Full feature list

Every core feature, in one place.

NetEcho is security auditing and day-to-day network management on one dashboard. Below is the complete feature set, organized by category — auditing, config change tracking, device polling, remote access, automation, and the platform-level security it all runs on.

the five things you'll actually live in

Flagship tools

The categories below cover everything. These five are what a working day on NetEcho actually looks like.

per-member dashboard

Ops Center & Live Topology Map

A live, per-member operations dashboard built around one thing: the member's actual network topology, on screen, colored by real-time device status. Auto-refreshes every 15 seconds — this is the screen you leave open, not a report you pull up when something breaks.

  • Live network map — the member's real discovered topology, with every device color-coded by current up/down status the moment it changes, not just a static diagram
  • Audit score trend, active alarms, and BGP redundancy status in the same view
  • Pending config changes, interface thresholds, IP space, and BGP interface traffic — all on the same screen, no tab-switching
the audit engine

Security Audits & Reports

Not a pass/fail checklist — every finding in the report explains itself, in a document you can actually hand to a customer.

  • Prioritized action items — every finding ranked and grouped, not just listed
  • Plain-English findings — what it means, how to fix it, and which devices are affected, per finding
  • Device-by-device score breakdown, IP utilization, and port-scan results in the same report
ssh-based discovery

Network Mapping

Standalone topology discovery, separate from any single audit run — scans a member's live devices over SSH and builds the map from what's actually there.

  • Discovers L3 adjacency and BGP peering without relying on stale config uploads
  • Feeds the live status map shown on that member's Ops Center
  • Re-scan on demand as the network changes
per-interface history

Interface Traffic Graphing

Every polled interface gets its own utilization and throughput history — not just a current-state number.

  • Full utilization % and throughput charts per interface, auto-scaled bps/Kbps/Mbps/Gbps
  • Inline trend sparklines across a device's whole interface list, loaded in one request
  • Configurable utilization thresholds — global default or per-member — flag interfaces that need a throughput upgrade
  • Pin favorite interfaces straight onto that member's Ops Center
search everything

Config Search & Log Explorer

Two dedicated tools for finding one thing across an entire fleet, instead of opening devices one at a time.

  • Config Search — grep-style search across every device's config, scoped to a member or the whole fleet
  • Log Explorer — filter every device's logs by severity, device, and time, with free-text search
external attack surface

Penetration & Attack-Surface Testing

The same checks a real external assessment runs, so nothing in it surprises you when a customer's actual compliance audit happens — run as part of a full audit, or entirely on its own.

  • ~90-port scan plus live DDoS-amplification triggers (NTP, DNS, memcached, SSDP, CLDAP, chargen) and SNMP default-community exposure
  • Opt-in default-credential & DNS hygiene checks — zone transfer, DNSSEC, SPF/DMARC/DKIM — gated behind an explicit warning and acceptance step
  • Standalone report, exportable as PDF or HTML, scoped to just these findings
01 — auditing & reporting

Security Auditing & Reporting

Analyzes Cisco IOS/NX-OS, JunOS, Arista EOS, and other device configs for security misconfigurations, scores every member, and delivers customer-ready reports automatically.

28+ automated checks

Weighted across Critical, High, Medium, and Low severity — each device scored individually, then averaged into a member-wide score.

Automated scheduling

Re-run audits on a timer from one day up to twelve months, set globally or overridden per member.

HTML + PDF report export

Self-contained, logo-branded customer reports — download, email, or render straight to PDF.

Security score trend

A score-over-time chart on every customer report, with a plain-English improvement or decline summary.

Editable network topology

Auto-discovered L3/BGP topology diagrams you can drag, rewire, and save — or import your own from another tool.

BGP Explorer

Dual-homed redundancy checks, live RIPE/RouteViews visibility, and a per-provider coverage matrix for every owned prefix.

Custom scan checks

Build your own line-item checks with AND/OR word conditions — no regex required.

Remote probe agent

Delegate port scans to an external server so audits from inside the network don't produce false positives.

IPAM & location mapping

BGP prefix utilization visualization plus address geocoding with an embedded map, cached after first lookup.

Port scan & IP utilization, in the report

Every full audit includes the external attack-surface / port-scan results and IP address utilization alongside the security findings, or run the same scan on its own — see below.

02 — external attack surface

Penetration & Attack-Surface Testing

The same checks a real external assessment runs, so nothing in it surprises you when a customer's actual compliance audit happens. Runs as part of a full audit, or entirely on its own via a dedicated Run Pen Test report.

~90-port external scan

Management, database, file-sharing, industrial, and ISP/CPE-specific ports — MikroTik, TR-069/CWMP, and more — scanned against every public interface IP.

