See what we parse, and what we only record
Seven families, grouped the way a network engineer thinks about them. The third column says what the data is used for, not that a box was ticked.
- An estate is not read protocol by protocol, it is read by function. So the table below groups protocols by the role they play, not alphabetically.
- Seven families, 35 entries. Some feed the topology, the compliance checks and the reports. Others are simply recognised: a mode or a configuration line is enough to answer the question being asked.
- The difference is written in the third column, including where it is not flattering.
What is read, by family
The third column says what is done with the data, not merely that it is recognised.
| Family | Protocols | What NacTrack does with it |
|---|---|---|
| Discovery and adjacency | CDPLLDPARPIPv6 NDPMAC tables | Reported neighbours, IPv4 and IPv6 addressing and MAC tables are cross referenced to draw the topology. IPv6 neighbours are read on Cisco, Huawei and Dell. A neighbour a device announces but that is missing from the inventory stays visible as such, rather than being dropped from the diagram. |
| Switching | STPRSTPMSTPLACPVLANQinQ | Spanning tree is read on Cisco and Huawei platforms: root, cost, blocking ports. Link aggregates are rebuilt from their members, so the topology does not draw one link per member. RSTP and MSTP are identified as a mode, with no per instance analysis. |
| Routing | OSPFOSPFv3IS-ISBGPEIGRPVRFBFD | Adjacencies, advertised prefixes and VRF membership are read device by device, then brought together to follow a path end to end. VRF is the most developed dimension of the model: almost everything routed is attached to its own. OSPFv3 is read less deeply than OSPFv2. |
| Transport | MPLSLDPL2VPNVPLSEVPNVXLAN | LDP sessions, pseudowires, VPLS instances and their attachment points, EVPN families: transport services are rebuilt and tied to the customer they carry. Pseudowires and VPLS are limited to the platforms that genuinely carry those services, namely Cisco IOS, IOS XE, IOS XR and Huawei. EVPN and VXLAN are read more widely, including on NX-OS, Dell and Aruba. |
| Gateway redundancy | VRRPHSRPGLBP | Groups and their virtual address are read from the configuration, which ties a subnet's gateway to real devices. That is a declared state, not the outcome of an election watched live. GLBP is recognised, without detail. |
| Access control | 802.1XMABTACACSRADIUSTrustSec | Port authentication is read from the configuration, including where it hides behind an interface template and so does not appear on the interface itself, then matched with the sessions read from Cisco ISE. TrustSec is recognised, with no SGT matrix analysis. |
| Management plane | SSHTelnetSNMPNTPDHCP | SSH is the collection method itself. Telnet, SNMP, NTP and DHCP relays are read from the configuration and evaluated as hardening points. NacTrack does not poll SNMP and measures no traffic: it reports what is configured. |
A protocol absent from this table is not read. The list comes from the parsers that actually ship, not from a marketing catalogue: it moves with every release, and the release installed on your site is the one that counts. If a protocol you need is missing, ask, and the answer will be yes or no rather than soon.
Check it against your own estate
Coverage by platform
The same exercise, vendor by vendor: seventeen platforms, with the empty cells published.
›How the collection works
The whole path, from the SSH session through to the answer, with the diagram.
›L2VPN and transport
The most developed family in the model, seen from the screen rather than from the table.
›Is a protocol missing from the list?
Send us what you run. We answer with what is read today, and what is not.
