Clients — sorted worst-first
| health | grade | worst hop | targets | failing | |
|---|---|---|---|---|---|
| loading… | |||||
VPN point leaderboard — best-first · advisory
| # | point | region | health | clients | worst hop |
|---|---|---|---|---|---|
| loading… | |||||
Watchlist — hosts every agent checks
| host / value | kind | checks | |
|---|---|---|---|
| loading… | |||
admins set the global target set here; agents apply it on their next config pull/ingest. Switch “view as” to admin to save.
Egress — VPN points & exit detection
| point (dns_name) | region | kind | egress CIDRs (comma-separated) | |
|---|---|---|---|---|
| loading… | ||||
agents match their public IP (GET /v1/whoami) against these CIDRs to detect which VPN they exit through — pritunl = local client, amnezia = router, office = gateway. Switch “view as” to admin to save.
Auth — Azure AD / OIDC
Group → role
| Azure group | NetDiag role | |
|---|---|---|
| loading… | ||
staff sign-in maps an Azure group to a NetDiag role. The secret is write-only (leave blank to keep the stored one). admin only.
Operational
capacity & cache knobs. Saved immediately; applied on the next Hub restart. admin only.