Overview
—
Health by user —
okwatchat-riskcriticalno data
You're signed in as a viewer. Grab the NetDiag agent from Downloads and see the best exit under VPN points. Per-user logs and egress detail need the support role.
Clients — worst-first
| client | egress (isp · ip · loc) | health | grade | worst hop | targets | failing | devices | last seen | |
|---|---|---|---|---|---|---|---|---|---|
| loading… | |||||||||
User — (support+ · audited)
Logs
VPN point leaderboard — best-first · advisory
| # | point | region | health | clients | worst hop |
|---|---|---|---|---|---|
| loading… | |||||
Watchlist — targets agents check
| host / value | kind | checks | |
|---|---|---|---|
| loading… | |||
The global set is the default for every agent; a per-client set overrides it for that client's agents (matched by their
client_id). Pick a set above, or add a client. Saving an empty client set removes the override (reverts to global). Agents apply on their next config pull/ingest.Egress — VPN points & exit detection
| point (dns_name) | region | kind | protocol | egress CIDRs (comma-separated) | |
|---|---|---|---|---|---|
| loading… | |||||
agents match their public IP (GET /v1/whoami) against these egress entries to detect which VPN they exit through — enter a plain IP (e.g.
203.0.113.34, stored as /32) or a CIDR range (e.g. 203.0.113.0/24), comma/space separated. pritunl = local client, amnezia = router, office = gateway, killswitch = corporate egress ranges (labelled “KillSwitch VPN — inside company network”). protocol labels the VPN at this egress (AmneziaWG/WireGuard/OpenVPN) for the router case — where the client can’t detect it locally and one IP may run several; a desktop client that sees its own tunnel overrides it. Sign in as an admin to save.Detection policy — pushed to agents
verdict thresholds + VPN-advisory cadence the Hub pushes to every agent (via versioned /v1/config). Set all three thresholds together, or leave all blank to let agents keep their local default. Agents apply on their next config pull / ingest. (KillSwitch / company egress ranges are managed in the Egress panel as a point of kind
killswitch.)Auth — Azure AD / OIDC
Group → role
| Azure group | NetDiag role | |
|---|---|---|
| loading… | ||
staff sign-in maps an Azure group to a NetDiag role. The secret is write-only (leave blank to keep the stored one). admin only. Register this redirect URI on the Azure app (Authentication → Web):
https://netd.wavea.cc/api/auth/callback. Saving applies immediately — no Hub restart. Empty fields fall back to the Hub's deploy-time --oidc-* flags/env, so clearing a field here cannot disable a value set at deploy level (to fully disable Azure, remove it from the deploy env).Operational
capacity & cache knobs. Saved immediately; applied on the next Hub restart. admin only.
Revoked devices
| agent / device id | |
|---|---|
| loading… | |
a revoked device id is rejected immediately on ingest and cannot re-enroll (per-agent enrollment mode only). admin only.
Agent downloads
| os | arch | file | size | sha256 | |
|---|---|---|---|---|---|
| loading… | |||||
per-OS client installers (built via scripts/build-agents.sh, served from the Hub
--agents-dir). Verify integrity against the published SHA256SUMS. Binaries are unsigned pending OS code-signing certs.