On-prem · Real-time · Multi-vendor

One console for your entire
network fabric.

NOVA NETWORK unifies switch management, SNMP & API monitoring, live traffic analytics, topology, endpoint correlation and alerting into a single self-hosted platform — with signed licensing and defense-grade security built in.

SNMP v1 / v2c / v3 SSH multi-vendor sFlow · NetFlow · IPFIX Syslog RFC 3164/5424 Ed25519 signed licensing
10+
Switch vendor drivers
15+
SNMP device types
2s
Live telemetry tick
100%
On-premise, your data
Monitoring & Telemetry

See everything, from the port to the packet

Poll it, sniff it, or call its API — NOVA collects switch, device, endpoint and flow telemetry in real time and renders it in one place.

Switch monitoring over SSH

Live per-port status, throughput and error counters, PoE budget, QoS/VoIP policy and running-config — collected over SSH with a warm connection pool that tolerates legacy gear.

  • Port stats
  • PoE
  • QoS
  • Reachability

SNMP device monitoring

Poll UPS, PDUs, sensors and servers with SNMP v1/v2c and secure v3 (auth+priv). Declarative profiles map OIDs to metrics, enums and thresholds — hot-reconfigurable.

  • v3 auth/priv
  • 15+ types
  • Profiles
  • 30s poll

API monitors

Monitor any REST API as if it were a device. Any method, any auth (bearer, basic, API-key, login), extract fields by JSON path, and get the same gauges, sparklines and edge-triggered alerts.

  • REST / JSON
  • Bearer · Basic
  • 10s poll
  • Encrypted creds

Live traffic analytics

Built-in sFlow v5 and NetFlow v5/v9 + IPFIX collectors decode flows into top applications, top talkers, protocol mix and east-west vs. internet locality — updated every two seconds.

  • sFlow 6343
  • NetFlow 2055
  • Top talkers
  • App classify

Health & environment

CPU, memory, temperature, fans, PSUs and uptime roll up into an explainable 0–100 fleet-health score with per-factor deductions — missing data never counts against you.

  • 0–100 score
  • Environment
  • Explainable

Endpoint correlation

Every end device on one row: MAC → IP → vendor (OUI) → switch/port/VLAN → 802.1X session → LLDP identity → live traffic → port syslog. Pure correlation, no extra agents.

  • ARP · MAC table
  • 802.1X
  • OUI vendor
  • LLDP
Device Management

Manage the fabric, don't just watch it

Multi-vendor CLI drivers, guarded configuration changes, versioned backups and a real SSH terminal — with honest "unsupported" instead of guesswork.

Multi-vendor drivers

Vendor-aware CLI command sets and parsers for Cisco IOS/IOS-XE, Ruckus ICX/FastIron, Aruba CX, HPE/Aruba ProCurve, Extreme, Huawei, Juniper, MikroTik, D-Link and TP-Link.

  • 10 drivers
  • Cisco + Ruckus verified

Config backup & diff

Deduplicated running-config snapshots (SHA ring of 40 per switch), side-by-side diff, and an audited, confirm-gated revert restricted to owners and admins.

  • Versioned
  • Diff
  • Revert

Guarded changes

A safe change pipeline — validate → dry-run preview → serialized apply → verify → targeted rollback on failure. Strict allow-lists are the CLI-injection chokepoint. Off by default.

  • Dry-run
  • Rollback
  • Allow-list

Browser SSH terminal

A full interactive SSH session in the browser, brokered over an authenticated real-time channel — operator-and-above only, one shell per socket, every open and close audited.

  • Live shell
  • RBAC-gated
  • Audited

Neighbor discovery

LLDP/CDP neighbor tables collected across vendors and stitched together to build the live topology graph automatically — no manual link mapping.

  • LLDP
  • CDP fallback

Signed device catalog

New device profiles are delivered from the cloud catalog, each Ed25519-signed and verified against a pinned key before use — a rogue server or MITM can't inject a profile.

