feat: reflect netOrk v0.12.0–v0.28.0 release notes

Seventeen releases since the site was last brought up to date, checked
against the changelog and the code at the v0.28.0 tag.

- New feature sections: Security Assessment (TLS/SSH grades, CVE and
  container-image matching, exposure, deep scans; Knowledge Base licence),
  Vulnerability Management (triage queue, decisions with reasons, deferrals
  that come back, verified fixes), DHCP, Managed Services, Notifications
  (Signal).
- Existing sections gain per-user SSH keys and session windows, multi-role
  devices, one device per address per site, LAN Scan, MAC-table topology,
  service checks, site reachability, per-site firewall profiles with diff,
  honoured drift auto-correct, 16 Ansible roles, 18 dashboard widgets.
- Corrections: Docker status is Linux/OMV/QNAP, not Proxmox.
- Roadmap: CVE tracking shipped and is gone from "Planned"; a "Next release"
  group lists what is on main but unreleased (CrowdSec across sites, Windows
  driver, single-use console tickets, reboots refused instead of faked).
- NIS2: Art. 21 (2e) now describes the vulnerability handling that exists,
  (2i) adds attributable terminal sessions; CVE tracking left "coming".
- Persona pages: two new items each, counts updated. Glossary: Kea, WinRM,
  LAPI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-09-26 07:33:02 +02:00
co-authored by Claude Opus 5.5
parent 04c5c00280
commit 4cba6e156c
8 changed files with 335 additions and 53 deletions
+80 -15
View File
@@ -95,12 +95,22 @@ hardware and want operational visibility beyond what consumer dashboards offer.
- Vendor/model/OS auto-populated from NAPALM `get_facts()`
- Site assignment with FK to structured Site records
- AP Profile assignment for grouped OpenWRT config
- Web SSH terminal: sessions log in with each user's own SSH key, never the
device's shared account; opened and refused sessions are recorded. Sessions
are movable, dockable windows that survive navigating away
- A device can hold several roles at once (e.g. storage + hypervisor + Linux)
- One device per address per site; duplicates are refused (VMs exempt)
- Business criticality per device and site, used in vulnerability ranking
### Discovery
- ICMP ping sweep, SNMP scan, HTTP/HTTPS probing
- Device fingerprinting: vendor + platform confidence scoring
- FQDN resolution (reverse DNS)
- Manual adoption from scan results (no auto-create to avoid inventory noise)
- Discovery jobs in a sortable, filterable table, grouped per site
- LAN Scan: ping sweep from netOrk, each site satellite and every firewall;
live results with MAC and manufacturer; a finished scan becomes a discovery
job in one step
### VM Provisioning
- Cloud-Init based VM creation directly from a hypervisor's VMs tab — no
@@ -124,23 +134,32 @@ Custom NAPALM drivers for all of the following:
| Driver | Device type |
|---|---|
| `openwrt` | OpenWRT access points |
| `opnsense` | OPNsense firewalls |
| `proxmox` | Proxmox VE hypervisors |
| `fritzbox` | AVM Fritz!Box routers (read-only) |
| `hpe_officeconnect` | HPE OfficeConnect 1820 / 1920S switches |
| `linux` | Generic Linux servers |
| `procurve` | HP ProCurve / Aruba switches |
| `tplink_jetstream` | TP-Link Jetstream managed switches |
| `netgear` | Netgear switches |
| `fritzbox` | AVM Fritz!Box routers |
| `zyxel` | Zyxel switches |
| `netgear_plus` | Netgear Plus switches (web UI) |
| `netgear_smart` | Netgear Smart Managed Pro switches |
| `openmediavault` | OpenMediaVault NAS |
| `openwrt` | OpenWrt routers and access points |
| `opnsense` | OPNsense firewalls |
| `procurve` | HPE ProCurve / Aruba switches |
| `proxmox` | Proxmox VE hypervisors |
| `qnap_qts` | QNAP NAS on QTS |
| `sonos` | Sonos speakers |
| `tplink_jetstream` | TP-Link JetStream managed switches |
| `yealink` | Yealink IP phones |
| `zyxel` | Zyxel VMG routers (not switches) |
Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper JunOS.
The built-in NAPALM drivers (Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper JunOS)
are installed but not tested with netOrk and get none of its driver-specific
features. Capability matrix (audited against v0.28.0): see `src/pages/Drivers.tsx`.
Reboot from netOrk actually restarts only OpenWrt and Proxmox.
### Networking & Inventory
- Interface browser with IPv4/IPv6 addresses, MAC, speed, MTU
- LLDP neighbor discovery and topology graph
- LLDP neighbor discovery and topology graph, plus links derived from switch
MAC tables (drawn dashed)
- Radio problems between the access points of a site are reported
- ARP table and DHCP lease browser per device
- Subnet browser with interface-to-subnet assignments
- VLAN list grouped by site; per-VLAN device membership view
@@ -170,8 +189,10 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Configuration Automation (Ansible)
- Reusable Ansible roles and playbooks stored and edited directly in
netOrk — no separate git checkout
- 11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban
- 16 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy,
portainer, watchtower, uptime-kuma, vaultwarden, stalwart, bulwark, searxng,
postiz, listmonk, wireguard, fail2ban
- Roles state their resource needs; undersized hosts are refused with a reason
- Automatic dependency resolution — assigning `docker` pulls in `base`
automatically, no manual role ordering
- Built-in roles can't be deleted but are fully editable; customizations
@@ -215,7 +236,7 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- One-click Ack on any warning — clears it immediately and writes an audit log
entry; for config-change warnings the current state is accepted as the new
baseline
- Docker container and image status (Proxmox/Linux)
- Docker container and image status (Linux, OpenMediaVault, QNAP)
- Service status and start/stop/restart (systemd)
- VM/container list with OS device cross-linking (Proxmox)
- Per-device availability windows — suppress OFFLINE status and poll-failure
@@ -225,21 +246,65 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- OPNsense: TLS certificate monitoring for the Trust store, with
expiring-soon / expired warnings
- OPNsense: Dynamic DNS service-down warning (os-ddclient)
- Service checks about once a minute (DNS, NTP, VPN tunnels, core daemons,
gateways), derived automatically; three failures before an alert; can run
from satellites, including a DHCP check
- Site reachability: polling pauses behind a dead tunnel, one warning names
it, everything is re-polled when it returns
### Dashboards
- Configurable, shareable dashboards — build your own from a widget picker
instead of a fixed layout
- WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas
- 13 widget types: stats, device warnings, recently updated devices, network
- 18 widget types: stats, device warnings, recently updated devices, network
topology, EOL status, config drift summary, Wazuh security alerts, audit log
activity, discovery jobs status, upcoming scheduled actions, DNS zones
overview, site overview, config snapshot history
overview, site overview, config snapshot history, managed services,
certificate expiry, outdated Docker images, firewall profile deployment
status, service checks
- Multi-instance widgets with independent per-widget settings
- Share a dashboard with specific users; recipients can subscribe to the
owner's live version or clone it into their own editable copy
- Favorite dashboards for quick access from the main menu; set any dashboard
as your home view
### Notifications
- Signal messages for everything netOrk watches; each person registers their
