Diagnostics Engine

Does the service actually work, or does it merely respond?

A central ping or a green DNS status is not enough for a defensible diagnosis. What matters is whether the service works where clients and access points actually need it. Control runs targeted checks for APs, sites, SSIDs, or VLANs and connects the result with technical evidence.

The scope matters

Small local deviations can create major operational problems.

DNS

Healthy globally, unresolvable locally

A specific RADIUS, NTP, or cloud hostname cannot be resolved through the resolver at one site. Control shows the resolver, target, response, runtime, and affected scope.

DHCP

Successful, but too slow

A lease is issued, but far too late. DHCP relay, VLAN, packet loss, switch-port, or link issues become visible as potential infrastructure context.

RADIUS

Authentication works, accounting fails

Control validates the server, role, port, authentication, accounting, RTT, DNS resolution, and the exact error returned.

NAC / SITE ENGINE

Online does not mean correctly onboarded

An AP can be reachable yet still belong to the wrong NAC group context, remain unonboarded, or receive an unexpected VLAN attribute.

CLOUD SERVICES

Firewall and SSL inspection

Internet connectivity works, but certificate manipulation or firewall rules prevent cloud communication and the onboarding of new access points.

Service-test pipeline for DHCP, gateway, DNS, NTP, RADIUS, NAC, and cloud services
From the selected scope through individual checks to an evidence-backed result.

Service matrix

One test run. Multiple access points. Comparable results.

The Service Matrix shows queue state, current phase, runtime, and result for each access point. Site-level differences become visible without investigating every AP individually.

Service Matrix with multiple APs and active service tests
DHCP, gateway, DNS, NTP, RADIUS, NAC, cloud, PoE, speed, duplex, and interface counters in the same scope.

Infrastructure correlation

The visible fault is not always the root cause.

A damaged uplink can cause CRC errors, drops, slow DHCP leases, and unstable sessions at the same time. If you only look at the DHCP failure, you can end up troubleshooting the wrong system. Control puts service results next to AP, switch-port, and link evidence.

NAC evidence with Site Engine and VLAN attributes
NAC evidence: onboarding, enrollment, VLAN attributes, and configuration status.
RADIUS evidence with authentication, accounting, and RTT
RADIUS evidence: server, role, authentication/accounting, reachability, RTT, and error details.

Packet evidence

When status values are not enough, the packet matters.

Remote Sniffer and RPCAP enable targeted captures with client, DNS, DHCP, or RADIUS filters. Scope, BPF preview, frame limit, runtime, safe stop, and PCAP download remain controlled and traceable.

Client DNS evidence captured through the remote sniffer
DNS resolution with client IP, resolver, responses, and unanswered requests.
Remote sniffer with BPF preview and PCAP download
RPCAP interface, evidence filter, safe stop, and PCAP download.

Result

Turn “it does not work” into a defensible finding.

Every check returns scope, executed steps, runtime, status, technical evidence, affected infrastructure, and a precise error message. The result can be documented directly or processed in a structured form.