// SELF-HOSTED FIREWALL MANAGEMENT

Firewall management that never leaves your perimeter.

SAMURAI is self-hosted, multi-vendor firewall management software: it reads security policies, NAT, objects, VPNs, and configuration changes across Palo Alto, FortiGate, Cisco FMC/FTD, and Juniper SRX, and runs entirely on your own VM. No cloud tenant, no telemetry, no data leaving your network. For teams who cannot or will not send firewall configuration to a vendor SaaS, it delivers the visibility and change tracking of a policy suite without the cloud dependency.

Updated July 2026

What self-hosted buys you

Your config never leaves your network

Policies, objects, and credentials stay on your VM. No cloud tenant ingests your rule base, and nothing is sent to a vendor for processing.

No telemetry, ever

SAMURAI phones home for nothing: no usage analytics, no license heartbeat, no crash reporting. The only traffic it makes is to the devices you point it at.

Air-gap friendly

Runs fully offline with an embedded IEEE OUI database and no external calls, so it deploys in air-gapped and restricted networks the same way it deploys anywhere else.

One Docker container

The whole platform is one self-contained container on a single VM. No Kubernetes, no managed service, no per-seat cloud subscription.

Multi-vendor in one place

Palo Alto, FortiGate, Cisco FMC/FTD/ASA, and Juniper SRX policies in a single searchable dashboard, next to the routers, switches, ACI fabrics, ISE, and vCenter around them.

Read-only by design

Show commands over SSH and read calls on vendor APIs. SAMURAI observes and reports; it never pushes configuration, so it can never break your network.

Self-hosted vs SaaS policy tools

Most firewall policy suites are moving to the cloud. That is fine until your security team asks where the configuration goes, or your environment has no internet at all. SAMURAI is built for the other answer.

Where your config lives

SAMURAI (self-hosted)

On your VM, inside your perimeter

SaaS policy tools

Ingested into the vendor cloud

Telemetry

SAMURAI (self-hosted)

None: nothing phones home

SaaS policy tools

Usage and license telemetry by default

Air-gapped networks

SAMURAI (self-hosted)

Fully supported, offline by design

SaaS policy tools

Usually unsupported, needs cloud connectivity

Deployment

SAMURAI (self-hosted)

One Docker container, minutes to first dashboard

SaaS policy tools

Cloud tenant onboarding or appliance rollout

If a cloud-managed policy suite fits your risk model, it may be the easier path. If your firewall configuration cannot leave your network, self-hosting is not a preference, it is a requirement, and that is what SAMURAI is built for.

Frequently asked questions

What is self-hosted firewall management?

Self-hosted firewall management runs the management and analysis software on infrastructure you control, rather than in a vendor cloud. Your firewall configuration, objects, and credentials never leave your network. SAMURAI is self-hosted by design: one Docker container on your own VM, no cloud tenant, no telemetry.

Does any data leave my network?

No. SAMURAI is fully self-hosted with no telemetry and no license heartbeat. It reads from your devices over their native APIs and SSH, stores everything locally, and makes no outbound calls except to the devices you register.

Can it run without internet access?

Yes. It ships with an embedded IEEE OUI database and needs no external services, so it runs fully air-gapped. See the air-gapped network security page for the details.

Which firewalls does it manage?

It reads Palo Alto (PAN-OS), FortiGate (FortiOS), Cisco FMC/FTD and ASA, and Juniper SRX (Junos OS), plus ACL visibility on Cisco routers, switches, and ACI fabrics. Management here means read, search, analyze, and track changes: SAMURAI is read-only and does not push configuration.

Is it an on-premise AlgoSec or Tufin alternative?

For multi-vendor visibility, effective-access and rule-hygiene analysis, and change attribution, yes, and it runs entirely on your own infrastructure. For cloud-based rule-recertification and provisioning workflows, the incumbents remain the specialists.

How is it deployed and licensed?

A single docker run on one VM; a typical deployment serves data in about five minutes. A free test license ships with the Docker image, no email required; production is licensed per deployment, sized by device count.

Firewall management, entirely on your terms.

Request a demoExplore the platform