Inventory, topology, compliance, CVE

Know exactly what is on your network.

NacTrack reads your devices over SSH and rebuilds your inventory, topology, compliance and CVE exposure. On your own infrastructure, with no agent to install.

  • Read only SSH, no agent
  • Multi vendor, no partnership required
  • No data leaves the site
app.nactrack.com/neighbors/topology/multi
NacTrack topology built from the CDP and LLDP neighbours the devices report
The estate you already have

Collected from these platforms, with no agent

A read only SSH session, the commands each platform understands, and nothing installed on your devices.

  • Cisco
  • Huawei
  • Juniper
  • Aruba
  • Arista
  • Nokia
  • Dell
  • Fortinet
  • F5
  • Palo Alto Networks
  • Infoblox
  • Forcepoint
Protocols

What NacTrack reads on your devices

Seven families, read over SSH on every platform. The detail, including what is read without deep analysis, is published.

Discovery and adjacency

CDP, LLDP, ARP, MAC tables

Switching

STP, RSTP, MSTP, LACP, VLAN, QinQ

Routing

OSPF, OSPFv3, IS-IS, BGP, EIGRP, VRF, BFD

Transport

MPLS, LDP, L2VPN, VPLS, EVPN

Gateway redundancy

VRRP, HSRP, GLBP

Access control

802.1X, MAB, TACACS, RADIUS, TrustSec

Management plane

SSH, Telnet, SNMP, NTP, DHCP

The cycle

It is not an installation, it is a lap that starts again

The four stages below repeat on every collection. It is the repetition that keeps the inventory current, not the first run.

Four stage collection cycle: connect, read, keep and correlate, answerFour stages arranged in a ring, walked in order and repeated on every collection, scheduled or started by you. Connect over SSH, read only. Read, using the vendor's own commands. Keep and correlate, which produces the history and the topology. Answer, from the state of the last collection.Every collectionscheduled, or started by youAnd againthe inventory is only currentbecause this happens againConnectSSH, read onlyReadthe vendor's own commandsKeep and correlatehistory and topologyAnswerfrom the last collection

Every collection scheduled, or started by you

  1. ConnectSSH, read only. Your credentials, the same access an operations engineer has. Nothing is written to the device.
  2. Readthe vendor's own commands. What IOS shows with one command reads differently on VRP or Junos.
  3. Keep and correlatehistory and topology. MAC tables, ARP tables, reported neighbours and configurations cross reference each other. Topology comes out of that crossing.
  4. Answerfrom the last collection. An answer always comes from the last collection, never from the live device, and the collection date travels with the data.

An answer always comes from the last collection, never from the device live. The detail of each stage is directly below.

Product tour

Product tour

app.nactrack.com/
NacTrack dashboard: models, software distribution and last reboots
Dashboard. Model breakdown, software versions in service, devices rebooted recently.
app.nactrack.com/devices
Device list: vendor, model, software version, site and lifecycle
Inventory. One estate, four vendors in ten rows, with the model, the software version read from the device, and the lifecycle.
app.nactrack.com/neighbors/topology/multi
Topology built from reported CDP and LLDP neighbours
Topology. Built from the CDP and LLDP neighbours the devices report themselves.
app.nactrack.com/ip/usage
IP, MAC and DHCP search down to the access port, with the VLAN
IPAM. An IP or MAC address, and the access port it was seen on, with its VLAN.
app.nactrack.com/diff/config
Two configurations compared side by side, changed lines highlighted
Config diff. Two collections side by side: lines added, removed and changed, with dates.
app.nactrack.com/neighbors/topology/multi
Spanning tree overlay on the topology: crowned root bridge and blocked links
Spanning tree. The spanning tree overlay on the topology: root bridge, blocking ports, PVST+, RSTP and MST instances.
app.nactrack.com/compliance/report
Compliance score per device, with the failing rules listed
Compliance. Score per device, rule by rule, with the configuration extract that triggers each failure.
app.nactrack.com/compliance/vulnerabilities
CVE findings matched against the versions read from the estate
Vulnerabilities. CVEs matched version by version, with exposure per device and what is actively exploited.
app.nactrack.com/eol
Hardware lifecycle: end of sale, end of support
End of life. Hardware lifecycle, kept by hand in a catalogue rather than inferred from the model name.
app.nactrack.com/reporting
The catalogue of available reports, with their scope
Reporting. The reports a committee or an auditor asks for, produced from the estate's real state.
app.nactrack.com/customers
The connected customer register, with product family and circuits
Operator customers. For an operator: the connected customers, their product family and their circuits, built from the network.
The difference that matters

Your configurations never leave the building

A network configuration holds the addressing plan, site names, SNMP communities, filtering rules and sometimes secrets. It is the map of the house.

NacTrack installs on your hardware, in your room. Your configurations, your inventory and your results never leave the building.

  • Appliance on your hardware, LUKS2 encrypted disk
  • Your data never leaves
  • No outbound telemetry by default
  • Strict isolation between tenants
  • Support access opened by you, when you decide
Frequent questions

What we get asked before the first meeting

Do you need internet access?

No for your data: it does not leave. The vulnerability catalogue and updates can transfer by file. One flow is needed over time, licence validation: without it the installation moves to read only after a long window rather than stopping.

What does the vendor see of our data?

Nothing, unless you open support access yourself, which you then close. There is no automatic upload of configurations, inventory or results.

What if our estate is out of date?

That is the most common case, and it is exactly what the first collection reveals. An estate moves faster than its documentation, everywhere.

Does NacTrack replace our monitoring?

No, and it should not be bought for that. NacTrack tells you what the network is, whether it is compliant and what it is exposed to. It does not tell you whether a device is answering right now, or how loaded it is. Those are different questions, and you need the answers to both.

How long until the first answer?

Between a minute and a half and three minutes per device when the device answers normally, and devices are collected in parallel: a hundred of them is then a matter of tens of minutes. The pace belongs to your network and your devices, not to us: on sensitive equipment, or during load hours, the collection is deliberately slowed and scheduled outside them. The real constraint is usually neither: it is getting read access approved.

After commissioning

What happens once it is installed

The part that is hardest to judge before buying, and the part that decides everything afterwards.

Corrected by the people who run it

NacTrack is built and exercised by field engineers, on real estates that are in production. The support flow that raises your incidents raises theirs too, and that is where the fixes come from: a device no specification anticipated, a ticket carrying what the device actually answers, then a release.

Support sees what you see

Incidents are raised from the installation itself, with the technical context already attached. You do not have to describe a problem the machine can describe better than you.

Remote access is closed by default

No permanent access and nothing dormant. When an intervention is needed you open it, for the duration, and you close it again.

You choose when you move version

Two channels: one stable, one ahead for those who want to see what is coming. You decide which you are on, and an update is triggered from your side.

Nothing needs the internet

Your data does not leave, and that is the only absolute promise here. The licence does have to reach our service from time to time: without it the installation moves to read only after a long window rather than stopping dead, and it is also the path security fixes arrive by.

See the product before you decide

The demonstration is read only, on a fictional estate. The account is requested through a form and arrives by email, on that estate or on a space prepared around your own questions.