Coverage

Multi vendor, and the matrix says where the gaps are

What follows is not the list of what NacTrack can learn to read, it is the list of what it already reads, empty cells included. A platform that is missing gets handled, not refused.

The estate you already have

The vendors NacTrack reads

Each one is a row of the table below, with what is actually read from it, column by column and empty cells included.

  • Cisco
  • Huawei
  • Juniper
  • Aruba
  • Arista
  • Nokia
  • Dell
  • Fortinet
  • F5
  • Palo Alto Networks
  • Infoblox
  • Forcepoint

What is collected per platform

Coverage is published as it is, including the gaps.

CoveredPartialNot covered

PlatformInventoryTopologyComplianceCVESpanning treeMPLS and L2VPN
Cisco IOS 12 and 15CoveredCoveredCoveredCoveredCoveredCovered
Cisco IOS XE 16 and 17CoveredCoveredCoveredCoveredCoveredCovered
Cisco ASACoveredPartialCoveredCoveredNot coveredNot covered
Cisco NX-OSCoveredCoveredCoveredCoveredCoveredPartial
Cisco IOS XRCoveredCoveredCoveredCoveredNot coveredCovered
Huawei VRPCoveredCoveredCoveredCoveredCoveredCovered
Juniper Junosby importby importby importby importNot coveredNot covered
Aruba AOS-CXCoveredCoveredCoveredCoveredNot coveredNot covered
Aruba AOSCoveredCoveredCoveredCoveredNot coveredNot covered
Dell OS10CoveredCoveredCoveredCoveredNot coveredNot covered
Arista EOSby importby importby importby importNot coveredNot covered
Nokia SR OSby importby importby importby importNot coveredNot covered
Fortinet FortiOSCoveredPartialCoveredCoveredNot coveredNot covered
F5 TMOSCoveredPartialCoveredCoveredNot coveredNot covered
Palo Alto PAN-OSCoveredPartialCoveredCoveredNot coveredNot covered
Infoblox NIOSCoveredNot coveredCoveredPartialNot coveredNot covered
Forcepoint NGFWCoveredPartialNot coveredCoveredNot coveredNot covered

Compliance rule sets ship per platform, and most have a reference configuration set that tests them on every build. Forcepoint NGFW is collected but has no rule set yet: we would rather say so than evaluate it against another vendor's rules. Spanning tree is captured on Cisco and Huawei switches, MPLS and L2VPN on Cisco IOS, IOS XE, IOS XR and Huawei. Firewalls and load balancers appear in the topology through their addressing rather than a reported neighbour, since those platforms do not run LLDP or CDP. Juniper Junos, Arista EOS and Nokia SR OS are marked by import: you supply the configurations and command outputs, NacTrack parses them and shows them alongside the rest of the estate. Automatic SSH collection does not support these three platforms, and we would rather say so here than at deployment.

app.nactrack.com/devices
The device list: four vendors, with model, software version, site and lifecycle
Ten rows of one table, four vendors: Aruba, Cisco, Huawei and F5. The model, software version, site and serial are read off the device, not typed in. The lifecycle column comes from a hand kept catalogue, never inferred from the model name, which is why it can be empty rather than wrong.
Beyond the columns above

Two platforms read for something other than a switch

The columns above describe a network device. These two are collected to answer a different question, so they are described by what is read from them.

PlatformWhat is read from it
Cisco ISENetwork access devices, live sessions with the 802.1X and MAB split, profiled endpoints, identity and endpoint groups, authorisation profiles, TrustSec with its SGTs, SGACLs and egress matrix, identity sources, TACACS profiles and command sets.
Cisco Catalyst 9800, on IOS XEThe controller, its access points, its WLANs, the radios and the associated clients. The controller is itself an IOS XE device, so the inventory, compliance and CVE of the IOS XE row already apply to it.

Both of these surfaces are in the lab, and the product says so on screen on every one of their pages. The controller was validated against a real CW9800M; AireOS, the previous generation, is not supported and we would rather write that here.

In detail

What is asked of each platform, command by command

The table above says what you get. This says how. Open a platform to see the commands the collector sends it, grouped by what they bring back.