own number, administrators pair netOrk once via QR code
- One message per site outage, daily summary for recurring items, hourly
bundling, quiet hours per number, mute per kind, full history with reasons
### DHCP
- DHCP reservations: import from the firewall, validated, diff, then apply
(adds and updates only)
- DHCP subnets (Kea on OPNsense) with options and search domains; settings
that break a network are refused
### Managed Services
- Every container-based service across devices with endpoints, TLS
certificates and access rules
- Compose editor with masked secrets and automatic backup snapshot; redeploy
is a separate confirmed step
- Zoraxy vhosts editable and written back; PostgreSQL databases listed
### Security Assessment
- Security tab per device: TLS/SSH grades A–F, installed software and
container images matched against known vulnerabilities, hardening benchmarks
- Ratings adjusted to the device (local access, trusted network, not running,
not booted kernel; raised when exploited in the wild)
- Kernel reboot recommendation with the vulnerabilities it would clear
- Exposure from firewall rules; internet-visible ports and abuse reports for
own public addresses; on-demand hardening audit and web scan
- Vulnerability data from the netOrk Knowledge Base (licence required)
### Vulnerability Management
- Triage queue across all devices, one row per vulnerability, ordered by
remediation deadline, exploitation, severity, likelihood, criticality, spread
- Decisions (not applicable / accept until / defer until / fixed) with a
mandatory reason; accept and not-applicable need an elevated permission
- Deferred and accepted items return by themselves; ignored ones go overdue
- Daily reassessment verifies fixes and reopens regressions
### Security Integrations (plugins)
- **Wazuh** — agent enrollment tracking, vulnerability counts (by severity),
recent alert history, CIS benchmark scores, one-click agent install fix stream
+33
View File
@@ -286,6 +286,39 @@ export const GLOSSARY: GlossaryEntry[] = [
},
match: ['MFA'],
},
{
id: 'kea',
category: 'networking',
display: 'Kea',
fullName: { en: 'ISC Kea DHCP', de: 'ISC Kea DHCP' },
definition: {
en: 'The DHCP server from ISC that OPNsense uses to hand out addresses; netOrk manages its subnets and reservations.',
de: 'Der DHCP-Server von ISC, mit dem OPNsense Adressen vergibt; netOrk verwaltet seine Subnetze und Reservierungen.',
},
match: ['Kea'],
},
{
id: 'winrm',
category: 'networking',
display: 'WinRM',
fullName: { en: 'Windows Remote Management', de: 'Windows Remote Management' },
definition: {
en: 'Microsoft\'s remote management protocol for Windows hosts, the Windows counterpart to SSH for automation.',
de: 'Microsofts Protokoll zur Fernverwaltung von Windows-Hosts, das Windows-Gegenstück zu SSH für Automatisierung.',
},
match: ['WinRM'],
},
{
id: 'lapi',
category: 'security',
display: 'LAPI',
fullName: { en: 'CrowdSec Local API', de: 'CrowdSec Local API' },
definition: {
en: 'The CrowdSec service that collects what its agents detect and holds the resulting ban decisions for one site or host.',
de: 'Der CrowdSec-Dienst, der sammelt, was seine Agenten erkennen, und die daraus folgenden Sperrentscheidungen für einen Standort oder Host hält.',
},
match: ['LAPI'],
},
{
id: 'nvd',
category: 'security',
+156 -16
View File
@@ -60,7 +60,7 @@ const en = {
body: 'Define desired state in netOrk. On every poll, device config is compared against it. Drifted devices get a warning; a one-click fix stream applies the correction and shows you live SSH output.',
},
driversHeading: 'Works with your hardware',
driversSub: 'netOrk ships with custom NAPALM drivers for 11 device types, plus all built-in NAPALM drivers. New drivers follow a documented registration pattern.',
driversSub: 'netOrk ships with custom NAPALM drivers for 15 device types, plus the built-in NAPALM drivers. New drivers follow a documented registration pattern.',
driversLink: 'Full driver reference →',
screenshot1: {
heading: 'Device detail at a glance',
@@ -109,12 +109,17 @@ const en = {
title: 'Device Management',
items: [
'CRUD for devices with credential profiles and SSH key management',
'Interactive Web-SSH console — full terminal session to any device straight from the browser, no separate SSH client needed',
'Web SSH terminal to any device straight from the browser — sessions log in with each user\'s own SSH key, never with the device\'s shared account; opened and refused sessions are recorded',
'SSH sessions are windows, not dialogs: move and resize them, run several at once, park them in the session bar or dock one beside the page — they survive navigating away',
'Per-device poll intervals (minutes) or manual-only',
'Status tracking: planned / staged / active / decommissioning / offline / disabled',
'Vendor / model / OS auto-populated from NAPALM get_facts()',
'Site assignment with FK to structured Site records',
'AP Profile assignment for grouped OpenWRT config',
'A device can hold several roles at once — a NAS that also runs VMs is storage and hypervisor, and shows the tabs for both',
'One device per address per site: adding a duplicate is refused with the name of the device that already holds the address',
'Devices and sites carry a business criticality that feeds into vulnerability ranking',
'Device pages list their sections beside the facts; pin a networking section as a second panel, jump anywhere with ⌘J',
],
},
{
@@ -124,6 +129,9 @@ const en = {
'Device fingerprinting: vendor + platform confidence scoring',
'FQDN resolution (reverse DNS)',
'Manual adoption from scan results — no auto-create to avoid inventory noise',
'Discovery jobs in a sortable, filterable table, grouped per site with the satellite that serves it',
'LAN Scan: ping sweep from netOrk, every site satellite and every firewall at once; results appear live with MAC address and manufacturer, and a finished scan becomes a discovery job in one step',
'A scan suggests the vantage point that can actually see the network you picked, and says which one could have when a source comes back empty',
],
},
{
@@ -165,7 +173,7 @@ const en = {
title: 'Networking & Inventory',
items: [
'Interface browser with IPv4/IPv6 addresses, MAC, speed, MTU',
'LLDP neighbor discovery and topology graph',
'LLDP neighbor discovery and topology graph — links worked out from switch MAC tables are drawn too (dashed), so devices that do not speak LLDP are connected as well',
'ARP table and DHCP lease browser per device',
'Subnet browser with interface-to-subnet assignments',
'VLAN list grouped by site; per-VLAN device membership view',
@@ -173,6 +181,27 @@ const en = {
'Per-SSID MAC access control lists (whitelist / blacklist) pushed to every AP broadcasting the SSID, quick-add straight from the Connected Clients list',
'MAC ACL state is a first-class drift item — covered by the same drift detection, scheduled auto-fix, and warning aggregation as any other config drift',
'Dedicated Access Control Lists tab on the Wireless page listing every SSID with its ACL editor inline',
'Radio problems between the access points of a site — several APs crowding the same spectrum — are reported, which no single AP\'s configuration could reveal',
],
},
{
title: 'DHCP',
items: [
'DHCP reservations managed in netOrk: import what the firewall already has in one step, see the diff, then apply',
'Checked before writing: no address claimed twice, no device listed twice, every address inside the subnet it is listed under',
'DHCP subnets (Kea on OPNsense) with their options and search domains, picked up by the regular poll',
