Coverage

If it answers SNMP,
it is on the map.

Nobody runs one manufacturer. Estates are assembled over a decade through mergers, refreshes and whichever supplier won that year — and monitoring that assumes otherwise ends up as three consoles that disagree.

The rule is simple: if a device answers SNMP, it is supported. Everything else — CDP and LLDP for neighbour discovery, NetFlow, sFlow and IPFIX for traffic, syslog and traps for events, SSH for configuration — adds a further layer wherever the equipment provides it. In practice that covers Cisco and Meraki, Juniper, HPE and Aruba, Fortinet, Palo Alto, Mellanox, Check Point and every other manufacturer of managed network equipment. Nothing is installed on the monitored devices, so coverage is a question of protocol support rather than of whether a vendor-specific agent still exists for a nine-year-old switch.

How coverage works

Protocols, not plugins.

The practical question is never "do you support brand X" but "does that device speak the standard protocols". Almost all of them do — including the equipment that predates whoever currently administers it.

Discovery

SNMP, CDP and LLDP

Devices are found and identified through standard MIBs, and the links between them through neighbour discovery. Cisco and Meraki, Juniper, HPE and Aruba, Fortinet, Palo Alto, Mellanox, Check Point, Extreme, MikroTik — and anything else that answers SNMP — all appear on the same map.

Works on anything that answers SNMP — including the equipment nobody has documentation for any more.

Health

Interface and device counters

Availability, response time, port state, errors, discards, CPU, memory and temperature come from standard and vendor MIBs. Where a manufacturer exposes something extra, it is read; where it does not, the standard set still applies.

The floor is universal. Vendor-specific detail is a bonus rather than a dependency.

Traffic

NetFlow, sFlow and IPFIX

Whichever of the three a device exports is collected and normalised into the same view, so a network that speaks NetFlow in one place and sFlow in another still produces one ranked list.

You do not have to standardise your estate on one flow protocol to get one answer.

Events

Syslog and SNMP traps

Everything sends these, and they are usually spread across several collectors nobody reads. Bringing them into the same timeline as the counters and the traffic is most of their value.

Correlated against traffic, a syslog line stops being noise and becomes context.

Configuration

SSH, per device family

Backup, comparison and restore work over SSH against each platform's own command set. This is the one area that genuinely is vendor-specific, and it is handled per family rather than per product.

A mixed estate is backed up on one schedule, into one history, with one diff view.

Packets

Vendor-independent by definition

The sniffer reads the traffic itself. It does not know or care which manufacturer forwarded the frame, which makes the packet layer the one part of the platform where vendor support is not a concept.

This is why the hardest problems are also the most portable ones across a mixed network.

What this means in practice

  • One console, not one per manufacturer. The map, the traffic view and the configuration history cover the whole estate rather than a slice of it.
  • No agents anywhere. Nothing to install, patch or get approved on the monitored equipment — which is also what makes old and locked-down devices coverable.
  • Acquisitions do not need a project. A network you inherit is discovered by the same mechanism as the one you built.
Common questions

Short answers.

Which network vendors does Net-Monitor support?

Coverage is by protocol rather than by brand: if a device answers SNMP it is supported, and CDP or LLDP, NetFlow/sFlow/IPFIX and SSH each add a further layer where present. In practice that means Cisco and Meraki, Juniper, HPE and Aruba, Fortinet, Palo Alto, Mellanox, Check Point, Extreme, MikroTik — and effectively every other manufacturer of managed network equipment, including the ones nobody has documentation for any more.

Do I need an agent on each device?

No. Nothing is installed on the monitored equipment at all. This matters most for the devices you cannot touch — old switches, appliances under a support contract that forbids modification, and industrial controllers that cannot run software of any kind.

What if a device only supports SNMP?

Then you get discovery, identification, health and interface statistics for it, which is the majority of what most devices are monitored for. Traffic analysis needs flow export or a capture point on its path, and configuration management needs SSH — but the absence of either does not exclude the device from the platform.

How does this work after an acquisition?

The inherited network is discovered by exactly the same mechanism as the existing one, which usually produces an accurate map and inventory faster than the acquired organisation can supply documentation. It is a common reason the discovery capability gets used first.

Curious what it would find on your estate?

Discovery on a real network takes an afternoon and is the fastest way to see the coverage for yourself.

Chat with an engineer