Cisco IOS and IOS XE45 SSH commands

Addressing

  • show ip dhcp binding
  • show ip dhcp pool

Configuration

  • show running-config

Endpoints seen

  • show ip arp
  • show mac address-table

Inventory

  • show inventory
  • show switch

Ports and interfaces

  • show interfaces
  • show interfaces transceiver detail
  • show ip interface brief
  • show ipv6 interface brief
  • show vlan brief
  • show vlans

Redundancy

  • show standby brief
  • show vrrp brief

Routing

  • show bfd neighbors
  • show bgp ipv4 unicast summary
  • show bgp vpnv4 all summary
  • show ip bgp ipv4 unicast summary
  • show ip bgp vpnv4 all summary
  • show ip eigrp neighbors
  • show ip ospf neighbor
  • show ip route eigrp
  • show ip route isis
  • show ip route ospf
  • show isis database detail
  • show isis neighbors detail

Spanning tree

  • show spanning-tree
  • show spanning-tree detail
  • show spanning-tree mst detail
  • show spanning-tree vlan all detail

Topology

  • show cdp neighbors detail
  • show lldp neighbors detail

Transport and L2VPN

  • show bridge-domain
  • show ethernet service instance detail
  • show l2vpn service all
  • show l2vpn service vfi all detail
  • show l2vpn vfi detail
  • show mpls l2transport vc
  • show mpls ldp interface
  • show mpls ldp neighbor
  • show mpls ldp neighbor detail
  • show vfi
  • show xconnect all
  • show xconnect all detail
Cisco NX-OS24 SSH commands

Configuration

  • show running-config

Endpoints seen

  • show ip arp
  • show mac address-table

Inventory

  • show inventory
  • show system resources

Licensing

  • show license usage

Ports and interfaces

  • show interface
  • show interface status
  • show ip interface brief
  • show vlan

Redundancy

  • show hsrp brief
  • show vrrp brief

Routing

  • show bgp all summary
  • show bgp ipv4 unicast summary
  • show bgp vrf all ipv4 unicast summary
  • show ip eigrp neighbors
  • show ip ospf neighbor
  • show ip route eigrp
  • show ip route isis
  • show ip route ospf

Spanning tree

  • show spanning-tree detail
  • show spanning-tree vlan 1-4094 detail

Topology

  • show cdp neighbors detail
  • show lldp neighbors detail
Cisco IOS XR5 SSH commands

Access lists

  • show access-lists ipv4 usage pfilter location all

Device health

  • show memory summary
  • show processes cpu

Licensing

  • show license summary

Ports and interfaces

  • show policy-map interface all
Cisco ASA15 SSH commands

Configuration

  • show running-config

Endpoints seen

  • show arp
  • show mac-address-table

Inventory

  • show inventory

Ports and interfaces

  • show interface
  • show interface ip brief
  • show ipv6 interface brief
  • show nameif

Redundancy

  • show failover

Routing

  • show bgp summary
  • show eigrp neighbors
  • show ipv6 route
  • show ospf neighbor
  • show route
  • show route ospf
Huawei VRP30 SSH commands

Addressing

  • display ip pool

Configuration

  • display current-configuration

Device health

  • display cpu-usage
  • display memory-usage

Endpoints seen

  • display access-user brief
  • display arp
  • display ipv6 neighbors
  • display mac-table

Inventory

  • display device
  • display elabel
  • display version

Licensing

  • display license
  • display license resource usage

Ports and interfaces

  • display interface brief
  • display ip interface brief
  • display ipv6 interface brief

Redundancy

  • display vrrp brief

Routing

  • display bfd session all
  • display bfd statistics
  • display bgp ipv6 peer
  • display bgp peer
  • display bgp vpnv4 peer
  • display isis peer

Spanning tree

  • display stp brief
  • display stp instance all
  • display stp interface

Topology

  • display lldp neighbor

Transport and L2VPN

  • display mpls l2vc
  • display mpls ldp interface
  • display mpls ldp peer
Aruba AOS-CX20 SSH commands

Configuration

  • show running-config

Endpoints seen

  • show arp
  • show mac-address-table

Inventory

  • show module
  • show system

Ports and interfaces

  • show interface
  • show interface brief
  • show lacp aggregates
  • show lacp interfaces
  • show vlan

Routing

  • show bgp all-vrf all neighbors
  • show ip ospf interface all-vrfs
  • show ip ospf neighbors all-vrfs
  • show ip route all-vrfs

Topology

  • show cdp neighbor-info
  • show lldp neighbor-info
  • show lldp neighbor-info detail

Transport and L2VPN

  • show evpn evi detail
  • show interface vxlan
  • show interface vxlan vteps
Dell OS1015 SSH commands