'Settings that quietly break a network are refused up front — a search domain next to a public resolver, a bare "local" entry, a missing gateway',
'Applying only adds and updates; anything configured by hand on the firewall is left alone',
],
},
{
title: 'Managed Services',
items: [
'Every container-based service across all devices, with its endpoints, TLS certificates and access rules',
'Compose editor per service: secrets are masked, saving takes a backup snapshot, redeploying is a separate confirmed step',
'Zoraxy reverse proxy: vhost endpoints listed and editable, written straight back to the proxy',
'PostgreSQL containers list their databases with owner, size and encoding',
'Containers still running a superseded image are flagged; "Fix now" recreates them',
],
},
{
@@ -180,25 +209,29 @@ const en = {
items: [
'Config drift detection: desired state (DB) vs device state (poll snapshot)',
'One-click drift fix stream with live SSH output in the browser',
'Fix every drifted access point in one go: sites in parallel, the devices of a site one after another, so a change never takes a whole location down',
'netOrk writes to a device only where you asked it to — with automatic drift correction off for a profile, nothing is changed, including inside a scheduled fix window',
'UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)',
'AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port',
'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer',
'One-click config restore for OPNsense from any prior snapshot',
'Unauthorized configuration changes are surfaced as a device warning',
'netOrk\'s own config pushes (drift fixes, ACL provisioning) are recognized and auto-accepted as the new baseline — never mistaken for an unauthorized change',
'Firewall profiles scoped per site and compared against a live OPNsense device (Diff tab); applying writes the changes step by step and never deletes anything automatically',
],
},
{
title: 'Configuration Automation (Ansible)',
items: [
'Reusable Ansible roles and playbooks stored and edited directly in netOrk — no separate git checkout',
'11 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban',
'16 built-in roles ready to assign: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, stalwart (mail), bulwark (webmail), searxng, postiz, listmonk, wireguard, fail2ban',
'Each role states what it needs from a machine; a host that is too small is refused with the reason, before anything is built',
'Automatic dependency resolution — assigning docker pulls in base automatically, no manual role ordering',
'Built-in roles can\'t be deleted but are fully editable; customizations survive upgrades, and only untouched files auto-heal on bugfixes',
'ansible-doc-backed autocomplete while writing roles and playbooks',
'Upload your own role as an archive',
'Device-level role assignment with a dedicated Ansible tab on the device detail page',
'Run history per device, snapshotting the exact role/playbook content that was executed',
'Run history per device, snapshotting the exact role/playbook content that was executed — each run\'s full log can be opened',
'Wired into VM provisioning: assign roles at VM-creation time and they run automatically after boot',
],
},
@@ -229,13 +262,26 @@ const en = {
'SNMP health metrics (CPU, memory, interface counters) via get_health_metrics()',
'Per-device warning system with severity levels (error / warning / info)',
'One-click Ack on any warning — clears it immediately and logs the action; config-change warnings accept the current state as the new baseline',
'Docker container and image status (Proxmox/Linux)',
'Docker container and image status (Linux, OpenMediaVault, QNAP)',
'Service status and start/stop/restart (systemd)',
'VM/container list with OS device cross-linking (Proxmox)',
'Per-device availability windows — suppress OFFLINE status and poll-failure warnings during expected downtime (e.g. a nightly power-off); opt-in, unconfigured devices are unaffected',
'OPNsense: BGP neighbor status polling and display, with a peer-down warning',
'OPNsense: TLS certificate monitoring for the Trust store, with expiring-soon / expired warnings',
'OPNsense: Dynamic DNS service-down warning (os-ddclient)',
'Service checks about once a minute: DNS, time servers (including ones that answer but lost sync), VPN tunnels, core daemons and gateways — derived from what netOrk already knows, nothing to set up',
'A check reports after three failures in a row; checks can run from a site satellite, including a DHCP check from inside the local network',
'Site reachability: when the tunnel to a site is down, polling there pauses, one warning names the tunnel, and every device is polled again the moment it returns',
],
},
{
title: 'Notifications',
items: [
'Signal messages for everything netOrk watches — failed devices, unreachable sites, expiring certificates, dead tunnels, failed automation runs',
'Each person registers their own number; administrators connect netOrk to Signal once with a QR code',
'Kept quiet on purpose: one message per site outage instead of one per device, a daily summary for recurring items, bundling beyond an hourly limit',
'Quiet hours per number with emergencies still getting through; mute any kind of message for two hours or for good',
'A history of every notification, including the ones netOrk chose not to send and why',
],
},
{
@@ -243,12 +289,35 @@ const en = {
items: [
'Configurable, shareable dashboards — build your own from a widget picker instead of a fixed layout',
'WYSIWYG grid-layout editor: drag, resize, and arrange widgets on a canvas',
'13 widget types: stats, device warnings, recently updated devices, network topology, EOL status, config drift summary, Wazuh security alerts, audit log activity, discovery jobs status, upcoming scheduled actions, DNS zones overview, site overview, config snapshot history',
'18 widget types: stats, device warnings, recently updated devices, network topology, EOL status, config drift summary, Wazuh security alerts, audit log activity, discovery jobs status, upcoming scheduled actions, DNS zones overview, site overview, config snapshot history, managed services, certificate expiry, outdated Docker images, firewall profile deployment status, service checks',
'Multi-instance widgets with independent per-widget settings, e.g. two warnings widgets scoped to different sites',
'Share a dashboard with specific users; recipients can subscribe to always see the owner\'s live version, or clone it into their own editable copy',
'Favorite dashboards for quick access from the main menu; set any dashboard as your home view',
],
},
{
title: 'Security Assessment',
items: [
'Every device has a Security tab: TLS and SSH configuration graded A to F, installed software matched against known vulnerabilities, configuration checked against hardening benchmarks — nothing to install on the device',
'Container images are inventoried and matched against the same data, so a long-running container is no blind spot',
'Ratings reflect the device, not only the published score: lowered when a flaw needs local access, sits in a trusted network, or affects software that is not running or a kernel that is not booted; raised when it is exploited in the wild',
'A reboot comes with numbers: the vulnerabilities on the running kernel that booting the installed newer one would clear',
'Exposure: which less-trusted networks reach a device and on which ports, read from the firewall rules; what the internet sees of your public addresses and whether one is reported for abuse',
