SAMURAI review
A read-only way to analyze firewall rules and network visibility on premises.
Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026
SAMURAI is Nometa’s self-hosted platform for teams managing policies across multiple firewall vendors and surrounding network infrastructure. Its Policy Analyzer calculates effective permitted traffic, resolves objects and NAT, and identifies shadowed, redundant, or overly broad rules. Mid-market and enterprise teams that need policy visibility without granting write access may find that scope useful, particularly in offline or air-gapped environments.
Policy analysis is the clearest strength: rules are scored by exposure, and normalized policy views help teams examine configurations across supported platforms. SAMURAI also reads firewall configurations and tracks changes, with a searchable dashboard covering firewalls and nearby network infrastructure. Integrations include Palo Alto Networks, Cisco FTD, FortiGate, Juniper SRX, Cisco ACI, Cisco FMC, Cisco ASA, and Cisco routers and switches. This breadth suits mixed-vendor environments; teams seeking policy simulation or automated remediation will need another approach.
Deployment is on premises through a Docker container on the customer’s VM, supporting offline and air-gapped use. Device access is read-only, so SAMURAI does not push configuration changes; that boundary may suit monitoring but limits it as a policy-change workflow tool. According to the vendor’s pricing description, production licensing is per deployment and sized by device count, with pricing handled through sales. The vendor also describes a free test license, but it should not be treated as an ongoing free plan. Choose SAMURAI for cross-vendor analysis and change visibility in controlled environments; consider alternatives if write access, simulation, or change automation is central to your requirements.
SAMURAI pros and cons
- Where it wins
- Calculates effective traffic with objects and NAT resolved
- Flags shadowed, redundant, and overly broad firewall rules
- Runs in a self-hosted Docker container for air-gapped environments
- Where it doesn't
- Read-only access means it cannot push configuration changes
- No policy simulation or change automation
- Production licensing is per deployment and sized by device count
SAMURAI fact sheet, pricing and score →
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.
Last updated · How we research and update