DDoS-amplification vector checks

Live probes for NTP monlist, open DNS resolvers, memcached, SSDP, CLDAP, and chargen — the exact protocols abused in real-world reflection attacks.

SNMP exposure testing

Checks for well-known default community strings responding, not just whether the port is open.

Routing-protocol exposure

Flags BGP reachable from the internet outright — something that should never happen for an ISP.

Opt-in default-credential testing

Attempts a short list of well-known logins against exposed SSH and HTTP management interfaces — off by default, gated behind an explicit warning and required acceptance step.

DNS hygiene checks

Zone transfer (AXFR), DNSSEC presence, and SPF/DMARC/DKIM mail-authentication records, checked against a supplied domain.

Standalone Run Pen Test report

A dedicated scan and report, independent of a full audit — no config-compliance noise, just the external-facing findings.

HTML + PDF export

Self-contained pen-test report, exportable the same way as a full audit report — download, email, or render straight to PDF.

03 — config change tracking

Configuration Change Tracking

A working NCCM system: every device config is version-controlled with full history, diffing, and an approval workflow — with noise filtered out automatically so real changes never get lost in false positives.

Automatic change detection

A background watcher hashes every device config every 30 seconds and snapshots anything that changed.

Full diff & version compare

Diff any change against the approved baseline, or pick any two versions and compare them directly.

Approve / Approve All

Mark a change as the new baseline that future diffs are measured against, one at a time or in bulk.

Scheduled digests

Weekly, bi-weekly, or monthly email of every unapproved change and its actual diff content — not just a device list.

Smart noise filtering

Vendor save-banners, cosmetic formatting flips, and masked secrets are automatically excluded so they never trigger a false "changed" alert.

Bad-pull protection

A drastically different or blank capture is automatically re-verified before it's ever recorded as a real change.

Config Search

Grep-style search across every device's config, scoped to a member or, for admins, the whole fleet at once.

Log Explorer

A dedicated syslog search tool — filter every device's logs by severity, device, and time range, or search message text directly.

Tenant-facing access

Non-admin users see change history for their own assigned sites, with independent alert emails and schedules.

04 — device polling

SNMP & SSH Device Polling, Remote Pull

Inventories and pulls configs from devices directly — over SNMP, SSH, or a scheduled SFTP sync from a remote server — with broad support for older hardware.

SNMP + SSH polling

Cisco IOS/NX-OS, Juniper JunOS, Arista EOS, Dell/Force10, FS.COM, and Nokia SR OS, with vendor and version detection.

Scheduled remote pull

Pull a members folder from a remote server on a schedule via SFTP, with SSH-key, password, or PuTTY .ppk auth.

Bulk device import

Add many devices at once from a CSV or XLSX spreadsheet, with a per-row success/failure report.

Legacy SSH compatibility

Connects to older gear modern SSH libraries dropped by default — restoring support instead of failing outright.

Jumpbox / bastion tunneling

Route every SSH connection, SNMP poll, and terminal session through one configured jump server, globally or per member. The jumpbox itself needs nothing installed — just SSH access and a network path to the managed devices.

Configurable SSH connection limit

Caps how many SSH sessions can be open through the jumpbox at once; every sweep and bulk tool scales its own parallelism to that number automatically, and it's raisable once the jumpbox is confirmed to sustain more.

Telnet support

For gear with SSH disabled entirely — config pull, terminal, and automation all fall back to Telnet per credential.

Concurrent polling

Polls up to 5 devices at once with a live time-remaining estimate, instead of sweeping the fleet one device at a time.

License info pull

Pulls license status and expiration per device from its own dedicated SSH session and schedule.

Per-device interface inventory

Every device's live interfaces, status, and utilization in one place, without opening a terminal to check.

05 — in-browser ssh terminal

In-Browser SSH Terminal

A real interactive shell to any device, straight from its page in the browser — no PuTTY or terminal app required.

Live shell, auto-login

Connects and authenticates with the device's saved credentials, auto-entering enable mode automatically.

Full session logging

Every session's complete transcript is recorded with passwords redacted, reviewable per device, per member, or platform-wide.

Show-commands-only mode

Lock a limited or tenant account to read-only show commands — everything else is refused before it reaches the device.

Standalone Terminal App

A pop-out, multi-pane terminal to your own admin-defined infrastructure, with SFTP file browsing, scrollback search, and session logs.

06 — diagnostic tools

Diagnostic Tools

Ping, traceroute, path monitoring, and a couple of everyday network-admin utilities — runnable from this server, a global jumpbox, or a member's own jumpbox.

Multi-target Ping

Run any number of simultaneous tests, each with a live RTT graph and loss percentage.