'Deeper scans on demand — a hardening audit of the host and a web scan of its management interface',
'Vulnerability data comes from the netOrk Knowledge Base and needs a licence; netOrk keeps a local copy and never tells it what you have installed',
],
},
{
title: 'Vulnerability Management',
items: [
'Triage queue across every device: one row per vulnerability, ordered by remediation deadline, known exploitation, severity, likelihood, asset criticality and spread — each row says why it is where it is',
'Filters for exploited, overdue and patch available; hardening findings without a CVE have their own list',
'Decisions: not applicable (with the standard reasons an auditor\'s tooling reads), accept the risk until a date, defer until a date, fixed — per device, site, device kind or everywhere, the most specific one wins',
'Every decision needs a reason in your own words; accepting a risk or declaring something not applicable needs a permission operators do not have',
'Deferred and accepted items come back on their date by themselves, sooner if the vulnerability becomes exploited; ignored ones are marked overdue',
'Fixes close themselves: a daily reassessment closes a fix that two assessments in a row no longer find, and reopens one that comes back',
],
},
{
title: 'Security Integrations',
items: [
@@ -303,7 +372,8 @@ const en = {
'RBAC with four built-in roles and custom permission sets — access control evidence',
'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))',
'EOL Tracking plugin flags devices on unsupported firmware/OS via endoflife.date — supply chain security baseline (Art. 21 (2d))',
'Wazuh CVE counts by severity (critical / high / medium) linked to each device record',
'Vulnerability handling with evidence: every triage decision carries a reason, a date and who made it, and is written to the audit log (Art. 21 (2e))',
'Terminal sessions are attributable to a person — each user logs in with their own key, and opened and refused sessions are recorded (Art. 21 (2i))',
'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))',
'Config drift tracking: desired state vs. polled state — detect unauthorized changes',
'Security agent coverage report: which devices have Wazuh, Graylog, CrowdSec active',
@@ -485,7 +555,7 @@ const de: Translations = {
body: 'Sollzustand in netOrk definieren. Bei jeder Abfrage wird die Gerätekonfiguration damit verglichen. Abweichende Geräte erhalten eine Warnung; ein Ein-Klick-Fix-Stream wendet die Korrektur an und zeigt den SSH-Output live im Browser.',
},
driversHeading: 'Funktioniert mit deiner Hardware',
driversSub: 'netOrk liefert eigene NAPALM-Treiber für 11 Gerätetypen, plus alle integrierten NAPALM-Treiber. Neue Treiber folgen einem dokumentierten Registrierungsmuster.',
driversSub: 'netOrk liefert eigene NAPALM-Treiber für 15 Gerätetypen, plus die integrierten NAPALM-Treiber. Neue Treiber folgen einem dokumentierten Registrierungsmuster.',
driversLink: 'Vollständige Treiberreferenz →',
screenshot1: {
heading: 'Gerätedetails auf einen Blick',
@@ -534,12 +604,17 @@ const de: Translations = {
title: 'Geräteverwaltung',
items: [
'CRUD für Geräte mit Credential-Profilen und SSH-Schlüsselverwaltung',
'Interaktive Web-SSH-Konsole — vollständige Terminal-Sitzung zu jedem Gerät direkt im Browser, kein separater SSH-Client nötig',
'Web-SSH-Terminal zu jedem Gerät direkt im Browser — Sitzungen melden sich mit dem eigenen SSH-Schlüssel des Benutzers an, nie mit dem geteilten Gerätekonto; geöffnete und verweigerte Sitzungen werden protokolliert',
'SSH-Sitzungen sind Fenster statt Dialoge: verschieben, Größe ändern, mehrere parallel, in der Sitzungsleiste parken oder neben der Seite andocken — sie überstehen den Seitenwechsel',
'Konfigurierbare Poll-Intervalle (Minuten) oder nur manuell',
'Statusverfolgung: geplant / bereitgestellt / aktiv / außer Betrieb / offline / deaktiviert',
'Hersteller / Modell / OS automatisch befüllt über NAPALM get_facts()',
'Standortzuweisung über FK zu strukturierten Standortdatensätzen',
'AP-Profil-Zuweisung für gruppierte OpenWRT-Konfiguration',
'Ein Gerät kann mehrere Rollen zugleich haben — ein NAS, das auch VMs betreibt, ist Storage und Hypervisor und zeigt die Tabs für beides',
'Ein Gerät pro Adresse und Standort: ein Duplikat wird mit dem Namen des Geräts abgelehnt, das die Adresse bereits hat',
'Geräte und Standorte tragen eine geschäftliche Kritikalität, die in die Schwachstellen-Priorisierung einfließt',
'Geräteseiten listen ihre Bereiche neben den Fakten; einen Netzwerk-Bereich als zweites Panel anheften, mit ⌘J überallhin springen',
],
},
{
@@ -549,6 +624,9 @@ const de: Translations = {
'Geräte-Fingerprinting: Hersteller + Plattform mit Confidence-Score',
'FQDN-Auflösung (Reverse DNS)',
'Manuelle Übernahme aus Scan-Ergebnissen — kein Auto-Create, um Inventar-Rauschen zu vermeiden',
'Discovery-Jobs in einer sortier- und filterbaren Tabelle, gruppiert nach Standort mit dem zuständigen Satellite',
'LAN-Scan: Ping-Sweep gleichzeitig von netOrk, jedem Standort-Satellite und jeder Firewall; Ergebnisse erscheinen live mit MAC-Adresse und Hersteller, ein fertiger Scan wird mit einem Schritt zum Discovery-Job',
'Ein Scan schlägt den Standpunkt vor, der das gewählte Netz tatsächlich sieht, und nennt bei einer leeren Quelle den, der es hätte sehen können',
],
},
{
@@ -590,7 +668,7 @@ const de: Translations = {
title: 'Netzwerk & Inventar',
items: [
'Schnittstellen-Browser mit IPv4/IPv6-Adressen, MAC, Geschwindigkeit, MTU',
'LLDP-Nachbarn-Erkennung und Topologie-Graph',
'LLDP-Nachbarn-Erkennung und Topologie-Graph — aus Switch-MAC-Tabellen abgeleitete Verbindungen werden mitgezeichnet (gestrichelt), sodass auch Geräte ohne LLDP verbunden erscheinen',
'ARP-Tabelle und DHCP-Lease-Browser pro Gerät',
'Subnetz-Browser mit Schnittstellen-zu-Subnetz-Zuordnungen',
'VLAN-Liste gruppiert nach Standort; VLAN-Mitgliedsansicht pro Gerät',
@@ -598,6 +676,27 @@ const de: Translations = {
'MAC-Zugriffskontrolllisten pro SSID (Whitelist / Blacklist), gepusht auf jeden AP, der die SSID ausstrahlt — Schnell-Hinzufügen direkt aus der Liste der verbundenen Clients',
'MAC-ACL-Zustand ist ein vollwertiges Drift-Item — abgedeckt von derselben Drift-Erkennung, geplanten Auto-Fixes und Warnungsaggregation wie jeder andere Config-Drift',
'Eigener Access-Control-Lists-Tab auf der Wireless-Seite, listet jede SSID mit ihrem ACL-Editor inline',
'Funkprobleme zwischen den Access Points eines Standorts — mehrere APs im selben Spektrum — werden gemeldet; die Konfiguration eines einzelnen APs könnte das nie zeigen',
],
},
{
title: 'DHCP',
items: [
'DHCP-Reservierungen in netOrk verwalten: Vorhandenes von der Firewall in einem Schritt importieren, Diff ansehen, dann anwenden',
'Vor dem Schreiben geprüft: keine Adresse doppelt vergeben, kein Gerät doppelt, jede Adresse im Subnetz, unter dem sie steht',
'DHCP-Subnetze (Kea auf OPNsense) mit Optionen und Suchdomänen, vom regulären Poll übernommen',
'Einstellungen, die ein Netz still kaputtmachen, werden vorab abgelehnt — Suchdomäne neben öffentlichem Resolver, ein nackter „local"-Eintrag, fehlendes Gateway',
'Anwenden ergänzt und aktualisiert nur; von Hand auf der Firewall Eingerichtetes bleibt unberührt',
],
},
{
title: 'Managed Services',
items: [
'Jeder containerbasierte Dienst über alle Geräte, mit Endpunkten, TLS-Zertifikaten und Zugriffsregeln',
'Compose-Editor pro Dienst: Geheimnisse maskiert, Speichern legt einen Backup-Snapshot an, Redeploy ist ein separater, bestätigter Schritt',
'Zoraxy-Reverse-Proxy: vhost-Endpunkte gelistet und bearbeitbar, direkt in den Proxy zurückgeschrieben',
