Home › Documentation › Uplivra Network Engineer Guide
Handbook · Network engineers and MSP engineersUplivra Network Engineer Guide
How to use Uplivra as a network engineer, step by step: switch ports, the network map, traffic flows, configuration backups, compare and safe restore, IPAM, VLANs and DHCP, path quality, capacity, logs and SNMP traps, packet capture, firmware upgrades and lifecycle, vulnerability scanning, and MSP routing basics.
Uplivra Technologies LLC · Handbook for Uplivra 26.10 · Updated 1 October 2026 · Latest version: https://uplivra.com/guides/network-engineer-guide.html
Before you start
This guide is for the engineers who look after switches, routers, firewalls and wireless. It assumes Uplivra is installed and your devices are added (see the Administrator Handbook). Menus are written like Network › Capacity.
What you need
| For | You need |
|---|---|
| Almost everything here | The Network Pro module on the devices you choose (Settings › License and modules), and an SNMP check on each switch, router and firewall |
| Configuration backups and restore | A Configuration backup check with an SSH login |
| Long log history, log search and log alerts | Log Intelligence (Network Pro alone includes a 7-day event viewer) |
| Recording SPAN ports all the time | Packet Capture and a packet capture collector |
| Firmware plans and end-of-life dates | Upgrade & Lifecycle |
| CVE matching | Vulnerability Scanning |
Saving an SNMP login once. Settings › Device logins › Add a login, choose SNMP v3 (username and passwords — recommended) or SNMP v1/v2c (community string), give it a short name such as office-switches, pick a device under Try it before saving, click Test this login, then Save login. Pick that login in each device's SNMP check. The settings must match the device, for example on Cisco IOS:
snmp-server group UPLIVRA v3 priv
snmp-server user uplivra UPLIVRA v3 auth sha <auth-password> priv aes 128 <privacy-password>
Allow the collector's address in any SNMP access list on the device.
Ports and links
Network › Ports and links shows every switch and router port in one place: in use or free, speed and duplex, VLANs, PoE, errors and discards, what's plugged in and how busy it is. Needs a look at the top lists the ports to check first, such as ports stuck at 100 Mb, error counters climbing, or an uplink near its limit.
On a switch's device page, the port table adds, with Network Pro:
- VLAN: the untagged (native) VLAN, and below it the tagged VLANs (
10, 20-29, 99). Read from Q-BRIDGE-MIB; on Cisco from CISCO-VTP-MIB and CISCO-VLAN-MEMBERSHIP-MIB. - PoE: watts per port (Cisco and MikroTik), and PoE power delivered against the switch's budget.
- Optic: receive and transmit light (dBm), temperature, voltage and bias for SFP, SFP+ and QSFP modules that report digital optical monitoring.
Two alert rules are added for optics: Optic out of range (device's own limits) and Optic running hot (above 70 °C for 15 minutes), next to Receive light low. Details: Network Pro in depth.
Duplex mismatch needs no setup: a port at half duplex, or late collisions on a port that says full duplex, raises a notice with the switch and port.
The network map
Network › Network map draws how firewalls, switches and access points connect, from LLDP, CDP and the MAC tables the devices report every 5 minutes. Click a device to open it.
- Turn on LLDP (or CDP) on your switches and routers, for example
lldp runon Cisco IOS. - Make sure each one has a working SNMP check.
- Devices seen on the map but not monitored are counted at the top: add them from Discovery.
- "Sits behind" from the map suggests parent devices. Click Use these: when a core switch goes down you then get one alert, not one for every device behind it.
What changed (on the map) lists neighbor changes newest first: New, Gone, Moved and MAC moved (a device moved to another access port). Filter by device and by time; a year is kept. A switch's page links to What moved on this device's ports.
Traffic flows (NetFlow, IPFIX, sFlow)
- Settings › Sites and collectors: at the site, tick Receive traffic flows here and keep the ports (2055 for NetFlow/IPFIX, 6343 for sFlow). Click Save.
