One console for your entire
network fabric.
NOVA NETWORK unifies switch management, SNMP & API monitoring, live traffic analytics, topology, endpoint correlation and alerting into a single self-hosted platform — with signed licensing and defense-grade security built in.
See everything, from the port to the packet
Poll it, sniff it, or call its API — NOVA collects switch, device, endpoint and flow telemetry in real time and renders it in one place.
Switch monitoring over SSH
Live per-port status, throughput and error counters, PoE budget, QoS/VoIP policy and running-config — collected over SSH with a warm connection pool that tolerates legacy gear.
- Port stats
- PoE
- QoS
- Reachability
SNMP device monitoring
Poll UPS, PDUs, sensors and servers with SNMP v1/v2c and secure v3 (auth+priv). Declarative profiles map OIDs to metrics, enums and thresholds — hot-reconfigurable.
- v3 auth/priv
- 15+ types
- Profiles
- 30s poll
API monitors
Monitor any REST API as if it were a device. Any method, any auth (bearer, basic, API-key, login), extract fields by JSON path, and get the same gauges, sparklines and edge-triggered alerts.
- REST / JSON
- Bearer · Basic
- 10s poll
- Encrypted creds
Live traffic analytics
Built-in sFlow v5 and NetFlow v5/v9 + IPFIX collectors decode flows into top applications, top talkers, protocol mix and east-west vs. internet locality — updated every two seconds.
- sFlow 6343
- NetFlow 2055
- Top talkers
- App classify
Health & environment
CPU, memory, temperature, fans, PSUs and uptime roll up into an explainable 0–100 fleet-health score with per-factor deductions — missing data never counts against you.
- 0–100 score
- Environment
- Explainable
Endpoint correlation
Every end device on one row: MAC → IP → vendor (OUI) → switch/port/VLAN → 802.1X session → LLDP identity → live traffic → port syslog. Pure correlation, no extra agents.
- ARP · MAC table
- 802.1X
- OUI vendor
- LLDP
Manage the fabric, don't just watch it
Multi-vendor CLI drivers, guarded configuration changes, versioned backups and a real SSH terminal — with honest "unsupported" instead of guesswork.
Multi-vendor drivers
Vendor-aware CLI command sets and parsers for Cisco IOS/IOS-XE, Ruckus ICX/FastIron, Aruba CX, HPE/Aruba ProCurve, Extreme, Huawei, Juniper, MikroTik, D-Link and TP-Link.
- 10 drivers
- Cisco + Ruckus verified
Config backup & diff
Deduplicated running-config snapshots (SHA ring of 40 per switch), side-by-side diff, and an audited, confirm-gated revert restricted to owners and admins.
- Versioned
- Diff
- Revert
Guarded changes
A safe change pipeline — validate → dry-run preview → serialized apply → verify → targeted rollback on failure. Strict allow-lists are the CLI-injection chokepoint. Off by default.
- Dry-run
- Rollback
- Allow-list
Browser SSH terminal
A full interactive SSH session in the browser, brokered over an authenticated real-time channel — operator-and-above only, one shell per socket, every open and close audited.
- Live shell
- RBAC-gated
- Audited
Neighbor discovery
LLDP/CDP neighbor tables collected across vendors and stitched together to build the live topology graph automatically — no manual link mapping.
- LLDP
- CDP fallback
Signed device catalog
New device profiles are delivered from the cloud catalog, each Ed25519-signed and verified against a pinned key before use — a rogue server or MITM can't inject a profile.
- Signed
- Pinned key
- Auto-sync
The whole network, mapped and live
NOVA turns neighbor tables and flow data into an interactive map where every link shows real throughput.
Fleet topology & Constellation
Every switch's LLDP/CDP data merged into one graph of trunks and access links, each edge annotated with live bits-per-second from a background link-rate poller.
Live traffic view & insights
Real-time dashboards for top apps, talkers and protocol mix, plus an analytics view that surfaces east-west vs. north-south patterns across the fleet.
Pulsar favorites & drill-downs
Pin the switches, devices and metrics that matter to a favorites view, and drill into per-switch and per-device pages with gauges, sparklines and protocol detail.
Know first, from every signal
One rule engine spans device readings, syslog, port events, health, traffic and config changes — with de-duped notifications and email delivery.
Secure by construction
Every secret encrypted, every privileged action logged, every license cryptographically bound — and a codebase that treats all network input as hostile.
Encrypted at rest
All SSH/SNMP/API/SMTP credentials and private keys are AES-256-GCM encrypted; the master key is readable only by SYSTEM and Administrators.
Signed, machine-bound licensing
Ed25519-signed license blobs, bound to the machine's MAC identity, re-verified against a pinned cloud key every few seconds with an offline grace window before lock.
RBAC + 2FA
Explicit-allow roles (owner / admin / operator / viewer), PBKDF2-SHA512 passwords, per-IP login rate-limiting, and RFC 6238 TOTP two-factor with replay protection.
Append-only audit trail
Every privileged action — auth, users, switches, settings, TLS, terminal — is written to an append-only, categorized audit log.
Hardened parsers
Every untrusted parser — SNMP, syslog, sFlow, NetFlow, CLI output — is length- and count-bounded against malformed or hostile input.
Installed in minutes, always on
A single self-contained installer for Windows Server. No database to stand up, no runtime to install — and it hardens itself.
Run the installer
One signed .exe bundles the app and its runtime. No Node.js, no external database.
Self-hardening
It excludes its folder from Defender, locks the NTFS ACL to Administrators + SYSTEM, and opens the console port.
Always-on service
Registered as a background service that starts at boot and restarts itself if it ever stops.
Activate & go
Open the console, activate your license key, and start adding switches, devices and API monitors.
Ready to see your whole network in one place?
Book a walkthrough of NOVA NETWORK on your own infrastructure — monitoring, management, topology and security, unified.