'PostgreSQL-Container listen ihre Datenbanken mit Eigentümer, Größe und Encoding',
'Container, die noch ein veraltetes Image ausführen, werden markiert; „Fix now" erstellt sie neu',
],
},
{
@@ -605,25 +704,29 @@ const de: Translations = {
items: [
'Konfigurationsdrift-Erkennung: Sollzustand (DB) vs. Gerätezustand (Poll-Snapshot)',
'Ein-Klick-Drift-Fix-Stream mit Live-SSH-Output im Browser',
'Alle abweichenden Access Points auf einmal korrigieren: Standorte parallel, die Geräte eines Standorts nacheinander, damit nie ein ganzer Standort ausfällt',
'netOrk schreibt nur dort auf ein Gerät, wo es darum gebeten wurde — ist die automatische Drift-Korrektur für ein Profil aus, ändert sich nichts, auch nicht im geplanten Fix-Fenster',
'UCI-basierter Config-Push für OpenWRT (VLAN-Namen, SSID-Einstellungen, Radio-Konfiguration)',
'AP-Profil-System: Ländercode, HT/VHT-Modus, 802.11r, NTP, Syslog, SSH-Port',
'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer',
'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot',
'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt',
'netOrks eigene Config-Pushes (Drift-Fixes, ACL-Provisioning) werden erkannt und automatisch als neue Baseline akzeptiert — nie mit einer nicht autorisierten Änderung verwechselt',
'Firewall-Profile pro Standort und im Vergleich mit einer echten OPNsense (Diff-Tab); Anwenden schreibt die Änderungen Schritt für Schritt und löscht nie automatisch etwas',
],
},
{
title: 'Konfigurationsautomatisierung (Ansible)',
items: [
'Wiederverwendbare Ansible-Rollen und -Playbooks, direkt in netOrk gespeichert und bearbeitet — kein separates Git-Checkout',
'11 eingebaute Rollen sofort zuweisbar: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, wireguard, fail2ban',
'16 eingebaute Rollen sofort zuweisbar: base, ubuntu, docker, adguard, zoraxy, portainer, watchtower, uptime-kuma, vaultwarden, stalwart (Mail), bulwark (Webmail), searxng, postiz, listmonk, wireguard, fail2ban',
'Jede Rolle nennt, was sie von einer Maschine braucht; ein zu kleiner Host wird mit Begründung abgelehnt, bevor etwas gebaut wird',
'Automatische Abhängigkeitsauflösung — die Zuweisung von docker zieht base automatisch nach, keine manuelle Rollen-Reihenfolge nötig',
'Eingebaute Rollen lassen sich nicht löschen, sind aber vollständig editierbar; Anpassungen überstehen Updates, nur unveränderte Dateien heilen bei Bugfixes automatisch nach',
'ansible-doc-gestützte Autovervollständigung beim Schreiben von Rollen und Playbooks',
'Eigene Rolle als Archiv hochladen',
'Rollenzuweisung auf Geräteebene mit eigenem Ansible-Tab in der Gerätedetailansicht',
'Lauf-Historie pro Gerät, mit Snapshot des tatsächlich ausgeführten Rollen-/Playbook-Inhalts',
'Lauf-Historie pro Gerät, mit Snapshot des tatsächlich ausgeführten Rollen-/Playbook-Inhalts — das vollständige Log jedes Laufs lässt sich öffnen',
'In VM-Provisioning eingebunden: Rollen bei VM-Erstellung zuweisen — sie laufen automatisch nach dem Boot',
],
},
@@ -654,13 +757,26 @@ const de: Translations = {
'SNMP-Gesundheitsmetriken (CPU, Speicher, Schnittstellenzähler) via get_health_metrics()',
'Gerätespezifisches Warnsystem mit Schweregraden (Fehler / Warnung / Info)',
'Ein-Klick-Ack für jede Warnung — löscht sie sofort und protokolliert die Aktion; bei Config-Change-Warnungen wird der aktuelle Zustand als neue Baseline akzeptiert',
'Docker-Container- und Image-Status (Proxmox/Linux)',
'Docker-Container- und Image-Status (Linux, OpenMediaVault, QNAP)',
'Service-Status und Start/Stop/Neustart (systemd)',
'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)',
'Verfügbarkeitsfenster pro Gerät — unterdrückt OFFLINE-Status und Poll-Fehler-Warnungen während erwarteter Ausfallzeiten (z. B. nächtliches Abschalten); Opt-in, unkonfigurierte Geräte sind nicht betroffen',
'OPNsense: BGP-Nachbarschaftsstatus-Polling und -Anzeige, mit Peer-Down-Warnung',
'OPNsense: TLS-Zertifikatsüberwachung für den Trust Store, mit „läuft bald ab"/„abgelaufen"-Warnungen',
'OPNsense: Dynamic-DNS-Service-Down-Warnung (os-ddclient)',
'Service-Checks etwa einmal pro Minute: DNS, Zeitserver (auch solche, die antworten, aber selbst nicht synchron sind), VPN-Tunnel, Kerndienste und Gateways — abgeleitet aus dem, was netOrk ohnehin weiß, nichts einzurichten',
'Ein Check meldet sich nach drei Fehlschlägen in Folge; Checks können vom Standort-Satellite laufen, inklusive DHCP-Check aus dem lokalen Netz',
'Standort-Erreichbarkeit: Ist der Tunnel zu einem Standort weg, pausiert das Polling dort, eine Warnung nennt den Tunnel, und sobald er zurück ist, wird jedes Gerät sofort neu abgefragt',
],
},
{
title: 'Benachrichtigungen',
items: [
'Signal-Nachrichten für alles, was netOrk überwacht — ausgefallene Geräte, unerreichbare Standorte, ablaufende Zertifikate, tote Tunnel, fehlgeschlagene Automatisierungsläufe',
'Jede Person hinterlegt ihre eigene Nummer; Administratoren verbinden netOrk einmalig per QR-Code mit Signal',
'Bewusst leise: eine Nachricht pro Standortausfall statt einer pro Gerät, eine Tageszusammenfassung für Wiederkehrendes, Bündelung ab einem Stundenlimit',
'Ruhezeiten pro Nummer, Notfälle kommen trotzdem durch; jede Nachrichtenart für zwei Stunden oder dauerhaft stummschalten',
'Eine Historie jeder Benachrichtigung, auch der nicht versendeten, mit Begründung',
],
},
{
@@ -668,12 +784,35 @@ const de: Translations = {
items: [
'Konfigurierbare, teilbare Dashboards — eigene Dashboards aus einer Widget-Auswahl bauen statt festes Layout',
'WYSIWYG-Grid-Layout-Editor: Widgets auf einem Canvas per Drag & Drop platzieren und in der Größe anpassen',
'13 Widget-Typen: Stats, Gerätewarnungen, kürzlich aktualisierte Geräte, Netzwerktopologie, EOL-Status, Konfigurationsdrift-Zusammenfassung, Wazuh-Sicherheitsalerts, Audit-Log-Aktivität, Discovery-Job-Status, anstehende geplante Aktionen, DNS-Zonen-Übersicht, Standortübersicht, Konfigurationssnapshot-Historie',
'18 Widget-Typen: Stats, Gerätewarnungen, kürzlich aktualisierte Geräte, Netzwerktopologie, EOL-Status, Konfigurationsdrift-Zusammenfassung, Wazuh-Sicherheitsalerts, Audit-Log-Aktivität, Discovery-Job-Status, anstehende geplante Aktionen, DNS-Zonen-Übersicht, Standortübersicht, Konfigurationssnapshot-Historie, Managed Services, Zertifikatsablauf, veraltete Docker-Images, Firewall-Profil-Deployment-Status, Service-Checks',
'Mehrfachinstanzen desselben Widgets mit unabhängigen Einstellungen pro Widget, z. B. zwei Warnungs-Widgets für unterschiedliche Standorte',
'Dashboard mit bestimmten Benutzern teilen; Empfänger können es abonnieren, um immer die aktuelle Version des Owners zu sehen, oder es als eigene, editierbare Kopie klonen',
'Dashboards als Favorit markieren für schnellen Zugriff über das Hauptmenü; jedes Dashboard als Home-Ansicht festlegen',
],
},
{
title: 'Sicherheitsbewertung',
items: [
'Jedes Gerät hat einen Security-Tab: TLS- und SSH-Konfiguration mit Note A bis F, installierte Software gegen bekannte Schwachstellen abgeglichen, Konfiguration gegen Härtungs-Benchmarks geprüft — nichts auf dem Gerät zu installieren',
'Container-Images werden inventarisiert und gegen dieselben Daten geprüft, ein lange laufender Container ist kein blinder Fleck',
'Die Bewertung richtet sich nach dem Gerät, nicht nur nach dem veröffentlichten Score: niedriger, wenn eine Lücke lokalen Zugriff braucht, im vertrauenswürdigen Netz liegt oder Software betrifft, die nicht läuft bzw. einen Kernel, der nicht gebootet ist; höher, wenn sie aktiv ausgenutzt wird',