  • Signed
  • Pinned key
  • Auto-sync
Visibility & Topology

The whole network, mapped and live

NOVA turns neighbor tables and flow data into an interactive map where every link shows real throughput.

Fleet topology & Constellation

Every switch's LLDP/CDP data merged into one graph of trunks and access links, each edge annotated with live bits-per-second from a background link-rate poller.

Live traffic view & insights

Real-time dashboards for top apps, talkers and protocol mix, plus an analytics view that surfaces east-west vs. north-south patterns across the fleet.

Pulsar favorites & drill-downs

Pin the switches, devices and metrics that matter to a favorites view, and drill into per-switch and per-device pages with gauges, sparklines and protocol detail.

Alerting & Notifications

Know first, from every signal

One rule engine spans device readings, syslog, port events, health, traffic and config changes — with de-duped notifications and email delivery.

Unified alert rules
Per-type enable + minimum-severity floor across every source, RBAC-scoped.
Direct syslog receiver
UDP 514, RFC 3164/5424, attributed to a switch by source IP; drives faster-than-poll port events.
Threshold rules
User-built rules over any reading (e.g. CPU > 50), edge-triggered with cooldown + recovery.
Sentinel builder
Point-and-click metric catalog and rule builder with a live event feed.
Notification centre
Persists, live-pushes to authorized sessions, de-dupes, and forwards above threshold.
Email / SMTP
nodemailer delivery with the SMTP password encrypted at rest; sends at/above severity.
Event timeline
Acknowledge and filter a categorized event history, scoped to each role.
Config-change alerts
Fire when a running-config snapshot changes — detect drift the moment it happens.
Security & Licensing

Secure by construction

Every secret encrypted, every privileged action logged, every license cryptographically bound — and a codebase that treats all network input as hostile.

Encrypted at rest

All SSH/SNMP/API/SMTP credentials and private keys are AES-256-GCM encrypted; the master key is readable only by SYSTEM and Administrators.

Signed, machine-bound licensing

Ed25519-signed license blobs, bound to the machine's MAC identity, re-verified against a pinned cloud key every few seconds with an offline grace window before lock.

RBAC + 2FA

Explicit-allow roles (owner / admin / operator / viewer), PBKDF2-SHA512 passwords, per-IP login rate-limiting, and RFC 6238 TOTP two-factor with replay protection.

Append-only audit trail

Every privileged action — auth, users, switches, settings, TLS, terminal — is written to an append-only, categorized audit log.

Hardened parsers

Every untrusted parser — SNMP, syslog, sFlow, NetFlow, CLI output — is length- and count-bounded against malformed or hostile input.

# license state, verified continuously
nova license status
plan enterprise
signature Ed25519 · valid
machine bind a4:bb:6d:…:19 · match
heartbeat 5s · cloud reachable
server cloudnm.novasecops.com (locked)
# tamper the file → next heartbeat rejects it
nova access lockdown
folder ACL SYSTEM + Administrators only
defender excluded · always-on service
Access groups
Operators and viewers see only the switches in their groups; hidden IDs return 404 to avoid existence leaks.
Fleet ACL analysis
Cross-switch ACL matrix, drift detection, and a 5-tuple flow simulator.
TLS / HTTPS
Upload a validated PEM cert + key (encrypted at rest) for HTTPS with TLS 1.2+ and strict headers.
Session hygiene
Sliding 8-hour and absolute 24-hour session clocks; tokens stored only as hashes.
Deployment

Installed in minutes, always on

A single self-contained installer for Windows Server. No database to stand up, no runtime to install — and it hardens itself.

01

Run the installer

One signed .exe bundles the app and its runtime. No Node.js, no external database.

02

Self-hardening

It excludes its folder from Defender, locks the NTFS ACL to Administrators + SYSTEM, and opens the console port.

03

Always-on service

Registered as a background service that starts at boot and restarts itself if it ever stops.

04

Activate & go

Open the console, activate your license key, and start adding switches, devices and API monitors.

Ready to see your whole network in one place?

Book a walkthrough of NOVA NETWORK on your own infrastructure — monitoring, management, topology and security, unified.