# SAMURAI · Network Monitoring & Security Platform

> Self-hosted network monitoring and security platform that unifies Cisco APIC, NDO, FMC, ISE, Palo Alto, Fortinet FortiGate, Juniper SRX, VMware vCenter, routers, and switches into one dashboard. No agents, no SNMP polling.

SAMURAI reads native vendor APIs and SSH the way an engineer would, then correlates the whole estate in a single command surface.

## What it does
- **Endpoint discovery**: correlates endpoints across the estate from MAC tables, ARP, DHCP snooping, CDP/LLDP, 802.1X, and an offline IEEE OUI database. No CMDB required.
- **Path tracing**: hop-by-hop traffic path simulation across firewalls, routers, switches, and ACI fabrics, including reverse-path tracing.
- **Change detection**: snapshot-based configuration diffs with volatile-field filtering, attributed to the admin who made each change.
- **Firewall & policy analysis**: security policies, NAT, decryption policies, objects (resolved recursively to real protocols/ports), and VPNs across Palo Alto (PAN-OS), FortiGate (FortiOS), Cisco FMC/FTD, and Juniper SRX (Junos OS). The Policy Analyzer computes effective access, flags rule hygiene issues (shadowed, redundant, overly-broad), and scores per-rule risk in one canonical policy view across Palo Alto, Cisco FTD, FortiGate, Juniper SRX, and ACI.
- **Monitoring**: HTTPS/TCP health checks with per-device latency, a Prometheus metrics endpoint, and RFC5424 syslog forwarding.
- **Compliance**: 140+ automated CIS checks for Cisco IOS-XE, NX-OS, IOS-XR, and ASA, with scoring, waivers, and remediation tracking.
- **Cisco ISE**: TrustSec and network access device visibility alongside the rest of the estate.
- **VMware vCenter**: datacenters, clusters, hosts, VMs, and networks.

It is a configuration and state analyzer, not a traffic-log analyzer.

## Deployment
One self-contained container; a typical deployment serves data in about five minutes via a single docker run. Self-hosted only, air-gap friendly (offline OUI database, no telemetry). A free test license is on the Docker Hub page, no email required.

---

Canonical page: https://nometa.az/en/
Part of SAMURAI, a self-hosted, multi-vendor network monitoring & security platform. Overview: https://nometa.az/llms.txt
Contact: info@nometa.az · Docker Hub: https://hub.docker.com/r/beyrak44/samurai