'Ein Neustart kommt mit Zahlen: welche Schwachstellen des laufenden Kernels ein Boot in den bereits installierten neueren beseitigt',
'Exposition: welche weniger vertrauenswürdigen Netze ein Gerät auf welchen Ports erreichen, gelesen aus den Firewallregeln; was das Internet von den eigenen öffentlichen Adressen sieht und ob eine davon wegen Missbrauchs gemeldet ist',
'Tiefere Scans auf Abruf — ein Härtungs-Audit des Hosts und ein Web-Scan seiner Management-Oberfläche',
'Die Schwachstellendaten kommen aus der netOrk Knowledge Base und setzen eine Lizenz voraus; netOrk hält eine lokale Kopie und verrät ihr nie, was installiert ist',
],
},
{
title: 'Schwachstellenmanagement',
items: [
'Triage-Queue über alle Geräte: eine Zeile pro Schwachstelle, geordnet nach Behebungsfrist, bekannter Ausnutzung, Schweregrad, Wahrscheinlichkeit, Kritikalität und Verbreitung — jede Zeile sagt, warum sie dort steht',
'Filter für ausgenutzt, überfällig und Patch verfügbar; Härtungsbefunde ohne CVE haben eine eigene Liste',
'Entscheidungen: nicht zutreffend (mit den Standardgründen, die Audit-Werkzeuge lesen), Risiko akzeptieren bis, zurückstellen bis, behoben — pro Gerät, Standort, Geräteart oder global, die spezifischste gewinnt',
'Jede Entscheidung braucht eine Begründung in eigenen Worten; Risiko akzeptieren oder „nicht zutreffend" erfordert eine Berechtigung, die Operatoren nicht haben',
'Zurückgestelltes und Akzeptiertes kommt am Stichtag von selbst zurück, früher, wenn die Schwachstelle ausgenutzt wird; Liegengelassenes wird als überfällig markiert',
'Behebungen schließen sich selbst: eine tägliche Neubewertung schließt einen Fix, den zwei Bewertungen in Folge nicht mehr finden, und öffnet ihn wieder, wenn er zurückkommt',
],
},
{
title: 'Sicherheitsintegrationen',
items: [
@@ -728,7 +867,8 @@ const de: Translations = {
'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis',
'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))',
'EOL-Tracking-Plugin kennzeichnet Geräte mit nicht unterstützter Firmware/OS über endoflife.date — Supply-Chain-Sicherheits-Baseline (Art. 21 (2d))',
'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz',
'Schwachstellenbehandlung mit Nachweis: jede Triage-Entscheidung trägt Begründung, Datum und Entscheider und landet im Audit-Log (Art. 21 (2e))',
'Terminal-Sitzungen sind einer Person zuzuordnen — jeder meldet sich mit dem eigenen Schlüssel an, geöffnete und verweigerte Sitzungen werden protokolliert (Art. 21 (2i))',
'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))',
'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen',
'Security-Agent-Abdeckungsbericht: welche Geräte haben Wazuh, Graylog, CrowdSec aktiv',
+10 -6
View File
@@ -30,17 +30,21 @@ const FEATURES: Record<'en' | 'de', Item[]> = {
{ title: 'Device Management', body: 'CRUD for every device with credential profiles and SSH key management. Vendor, model, and OS auto-populate from NAPALM get_facts() — no manual data entry.' },
{ title: 'Config drift detection & one-click fix', body: 'Every poll compares device state against the desired state in netOrk. Drifted devices get a warning; fixing it streams live SSH output straight to the browser.' },
{ title: 'Git-backed config history', body: 'Every poll snapshots the config into a local Git repository — full history, side-by-side diffs between any two points in time, and one-click restore for OPNsense.' },
{ title: 'Ansible automation', body: '11 built-in roles (base, docker, adguard, wireguard, fail2ban, and more) with automatic dependency resolution. Write your own roles too, with full run history per device.' },
{ title: 'Ansible automation', body: '16 built-in roles (base, docker, adguard, wireguard, fail2ban, a mail server, and more) with automatic dependency resolution. Write your own roles too, with full run history per device.' },
{ title: 'VM Provisioning', body: 'Cloud-Init VMs on Proxmox straight from the hypervisor\'s VMs tab — pick an image, a VLAN, and an IP, and netOrk handles the DHCP reservation and Device linking.' },
{ title: 'Dashboards', body: 'Configurable, shareable dashboards built from 13 widgets on a WYSIWYG grid — replace the fixed layout with the view your team actually needs.' },
{ title: 'Dashboards', body: 'Configurable, shareable dashboards built from 18 widgets on a WYSIWYG grid — replace the fixed layout with the view your team actually needs.' },
{ title: 'Security assessment per device', body: 'TLS and SSH graded A to F, installed software and container images matched against known vulnerabilities, hardening benchmarks, and which networks can reach the device — without an agent on it.' },
{ title: 'Vulnerability triage with owners', body: 'One queue across all devices, ordered by what is exploited and overdue. Every decision needs a reason; accepting a risk needs a permission operators do not have, and fixes are verified by the next assessments.' },
],
de: [
{ title: 'Geräteverwaltung', body: 'CRUD für jedes Gerät mit Credential-Profilen und SSH-Schlüsselverwaltung. Hersteller, Modell und OS werden automatisch über NAPALM get_facts() befüllt — keine manuelle Eingabe.' },
{ title: 'Konfigurationsdrift-Erkennung & Ein-Klick-Fix', body: 'Bei jedem Poll wird der Gerätezustand mit dem Sollzustand in netOrk verglichen. Abweichende Geräte erhalten eine Warnung; der Fix streamt Live-SSH-Output direkt in den Browser.' },
{ title: 'Git-basierte Konfigurationshistorie', body: 'Bei jedem Poll wird die Konfiguration in ein lokales Git-Repository gesnapshottet — vollständige Historie, Side-by-Side-Diffs zwischen beliebigen Zeitpunkten und Ein-Klick-Restore für OPNsense.' },
{ title: 'Ansible-Automatisierung', body: '11 eingebaute Rollen (base, docker, adguard, wireguard, fail2ban und mehr) mit automatischer Abhängigkeitsauflösung. Eigene Rollen schreiben inklusive vollständiger Lauf-Historie pro Gerät.' },
{ title: 'Ansible-Automatisierung', body: '16 eingebaute Rollen (base, docker, adguard, wireguard, fail2ban, ein Mailserver und mehr) mit automatischer Abhängigkeitsauflösung. Eigene Rollen schreiben inklusive vollständiger Lauf-Historie pro Gerät.' },
{ title: 'VM-Provisioning', body: 'Cloud-Init-VMs auf Proxmox direkt aus dem VMs-Tab des Hypervisors — Image, VLAN und IP auswählen, netOrk übernimmt DHCP-Reservierung und Geräteverknüpfung.' },
{ title: 'Dashboards', body: 'Konfigurierbare, teilbare Dashboards aus 13 Widgets auf einem WYSIWYG-Grid — statt festem Layout die Ansicht, die euer Team wirklich braucht.' },
{ title: 'Dashboards', body: 'Konfigurierbare, teilbare Dashboards aus 18 Widgets auf einem WYSIWYG-Grid — statt festem Layout die Ansicht, die euer Team wirklich braucht.' },
{ title: 'Sicherheitsbewertung pro Gerät', body: 'TLS und SSH mit Note A bis F, installierte Software und Container-Images gegen bekannte Schwachstellen abgeglichen, Härtungs-Benchmarks, und welche Netze das Gerät erreichen — ohne Agent darauf.' },
{ title: 'Schwachstellen-Triage mit Verantwortlichen', body: 'Eine Queue über alle Geräte, geordnet nach Ausgenutztem und Überfälligem. Jede Entscheidung braucht eine Begründung; ein Risiko zu akzeptieren braucht eine Berechtigung, die Operatoren nicht haben, und Behebungen verifizieren die nächsten Bewertungen.' },
],
}
@@ -96,8 +100,8 @@ export default function ForItDepartment() {
</h2>
<p className="text-sm text-slate-400 leading-relaxed mb-4">
{lang === 'en'
? 'Custom NAPALM drivers for 11 device types, plus every built-in NAPALM driver.'
: 'Eigene NAPALM-Treiber für 11 Gerätetypen, plus alle integrierten NAPALM-Treiber.'}
? 'Custom NAPALM drivers for 15 device types, plus the built-in NAPALM drivers.'