- If the collector runs Ubuntu with a firewall:
sudo ufw allow 2055/udpandsudo ufw allow 6343/udp. - On the router or firewall, export NetFlow v5/v9, IPFIX or sFlow to the collector's address. For example, Cisco IOS Flexible NetFlow:
flow exporter UPLIVRA
destination 192.168.1.20
transport udp 2055
flow monitor UPLIVRA
exporter UPLIVRA
record netflow ipv4 original-input
interface GigabitEthernet0/0
ip flow monitor UPLIVRA input
- Within a few minutes, Network › Traffic flows shows top talkers, destinations, applications and conversations, by exporter and interface. Each exporting device's own page gets a Traffic flows section.
If nothing shows: the page says when an address sends flows but isn't a device in Uplivra yet (add it), or when Network Pro doesn't cover it (it needs a running SNMP check and a Network Pro license count that includes it).
Limits: 20,000 flow records a second per collector; the top 300 conversations per exporter per minute are kept and the rest added up as "Everything else". Network › Traffic flows › Limits shows what each collector received and dropped. Use sampling (1 in 100 or 1 in 1000) on busy links. Sampled flows are scaled up by the sampling rate. See Limits.
Configuration backups, compare and restore
Back up a device
- Save an SSH login under Settings › Device logins (a read-only account that can show the configuration is enough for backups).
- Open the device › Add a check › Configuration backup.
- Pick the SSH login, the Device type (or Detect automatically) and the SSH port. Command that prints the configuration is only for Custom command.
- Click Test these settings, then Save.
Supported device types: Cisco IOS / IOS-XE, Cisco Nexus (NX-OS), Cisco ASA / Firepower (ASA), Arista EOS, Aruba CX, HPE / Aruba ProCurve (ArubaOS-Switch), Juniper Junos, Fortinet FortiGate, MikroTik RouterOS, Ubiquiti EdgeOS / VyOS, Ubiquiti UniFi switch / gateway (shell), Palo Alto PAN-OS, SonicWall SonicOS, pfSense / OPNsense, Linux server (key files), and a custom command. Lines that change on every read (timestamps) are ignored, so a new version is kept only when something really changed.
See and compare versions
- Network › Configuration backups lists devices backed up, what changed in the last 7 days and what's failing.
- Open a device. Back up now takes one straight away.
- Under Versions, tick two and click Compare: added lines (+) and removed lines (−), with a link to the whole newer version.
- Give an important version a Label (for example "before the firewall migration") and Save label.
Configurations can contain passwords and keys, so only people allowed to see them can open them, and every view and download is in the audit log.
Restore a saved version (Cisco IOS/IOS-XE, Arista EOS, Juniper Junos)
Restore needs the Restore saved configurations to devices permission for two people. Only device families that can replace the whole configuration and undo it by themselves are allowed.
- Network › Configuration backups › the device › a version › Restore this version.
- Check the device now. Uplivra reads the current configuration. If it no longer matches the newest backup, you see exactly what differs and must tick a box to go on. You also see every line the restore changes.
- Send for approval. Say why, and choose whether to wait for a maintenance window covering the device.
- Another person approves under Network › Configuration backups › Restores. Nobody can approve their own.
- The collector checks the device once more, copies the file with SCP or SFTP (never TFTP, FTP or Telnet), applies it with an undo timer (10 minutes by default), reconnects and confirms. If it can't reconnect, the device undoes the change itself.
- A fresh backup is compared with the version you restored.
Device requirements (ip scp server enable and an archive path on Cisco; SCP or SFTP for the login on Arista and Junos) are in Restore a saved configuration.
IP addresses, VLANs and DHCP
IP addresses (IPAM)
Network › IP addresses shows what's in use in each subnet, worked out from your devices, discovery scans and the ARP tables of your routers and switches.
- Add a subnet for each network you own.
- Addresses outside your subnets lists ranges Uplivra has seen; click + to add the ones that are yours.
- Open a subnet to see used and free addresses, reservations and leases. Subnets warn when they're nearly full.
Set up a new network in one go
Network › IP addresses › Set up a network opens a wizard: the network and gateway, the next free VLAN ID, who does DHCP (nobody, the router, another server, or Uplivra's DHCP server on a collector), and a scan to find and optionally monitor what's there. Set the same VLAN on your switch ports and router; Uplivra keeps the list. See New networks, VLANs and Uplivra's DHCP server.
