Solutions

From a multi vendor estate to a single view

The information already exists, scattered across hundreds of devices that do not name the same things the same way. NacTrack cross references it and returns it in the only form operations can use: a chart, a filterable table, a colour code.

The chain

From a customer name to the port the service lands on

Every link is derived from something read off a device. The bottom row says what from.

Correlation chain: account, customer, service, attachment, device, siteSix links, each derived from collected data. Account and customer come from interface descriptions, naming conventions, contract references and VRF names. The service comes from the product named in the description and from the QoS policy. The attachment comes from the subinterface, the VLAN and collected addressing. The device comes from inventory, with its version and model. The site comes from the device hostname and reported neighbours.DERIVED FROMInterface descriptionsNaming conventionsAccountthe groupContract referencesVRF namesCustomerthe billed entityProduct namedQoS policyServicewhat is soldSubinterface and VLANCollected addressingAttachmentwhere it landsInventoryVersion and modelDevicethe boxDevice hostnameReported neighboursSitethe place

DERIVED FROM

  1. Accountthe group
  2. Customerthe billed entity
  3. Servicewhat is sold
  4. Attachmentwhere it lands
  5. Devicethe box
  6. Sitethe place

Blast radius is this same chain walked backwards, which is why the two answers cannot contradict each other. Every link remembers where it came from, and a walk reports the weakest one it crossed.

For a service provider

Your customers, seen from your own network

The customer as the starting point

An account, its entities, their services, and for each service the device and port where it actually lands. Built from the customer outward, not the reverse.

Blast radius

This device goes down: who is cut off, and which services. The reverse question walks exactly the same path, so the two answers cannot contradict each other.

Shared failure domains

Knowing three hundred customers share one PE and a single customer shares another changes the priority. On a diagram the two look alike.

Provenance on every link

An interface description is weaker than a configuration, which is weaker than an observed state. Every path reports the weakest link it crossed.

Redundancy asserted, never guessed

Protection is only recorded where it was labelled. Two ports with one down is not redundancy, and the product refuses to claim it is.

Per entity isolation

One tenant per subsidiary or managed customer, with separate rights and no leakage between tenants.

app.nactrack.com/customers
The connected customer register, with the product family and the circuits of every client file
The register is built from the network: every file comes from interface descriptions, VRF names and circuit references read off the devices, never from an import. The product families count clients per service sold, and mass market subscribers are counted separately because they are not client files. The module carries its lab notice, exactly as it does in the product.

What the product addresses at an operator

Core and edge

Core and provider edge routers, BGP, IS-IS and OSPF sessions, routes advertised on internet edge devices.

Transport services

MPLS and L2VPN circuits, xconnect, with the remote device and the state of each circuit.

Aggregation and access

VLAN continuity between sites, spanning tree, access ports, endpoints seen per site.

Multi generation estate

Old hardware is the least documented and the most fragile. It is also what SSH collection reaches without difficulty.

A dated statement for the regulator

A dated compliance and exposure report, produced from the real state rather than from a declaration.

Let us talk about your estate