: 'Eigene NAPALM-Treiber für 15 Gerätetypen, plus die integrierten NAPALM-Treiber.'}
</p>
<Link to="/drivers" className="text-sky-400 hover:text-sky-300 transition-colors text-sm font-medium">
{lang === 'en' ? 'Full driver reference →' : 'Vollständige Treiberreferenz →'}
+4
View File
@@ -33,6 +33,8 @@ const FEATURES: Record<'en' | 'de', Item[]> = {
{ title: 'Scheduled reboots & updates', body: 'Scheduled reboots for OpenWRT APs with per-site concurrency locking, and package updates scheduled or applied with one click.' },
{ title: 'Full audit log, filterable', body: 'Every action — who, when, what — filterable by date range, user, action, or resource, exportable to CSV or PDF.' },
{ title: 'Roles scoped to the job', body: 'Viewer/operator roles, or a custom permission set, hand out exactly the access support work needs — without granting engineer-level config rights.' },
{ title: 'Problems reach you on Signal', body: 'Failed devices, dead tunnels, expiring certificates — one message per outage instead of one per device, quiet hours per person, and any kind of message muted with one click.' },
{ title: 'Service checks every minute', body: 'DNS, time servers, VPN tunnels, core daemons and gateways are checked about once a minute, derived from what netOrk already knows — a dead resolver shows up in minutes, not at the next ticket.' },
],
de: [
{ title: 'Status auf einen Blick', body: 'Gerätespezifisches Warnsystem mit Schweregraden (Fehler / Warnung / Info); ein Dashboard-Warnungs-Widget zeigt jedes offene Problem standortübergreifend, ohne pro Gerät zu suchen.' },
@@ -41,6 +43,8 @@ const FEATURES: Record<'en' | 'de', Item[]> = {
{ title: 'Geplante Reboots & Updates', body: 'Geplante Neustarts für OpenWRT-APs mit standortbezogener Concurrency-Sperre, Paket-Updates geplant oder per Ein-Klick angewendet.' },
{ title: 'Vollständiges, filterbares Audit-Log', body: 'Jede Aktion — wer, wann, was — filterbar nach Datumsbereich, Benutzer, Aktion oder Ressource, exportierbar als CSV oder PDF.' },
{ title: 'Rollen passend zur Aufgabe', body: 'Betrachter-/Operator-Rollen oder ein eigener Berechtigungssatz geben genau den Zugriff, den Support-Arbeit braucht — ohne Engineer-Rechte für die Konfiguration.' },
{ title: 'Probleme kommen per Signal', body: 'Ausgefallene Geräte, tote Tunnel, ablaufende Zertifikate — eine Nachricht pro Ausfall statt einer pro Gerät, Ruhezeiten pro Person, und jede Nachrichtenart mit einem Klick stumm.' },
{ title: 'Service-Checks jede Minute', body: 'DNS, Zeitserver, VPN-Tunnel, Kerndienste und Gateways werden etwa einmal pro Minute geprüft, abgeleitet aus dem, was netOrk ohnehin weiß — ein toter Resolver fällt in Minuten auf, nicht erst beim nächsten Ticket.' },
],
}
+4
View File
@@ -33,6 +33,8 @@ const FEATURES: Record<'en' | 'de', Item[]> = {
{ title: 'A real audit trail to hand a client', body: 'Every orchestration action is logged — who, what, when — filterable and exportable to CSV or PDF. Evidence, not a verbal assurance.' },
{ title: 'Roles scoped per technician', body: 'Custom roles control exactly what each technician can do, from read-only visibility to full config access, per engagement.' },
{ title: 'Self-hosted, no per-seat SaaS', body: 'Docker Compose deployment, no telemetry, no cloud dependency — runs on your infrastructure or a client\'s, not a vendor\'s.' },
{ title: 'A dropped client site is one warning', body: 'When the tunnel to a site goes down, netOrk pauses polling there instead of turning every device red, names the tunnel, and re-polls everything the moment it is back.' },
{ title: 'Checks from inside the client network', body: 'Service checks run from the site satellite, so DNS, time servers and gateways are tested from where the client sits — including a DHCP check that only works on the local network.' },
],
de: [
{ title: 'Satellite-Deployments', body: 'Ein leichtgewichtiger Docker-Agent an einem Kundenstandort, den netOrk nicht direkt erreicht — pollt Geräte lokal und synct Ergebnisse per HTTPS zurück an Central. In einem Ablauf per VM-Provisioning deployt.' },
@@ -41,6 +43,8 @@ const FEATURES: Record<'en' | 'de', Item[]> = {
{ title: 'Ein echter Audit-Trail für den Kunden', body: 'Jede Orchestrierungsaktion wird protokolliert — wer, was, wann — filterbar und exportierbar als CSV oder PDF. Beleg statt mündlicher Zusicherung.' },
{ title: 'Rollen pro Techniker', body: 'Benutzerdefinierte Rollen legen genau fest, was jeder Techniker darf — von reinem Lesezugriff bis vollem Konfigurationszugriff, je nach Einsatz.' },
{ title: 'Self-hosted, kein Pro-Seat-SaaS', body: 'Docker-Compose-Deployment, keine Telemetrie, keine Cloud-Abhängigkeit — läuft auf eurer Infrastruktur oder der eines Kunden, nicht bei einem Anbieter.' },
{ title: 'Ein ausgefallener Kundenstandort ist eine Warnung', body: 'Fällt der Tunnel zu einem Standort, pausiert netOrk dort das Polling, statt jedes Gerät rot zu färben, nennt den Tunnel und fragt alles sofort neu ab, sobald er zurück ist.' },
{ title: 'Checks aus dem Kundennetz heraus', body: 'Service-Checks laufen vom Standort-Satellite, DNS, Zeitserver und Gateways werden also von dort geprüft, wo der Kunde sitzt — inklusive eines DHCP-Checks, der nur im lokalen Netz funktioniert.' },
],
}
+4 -6
View File
@@ -14,11 +14,11 @@ const REQUIREMENTS: Record<'en' | 'de', Requirement[]> = {
{ article: 'Art. 21 (2b)', label: 'Incident handling', coverage: 'partial', netork: 'Wazuh alert history, CrowdSec decisions, and Graylog syslog per device surface incidents at the network layer. A structured incident record with NIS2 Art. 23 reporting timers is on the roadmap.' },
{ article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'partial', netork: 'Every poll captures a configuration snapshot into a local Git repository — full history, a side-by-side diff viewer between any two points in time, and one-click restore for OPNsense. Backup/recovery for full device state beyond configuration is out of scope.' },
{ article: 'Art. 21 (2d)', label: 'Supply chain security', coverage: 'covered', netork: 'Vendor, model, firmware, and OS version are tracked per device after every poll. The EOL Tracking plugin checks each device\'s OS version against the endoflife.date API daily and flags unsupported or soon-to-be-unsupported software.' },
{ article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Per-device update status and installed package list tracked on every poll. Wazuh CVE counts by severity (critical / high / medium) linked directly to each device record. CVE cross-reference against NVD/OSV (without Wazuh) is on the roadmap.' },
{ article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Installed software and container images on every device are matched against known vulnerabilities, rated by what each flaw means on that device. A triage queue records a decision per vulnerability — not applicable, accepted until, deferred until, fixed — each with a reason, a date and who decided, written to the audit log. Deferrals come back by themselves, and a daily reassessment verifies fixes. Vulnerability data requires a netOrk licence.' },
{ article: 'Art. 21 (2f)', label: 'Assessing effectiveness of cybersecurity measures', coverage: 'partial', netork: 'The audit log records all orchestration actions. A per-site compliance dashboard (on roadmap) will aggregate security agent coverage, drift status, and patch metrics into a single view.' },
{ article: 'Art. 21 (2g)', label: 'Basic cyber hygiene & cybersecurity training', coverage: 'na', netork: 'Out of scope for a network orchestration platform. Training and hygiene policies are handled at the organizational level.' },
{ article: 'Art. 21 (2h)', label: 'Access control, asset management, human resources security', coverage: 'covered', netork: 'Full device inventory maintained automatically via discovery and continuous polling. RBAC with four built-in roles (viewer / operator / engineer / administrator) and custom role combinations. Complete audit log of all orchestration actions, filterable by date range, user, action, or resource — export to CSV or PDF for audit submissions.' },
{ article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'covered', netork: 'TOTP-based MFA for netOrk user accounts — authenticator app at login, backup codes for emergencies, session invalidation on TOTP changes, enforceable per role.' },
{ article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'covered', netork: 'TOTP-based MFA for netOrk user accounts — authenticator app at login, backup codes for emergencies, session invalidation on TOTP changes, enforceable per role. Terminal sessions to devices log in with each user\'s own SSH key, never a shared account, and opened and refused sessions are recorded.' },
{ article: 'Art. 21 (2j)', label: 'Physical and environmental security', coverage: 'na', netork: 'Out of scope. Physical security of the infrastructure hosting netOrk is an organizational and facility concern.' },
],
de: [