VLANs
Network › VLANs lists the VLAN IDs in use per site with their subnets, suggests the next free ID, and points out subnets that name a VLAN that isn't listed.
DHCP
- Uplivra's DHCP server (Network › DHCP server › Add a DHCP scope) runs on a Linux collector, with reservations, any option, network boot (PXE, UEFI, iPXE), a check for other DHCP servers before it serves, ping before offering, and a year of lease history.
- Windows DHCP and ISC Kea (Network › DHCP server › Other DHCP servers (Windows, Kea)): Uplivra reads scopes and leases (read-only), alerts at 90% full, and points out duplicate leases and clashes with IPAM reservations.
- Rogue DHCP watch: on your approved DHCP server's device, Add a check › DHCP server lists other approved servers; any other server that answers raises the Rogue DHCP server notice.
MAC addresses
Network › MAC addresses lists every MAC address Uplivra saw, with the maker, IP address, switch and port. See MAC addresses and makers.
Path quality and site-to-site tests
Network › Path quality shows every ping check measured from its site's collector: response time, jitter, packet loss, and an estimate of how a voice call would sound (MOS, 1 to 5; 4.0 and up is good, below 3.6 is poor). Add ping checks to the things that matter (internet gateway, SaaS front doors, branch routers) and watch them here.
Network › Site-to-site tests measures between two of your sites: a collector at one site sends small UDP probes to a collector at the other, which sends them straight back.
- Add a test: the sending site, the collector that answers, and its address as the sending site reaches it (VPN or WAN address).
- Keep the UDP port (4717), 50 probes, 20 ms apart, warn at 2% loss, every 5 minutes, or change them.
- Allow that UDP port from the sending collector to the answering one in any firewall or VPN policy.
Results show loss, latency, jitter and MOS, and appear on Path quality. The Voice quality poor rule warns when MOS stays below 3.6.
Capacity
Network › Capacity lists every interface your SNMP checks measure:
- 95th percentile in and out over 7, 30 and 90 days, and as a share of the link speed;
- Growth per 30 days (from each day's busy hour; needs at least 7 days of data);
- Days to 80% and 100% at that pace. Links reaching 80% within 90 days are highlighted.
Filter by site, device or name, sort by any column (soonest to fill first by default), and Download CSV for budget planning. Keep at least 90 days of 5-minute averages and 2 years of hourly averages under Settings › Data retention so the longer windows have data.
Logs and SNMP traps
Send syslog
- Settings › Sites and collectors: tick Receive syslog here at the site (port 514, UDP and TCP) and Save. For long retention, use a log collector on its own disk.
- Point each device's syslog at the collector's address. Cisco IOS example:
logging host 192.168.1.20 transport udp port 514
logging trap informational
service timestamps log datetime msec localtime show-timezone
- Messages appear under Logs within a minute.
What you get
- Network Pro includes an event viewer: messages from switches, routers, firewalls and access points for the last 7 days (up to 1,000,000 messages a day), filtered by sender, type, severity and time.
- Log Intelligence adds full-text search over all sources, longer history (kept encrypted and tamper-evident on the log collector), Saved searches, Live tail, Ask Intelligence for plain-English searches, and Log alerts: an alert when a search matches at least a number of messages within a time window (for example 5 failed sign-ins in 10 minutes). Checked every minute; the alert clears when the window is quiet.
- DNS names: the collector looks up each sender's PTR record in your internal DNS. Add reverse zones for your device networks to see names.
- Masking (Settings › Logs and masking) hides passwords and personal data before messages are stored or forwarded.
- Forwarding (Settings › Logs › Log forwarding) sends a copy to your SIEM (syslog over TLS, TCP or UDP), an HTTPS collector such as Splunk HEC, or S3 and Azure Blob. See Log forwarding.
SNMP traps
- Settings › Sites and collectors: tick Receive SNMP traps here at the site (port 162/UDP) and Save.
- Under Also accept these SNMP logins, tick the logins traps may use. Traps (v1, v2c or v3) must use one of the site's SNMP logins (a community or a v3 user); others are turned away.
