzer overview.
Continue to Getting Started to deploy and sign in.