Traceroute

ICMP-mode path tracing for reliable results against destinations that ignore classic UDP traceroute.

Path Monitor

A PingPlotter-style view that continuously pings every hop along a route, color-coded by loss and latency.

Target devices & BGP peers directly

Run any of the above against an already-polled device or an identified eBGP peer without typing an IP by hand.

DHCPd Config Generator

Builds an ISC dhcpd.conf subnet snippet from a network, range, and gateway — optionally scoped to a shared network.

DNS Records Generator

Builds BIND-style zone records — A, AAAA, CNAME, MX, TXT, NS, PTR, and SRV — manually or in bulk from an uploaded spreadsheet.

07 — automation

Automation (Config Push)

Scripted config changes across one device or an entire fleet, with a dry-run preview and pass/fail verification on every push.

Scripted SSH push

A simple WAIT / SEND line-based script drives the session exactly as written — enable prompts, conf t, and beyond.

Dry-run preview

See exactly which devices are eligible and the resolved, secret-masked command sequence before anything sends for real.

Pass/fail verification

Pulls the running-config before and after the script and shows a side-by-side diff, so a "pass" always comes with proof.

Parallel push

Push to up to 10 devices at once instead of one at a time, for large batches.

Live progress & abort

Real-time per-device log streamed to the browser, with an abort button that stops before the next device.

Scheduling

Recurring unattended pushes with an optional completion-summary email so a bad run doesn't go unnoticed.

08 — credentials manager

Credentials Manager

Reusable, rotatable SSH credential sets — set once, link to any number of devices.

Reusable credential sets

Save a username/password/enable-password once and link it across every device that uses it.

Stays linked, not copied

Rotating a password on the credential set updates every linked device immediately.

Per-credential login sequence

An optional scripted WAIT/SEND sequence (like the Cisco enable-mode dance) runs automatically before every push.

Excel export

Download every device and its credential — including passwords — as an offline password reference.

09 — cve reporting

CVE Vulnerability Reporting

Cross-references every polled device's platform and version against the National Vulnerability Database.

NVD vulnerability lookups

Cross-references each device's detected platform and version against the National Vulnerability Database — covering Cisco IOS/IOS-XE/NX-OS, Juniper JunOS, and Arista EOS.

Severity-ranked results

Every CVE found across a member's fleet, sorted by severity with CVSS score and a link to the full NVD advisory.

On-demand or fleet-wide scanning

Check a single device right now, or scan every device on a member at once with a live progress bar.

Isolated from scoring

A CVE finding is purely informational — it never moves a member's audit score.

10 — alerting & multi-tenant access

Alerting & Multi-Tenant Access

Score alerts, health reports, and a full multi-tenant model for handing each customer their own scoped view.

Email alerts

Score-drop notifications with a global default and per-member override, firing the moment a threshold is breached.

Live device up/down monitoring

Tracks every device's reachability continuously, with a configurable grace period before it's marked down (and alerted) or recovered — this is what drives the Ops Center map's live status.

Dashboard health reports

Full network summary, sorted best to worst score, delivered on a schedule.

Multi-tenant user management

Assign specific members to non-admin users, each with independent alert emails and report schedules.

Per-tenant view permissions

Four independent toggles control whether a tenant can see audits, change history, devices, or config files.

Change management preferences

Record how a member wants changes handled — view-only, contact before any change, or a Method of Procedure required — flagged before the terminal even opens.

Change management records

Upload a member's own change-management documentation and surface it right on the dashboard.

PagerDuty integration

Route device-down and threshold alerts straight into PagerDuty alongside email, so live monitoring plugs into an on-call rotation you already run.

11 — platform & security

Platform & Security

Self-hosted on your own infrastructure, hardened by default, with no phone-home telemetry.

Two-factor authentication

Opt-in TOTP with any authenticator app, plus one-time recovery codes downloadable as a PDF.

Self-service password reset

A one-hour, single-use reset link by email — never reveals whether an account exists, never resets 2FA.

Encryption at rest

Device credentials and 2FA secrets are encrypted in the database with a key stored outside it.

CSRF & session hardening

Per-session CSRF tokens app-wide, Secure/HttpOnly/SameSite cookies, and full security response headers.

SSH host-key pinning

Trust-on-first-use pinning for every device connection — rejects it outright if a key ever changes.

No phone-home

The only outbound call the app ever makes is an optional, user-triggered CVE lookup — no telemetry, ever.

Web-based self-upgrade

Upload a new release in Settings to upgrade in place, with an automatic pre-upgrade backup.

Runs without root

The installer never requires the service itself to run as root, on Linux with systemd support.

see it running

Every feature above, running against a real fleet.

The live demo uses the same build your customers would run — no cut-down trial, nothing staged.