Diagnostics Engine

Not only whether a service works—but where, for whom, and why.

A central ping or a green DNS status is not enough. Services must be tested from the network and scope in which clients and access points actually use them. Control runs targeted checks across individual APs, entire sites, SSIDs, or VLANs and connects the result with technical evidence.

Scope matters

Small local deviations can create major operational problems.

DNS

Healthy globally, unresolvable locally

A specific RADIUS, NTP, or cloud hostname cannot be resolved through the resolver at one site. Control shows the resolver, target, response, runtime, and affected scope.

DHCP

Successful, but too slow

A lease is issued, but far too late. DHCP relay, VLAN, packet loss, switch-port, or link issues become visible as potential infrastructure context.

RADIUS

Authentication works, accounting fails

Control validates the server, role, port, authentication, accounting, RTT, DNS resolution, and the exact error returned.

NAC / SITE ENGINE

Online does not mean correctly onboarded

An AP can be reachable yet still belong to the wrong NAC group context, remain unonboarded, or receive an unexpected VLAN attribute.

CLOUD SERVICES

Firewall and SSL inspection

Internet connectivity works, but certificate manipulation or firewall rules prevent cloud communication and the onboarding of new access points.

Service-test pipeline for DHCP, gateway, DNS, NTP, RADIUS, NAC, and cloud services
From the selected scope through individual checks to an evidence-backed result.

Service matrix

One test run. Multiple access points. Comparable results.

The Service Matrix shows queue state, current phase, runtime, and result for each access point. Site-level differences become visible without investigating every AP individually.

Service Matrix with multiple APs and active service tests
DHCP, gateway, DNS, NTP, RADIUS, NAC, cloud, PoE, speed, duplex, and interface counters in the same scope.

Infrastructure correlation

The visible fault is not always the root cause.

A damaged cable can simultaneously cause CRC errors, drops, slow DHCP leases, cloud interruptions, and unstable application sessions. Control correlates service results with AP, switch-port, and link evidence so teams do not troubleshoot the wrong system.

NAC evidence with Site Engine and VLAN attributes
NAC evidence: onboarding, enrollment, VLAN attributes, and configuration status.
RADIUS evidence with authentication, accounting, and RTT
RADIUS evidence: server, role, authentication/accounting, reachability, RTT, and error details.

Packet evidence

When status values are not enough, the packet matters.

Remote Sniffer and RPCAP enable targeted captures with client, DNS, DHCP, or RADIUS filters. Scope, BPF preview, frame limit, runtime, safe stop, and PCAP download remain controlled and traceable.

Client DNS evidence captured through the remote sniffer
DNS resolution with client IP, resolver, responses, and unanswered requests.
Remote sniffer with BPF preview and PCAP download
RPCAP interface, evidence filter, safe stop, and PCAP download.

Result

Turn “it does not work” into a defensible finding.

Every check returns scope, executed steps, runtime, status, technical evidence, affected infrastructure, and a precise error message. The result can flow directly into a report or downstream API processing.