# Self-Hosted Firewall Management (Multi-Vendor)

> Self-hosted, multi-vendor firewall management for Palo Alto, FortiGate, Cisco FMC/FTD, and Juniper SRX: analyze policies, NAT, objects, VPNs, and changes on your own VM. No SaaS, no telemetry, air-gap friendly.

Last updated: July 2026

SAMURAI is self-hosted, multi-vendor firewall management software that runs entirely on your own VM. No cloud tenant, no telemetry, no data leaving your network.

- **Your config never leaves your network**: policies, objects, and credentials stay on your VM; nothing is sent to a vendor for processing.
- **No telemetry**: no usage analytics, no license heartbeat. The only outbound traffic is to the devices you register.
- **Air-gap friendly**: runs fully offline with an embedded IEEE OUI database.
- **One Docker container** on a single VM; read-only by design, so it never pushes configuration.
- **Multi-vendor**: Palo Alto, FortiGate, Cisco FMC/FTD/ASA, and Juniper SRX in one dashboard, next to routers, switches, ACI fabrics, ISE, and vCenter.

## Self-hosted vs SaaS policy tools

| | SAMURAI (self-hosted) | SaaS policy tools |
|---|---|---|
| Where your config lives | On your VM, inside your perimeter | Ingested into the vendor cloud |
| Telemetry | None: nothing phones home | Usage and license telemetry by default |
| Air-gapped networks | Fully supported, offline by design | Usually unsupported, needs cloud connectivity |
| Deployment | One Docker container, minutes to first dashboard | Cloud tenant onboarding or appliance rollout |

## Frequently asked questions

### What is self-hosted firewall management?

Self-hosted firewall management runs the management and analysis software on infrastructure you control, rather than in a vendor cloud. Your firewall configuration, objects, and credentials never leave your network. SAMURAI is self-hosted by design: one Docker container on your own VM, no cloud tenant, no telemetry.

### Does any data leave my network?

No. SAMURAI is fully self-hosted with no telemetry and no license heartbeat. It reads from your devices over native APIs and SSH, stores everything locally, and makes no outbound calls except to the devices you register.

### Is it an on-premise AlgoSec or Tufin alternative?

For multi-vendor visibility, effective-access and rule-hygiene analysis, and change attribution, yes, and it runs entirely on your own infrastructure. For cloud-based rule-recertification and provisioning workflows, the incumbents remain the specialists.

### How is it deployed and licensed?

A single docker run on one VM; a typical deployment serves data in about five minutes. A free test license ships with the Docker image, no email required; production is licensed per deployment, sized by device count.

---

Canonical page: https://nometa.az/en/self-hosted-firewall-management/
Part of SAMURAI, a self-hosted, multi-vendor network monitoring & security platform. Overview: https://nometa.az/llms.txt
Contact: info@nometa.az · Docker Hub: https://hub.docker.com/r/beyrak44/samurai