@@ -26,11 +26,11 @@ const REQUIREMENTS: Record<'en' | 'de', Requirement[]> = {
{ article: 'Art. 21 (2b)', label: 'Bewältigung von Sicherheitsvorfällen', coverage: 'partial', netork: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen und Graylog-Syslog pro Gerät decken Vorfälle auf Netzwerkebene auf. Ein strukturierter Incident-Datensatz mit NIS2 Art. 23 Melde-Timern ist auf der Roadmap.' },
{ article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'partial', netork: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert — vollständige Historie, ein Side-by-Side-Diff-Viewer zwischen beliebigen Zeitpunkten und Ein-Klick-Restore für OPNsense. Backup/Recovery für den vollständigen Gerätezustand über die Konfiguration hinaus liegt außerhalb des Scopes.' },
{ article: 'Art. 21 (2d)', label: 'Supply-Chain-Sicherheit', coverage: 'covered', netork: 'Hersteller, Modell, Firmware und OS-Version werden nach jedem Poll pro Gerät erfasst. Das EOL-Tracking-Plugin gleicht die OS-Version jedes Geräts täglich mit der endoflife.date-API ab und kennzeichnet nicht mehr oder bald nicht mehr unterstützte Software.' },
{ article: 'Art. 21 (2e)', label: 'Schwachstellenbehandlung bei Erwerb, Entwicklung & Wartung', coverage: 'covered', netork: 'Update-Status und installierte Paketliste pro Gerät werden bei jedem Poll erfasst. Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) direkt mit jedem Gerätedatensatz verknüpft. CVE-Abgleich gegen NVD/OSV (ohne Wazuh) ist auf der Roadmap.' },
{ article: 'Art. 21 (2e)', label: 'Schwachstellenbehandlung bei Erwerb, Entwicklung & Wartung', coverage: 'covered', netork: 'Installierte Software und Container-Images jedes Geräts werden gegen bekannte Schwachstellen abgeglichen und danach bewertet, was die Lücke auf genau diesem Gerät bedeutet. Eine Triage-Queue hält pro Schwachstelle eine Entscheidung fest — nicht zutreffend, akzeptiert bis, zurückgestellt bis, behoben — jeweils mit Begründung, Datum und Entscheider, im Audit-Log protokolliert. Zurückgestelltes kommt von selbst zurück, eine tägliche Neubewertung verifiziert Behebungen. Die Schwachstellendaten setzen eine netOrk-Lizenz voraus.' },
{ article: 'Art. 21 (2f)', label: 'Beurteilung der Wirksamkeit von Cybersicherheitsmaßnahmen', coverage: 'partial', netork: 'Das Audit-Log erfasst alle Orchestrierungsaktionen. Ein Compliance-Dashboard pro Standort (auf der Roadmap) wird Security-Agent-Abdeckung, Drift-Status und Patch-Metriken in einer Ansicht zusammenfassen.' },
{ article: 'Art. 21 (2g)', label: 'Grundlegende Cyberhygiene und Cybersicherheitsschulungen', coverage: 'na', netork: 'Außerhalb des Scopes einer Netzwerk-Orchestrierungsplattform. Schulungen und Hygiene-Richtlinien werden auf Organisationsebene gehandhabt.' },
{ article: 'Art. 21 (2h)', label: 'Zugangskontrolle, Asset-Management, Personalsicherheit', coverage: 'covered', netork: 'Vollständiges Geräteinventar automatisch über Discovery und kontinuierliches Polling gepflegt. RBAC mit vier integrierten Rollen (Betrachter / Operator / Ingenieur / Administrator) und benutzerdefinierten Rollenkombinationen. Vollständiges Audit-Log aller Orchestrierungsaktionen, filterbar nach Datumsbereich, Benutzer, Aktion oder Ressource — Export als CSV oder PDF für Audit-Einreichungen.' },
{ article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'covered', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten — Authenticator-App beim Login, Backup-Codes für Notfälle, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar.' },
{ article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'covered', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten — Authenticator-App beim Login, Backup-Codes für Notfälle, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar. Terminal-Sitzungen zu Geräten melden sich mit dem eigenen SSH-Schlüssel des Benutzers an, nie mit einem geteilten Konto; geöffnete und verweigerte Sitzungen werden protokolliert.' },
{ article: 'Art. 21 (2j)', label: 'Physische und umgebungsbezogene Sicherheit', coverage: 'na', netork: 'Außerhalb des Scopes. Die physische Sicherheit der Infrastruktur, die netOrk hostet, ist eine organisatorische und gebäudetechnische Angelegenheit.' },
],
}
@@ -108,12 +108,10 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
const COMING: Record<'en' | 'de', ComingItem[]> = {
en: [
{ title: 'CVE tracking per device', detail: 'Automatic cross-reference of installed packages against NVD / OSV — no Wazuh agent required.' },
{ title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, agent deployment, drift, syslog, audit activity.' },
{ title: 'Incident workflow', detail: 'Structured incident records with NIS2 Art. 23 reporting timers (24 h / 72 h) and external webhook delivery.' },
],
de: [
{ title: 'CVE-Tracking pro Gerät', detail: 'Automatischer Abgleich installierter Pakete gegen NVD / OSV — kein Wazuh-Agent erforderlich.' },
{ title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Agent-Deployment, Drift, Syslog, Audit-Aktivität.' },
{ title: 'Incident-Workflow', detail: 'Strukturierte Incident-Datensätze mit NIS2 Art. 23 Melde-Timern (24 h / 72 h) und externer Webhook-Zustellung.' },
],
+44 -10
View File
@@ -7,13 +7,30 @@ type Group = { label: string; items: Item[] }
const GROUPS: Record<'en' | 'de', Group[]> = {
en: [
{
label: 'Planned',
label: 'Next release',
items: [
{
title: 'CVE tracking per device',
detail: 'Cross-reference installed packages and OS versions against NVD / OSV. Surfaces "this device has 3 unpatched CVEs (CVSS ≥ 7)" without leaving netOrk.',
title: 'CrowdSec across sites',
detail: 'The CrowdSec plugin grows into its own section: every LAPI instance, decisions and alerts across sites, how many sites one address reached, bans inside your own subnets counted separately, and which internet-facing hosts nobody watches yet.',
},
{
title: 'Windows driver',
detail: 'Windows hosts over WinRM: facts, interfaces, ARP, routes and services, including service control.',
},
{
title: 'Single-use console tickets',
detail: 'The browser terminal opens with a one-time ticket instead of passing the session token in the WebSocket URL.',
nis2: true,
},
{
title: 'Honest reboots',
detail: 'A reboot request for a device whose driver cannot restart it is refused with a reason instead of being reported as done.',
},
],
},
{
label: 'Planned',
items: [
{
title: 'Compliance dashboard',
detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.',
@@ -37,8 +54,8 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
nis2: true,
},
{
title: 'Firewall profile management — rework',
detail: 'Push reusable firewall rule templates to OPNsense and OpenWRT devices. The existing implementation is being re-scoped from scratch — profile types, rule sets, and the push mechanism are all under review before further work lands.',
title: 'Firewall profile management — next steps',
detail: 'Per-site profiles with a diff against a live OPNsense and step-by-step apply shipped in 0.12. Profile types, OpenWrt as a target, and the push mechanism beyond that are still under review.',
},
],
},
@@ -71,13 +88,30 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
],
de: [
{
label: 'Geplant',
label: 'Nächstes Release',
items: [
{
title: 'CVE-Tracking pro Gerät',
detail: 'CVE-Abgleich mit installierten Paketen und OS-Versionen über NVD / OSV. Zeigt „Dieses Gerät hat 3 ungepatchte CVEs (CVSS ≥ 7)" direkt in netOrk an.',
title: 'CrowdSec über alle Standorte',
detail: 'Das CrowdSec-Plugin wird ein eigener Bereich: jede LAPI-Instanz, Entscheidungen und Alerts über alle Standorte, wie viele Standorte eine Adresse erreicht hat, Sperren im eigenen Netz getrennt gezählt, und welche vom Internet erreichbaren Hosts noch niemand überwacht.',
},
{
title: 'Windows-Treiber',
detail: 'Windows-Hosts über WinRM: Fakten, Interfaces, ARP, Routen und Dienste, inklusive Dienststeuerung.',
},
{
title: 'Einmal-Tickets für die Konsole',
detail: 'Das Browser-Terminal öffnet mit einem einmal gültigen Ticket, statt das Sitzungstoken in der WebSocket-URL mitzugeben.',
nis2: true,
},
{
title: 'Ehrliche Neustarts',
detail: 'Eine Neustart-Anfrage für ein Gerät, dessen Treiber es nicht neu starten kann, wird mit Begründung abgelehnt, statt als erledigt gemeldet zu werden.',
},
],
},
{
label: 'Geplant',
items: [
{
title: 'Compliance-Dashboard',
detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.',
@@ -101,8 +135,8 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
nis2: true,
},
{
title: 'Firewall-Profile — Überarbeitung',
detail: 'Wiederverwendbare Firewall-Regel-Templates auf OPNsense- und OpenWRT-Geräte pushen. Die bestehende Implementierung wird von Grund auf neu bewertet — Profiltypen, Regelsätze und der Push-Mechanismus stehen vor der Weiterentwicklung auf dem Prüfstand.',
title: 'Firewall-Profile — nächste Schritte',
detail: 'Profile pro Standort mit Diff gegen eine echte OPNsense und schrittweisem Anwenden kamen mit 0.12. Profiltypen, OpenWrt als Ziel und der Push-Mechanismus darüber hinaus stehen noch auf dem Prüfstand.',
},
],
},