Configuration

  • show running-configuration

Endpoints seen

  • show ip arp
  • show mac address-table

Inventory

  • show inventory
  • show inventory media

Ports and interfaces

  • show interface
  • show interface status
  • show ip interface brief

Routing

  • show ip route

Spanning tree

  • show spanning-tree detail

Topology

  • show lldp neighbors
  • show lldp neighbors detail

Transport and L2VPN

  • show ip bgp l2vpn evpn summary
  • show nve remote-vtep
  • show virtual-network
Fortinet FortiOS17 SSH commands

Device health

  • get system performance status

Endpoints seen

  • get system arp

Inventory

  • get hardware nic
  • get system status

Ports and interfaces

  • get system interface physical

Routing

  • get router info bgp summary
  • get router info ospf neighbor
  • get router info routing-table all

Topology

  • diagnose lldp neighbor-detail
  • diagnose lldp neighbor-detail port1
  • diagnose lldp neighbor-summary
  • diagnose lldprx neighbor summary
  • get system lldp neighbors

VPN

  • diagnose vpn tunnel list
  • get vpn ipsec tunnel details
  • get vpn ipsec tunnel summary
  • get vpn ssl monitor
Forcepoint NGFW7 SSH commands

Device health

  • cat /proc/cpuinfo

Endpoints seen

  • cat /proc/net/arp

Inventory

  • /usr/sbin/sg-dmidata
  • /usr/sbin/sg-name
  • /usr/sbin/sg-version

Ports and interfaces

  • cat /proc/net/dev

Redundancy

  • /usr/sbin/sg-cluster status
F5 TMOS7 SSH commands

Inventory

  • list /sys global-settings hostname

Licensing

  • list /sys license

Ports and interfaces

  • list /net interface

Other

  • list /net self
  • list /net trunk
  • list /sys file ssl-cert
  • list /sys management-ip
Palo Alto PAN-OS6 configuration sections

Inventory

  • device and system

Policies

  • NAT rules
  • security policies
  • security zones

Ports and interfaces

  • interfaces

Routing

  • static routes
Cisco ISE15 API objects

Endpoints seen

  • endpoint
  • endpointgroup
  • profilerprofile

Inventory

  • mnt: Version
  • networkdevice

Live sessions

  • mnt: Session/ActiveList

Policies

  • activedirectory
  • authorizationprofile
  • egressmatrixcell
  • identitygroup
  • internaluser
  • sgacl
  • sgt
  • tacacscommandsets
  • tacacsprofile
Cisco Catalyst 9800, on IOS XE9 SSH commands

Device health

  • show application status ise

Wireless

  • show ap dot11 24ghz summary
  • show ap dot11 5ghz summary
  • show ap dot11 6ghz summary
  • show ap image
  • show ap summary
  • show wireless client summary
  • show wireless summary
  • show wlan summary
Infoblox NIOS5 API objects

Addressing

  • record:a
  • record:cname
  • record:host
  • record:ptr
  • zone_auth
Juniper Junos13 recognised on import

Configuration

  • configuration header: # JUNOS
  • show configuration

Inventory

  • hostname directive: host-name <name>;
  • show chassis
  • show chassis hardware
  • show version

Ports and interfaces

  • show interfaces

Routing

  • show bgp
  • show isis
  • show ospf
  • show route

Topology

  • show lldp
  • show lldp neighbors
Nokia SR OS2 recognised on import

Configuration

  • configuration header: # TiMOS

Inventory

  • hostname directive: system name <name>

235 entries in total, extracted from the collector itself on 2026-08-29, revision e61e75f2, rather than copied by hand. Not everything is read over SSH: Cisco ISE and Infoblox answer through their own API, and PAN-OS is read from the configuration the device exports. And a platform NacTrack never logs into is still recognised: you upload a session log or a configuration and it is parsed. Juniper is the clearest case, its commands are named one by one in the import detector. Each platform's label says which of the four applies. For the SSH platforms the list is what is specific to that platform: the branches sit on a shared base, so a short list means little that is specific, not little coverage, and Cisco IOS XR is the clearest case of that.

A platform that is missing

What happens when your platform is not in the table

  • You open a ticket. That is all we ask of you: the platform enters the support flow like any other request, and we carry it from there.
  • The rest is our work. The parsing runs on text from a real device, and that text is gathered while the ticket is handled. There is no vendor API to obtain, no partnership to sign and no third party release to wait for.
  • A platform comes in through import first, which gives inventory, compliance and CVE immediately, then moves to SSH collection once the command set has settled.
  • Specific architectures take the same route: an inherited addressing plan, a hand built VPLS, a naming convention peculiar to your house get described in a ticket, then correlated like everything else.

Is your hardware covered?

Send us the list of your platforms, the answer is precise and quick.