- Point the device's traps at the collector. Cisco IOS example (v2c):
snmp-server host 192.168.1.20 version 2c <community>
snmp-server enable traps snmp linkdown linkup coldstart
Links going down, restarts, SNMP login failures, BGP sessions dropping and UPSs on battery raise alerts. If the site page says traps turned away, the device's trap community or user isn't one the site accepts: fix it on the device or tick its login.
Packet capture
A short capture on any collector (Network Pro)
- Packet capture in the menu. Choose the site, the interface, a capture filter (tcpdump style, for example
host 10.0.0.5 and port 443) and start. Captures last up to 10 minutes on a collector; by default only the first 128 bytes of each packet are kept. - The capture's page shows a summary and the Packets list, which takes Wireshark-style display filters (
ip.addr == 10.0.0.5,tcp.flags.reset == 1,dns). - Download for Wireshark gives the full file.
To see traffic between other devices, mirror a switch port to a spare collector port (a SPAN port, with no IP address) and tick This interface is plugged into a switch's SPAN / mirror port. Switch commands for Cisco, Aruba CX, Juniper EX and UniFi are in Set up a SPAN port.
Record all the time (packet capture collector)
A packet capture collector records SPAN ports around the clock in a rolling window, so you can pull the minutes before a problem: Packet captures › From a packet capture collector, then the last 5, 15 or 60 minutes or a from/to time. Capture automatically when an alert opens pulls 3 minutes before to 30 seconds after an alert, filtered to the device. Set-up: Set up a packet capture collector.
Starting captures needs the Start captures permission; seeing them needs See and download captures. Every capture and download is in the audit log.
Upgrades and lifecycle
Upgrades in the menu (Upgrade & Lifecycle module) has five parts:
| Tab | What it does |
|---|---|
| The device list | Each device's model and software version against your approved versions. Download CSV |
| Approved versions | The version you approve per model or family, and a minimum |
| End-of-life dates | End-of-sale, end-of-support and warranty dates per model; add them or import a spreadsheet |
| Firmware | Your repository of approved images (Upload an image) |
| Upgrade plans | Staged upgrades with before-and-after checks |
Run an upgrade
- Upload the image under Firmware.
- On the device list, tick the devices and click Plan an upgrade for the ticked devices (or Upgrade plans › New upgrade plan). Give it a name, the image and the target version. Put a pilot device or two in stage 1.
- Take before snapshots: version, checks, ports with a link, neighbors, routing peers and configuration.
- Get the image onto the devices, only over SSH (SFTP or SCP): Copy to devices has the collector fetch the image, check its SHA-256, sign in with the device's configuration backup login, check the SSH host key and copy it (for example to
flash:). Or Get SFTP/SCP access for a read-only account to that one image for 8 hours, once an administrator has turned on repository access. - Upgrade the devices with the vendor's steps (How to upgrade this device on each device gives a starting point), then Mark as upgrading.
- Check after compares with the before snapshot. Accept differences that are expected, then move to the next stage. Later stages can't start until earlier ones are finished.
- Complete the plan. The plan and its report export for change records.
Devices that can only download over HTTPS can use a 24-hour HTTPS link from Firmware (shown once; Stop ends it early). TFTP, FTP, HTTP and Telnet are never used. Details: the Upgrade & Lifecycle module.
Vulnerability scanning
Vulnerabilities in the menu (Vulnerability Scanning module) matches each device's operating system and version against published CVEs and CISA's Known Exploited list. It covers network operating systems (Cisco IOS, IOS-XE, NX-OS, ASA, IOS XR, Junos, ArubaOS, FortiOS, PAN-OS, RouterOS, SonicOS, pfSense, OPNsense, EdgeOS, FastIron, EXOS, ESXi), not Windows or Linux desktops and servers.
- Vulnerabilities › Devices to scan: if your license doesn't cover every device, tick the ones to cover. Start with internet-facing firewalls and VPN gateways.
- Your server downloads the feed twice a day and matches weekly (or daily under Vulnerabilities › Settings). Update the feed and Scan now run them by hand.
- Open a CVE: Get the full record, Accept the risk (with a reason), Raise an alert, Open a help desk ticket or Plan the upgrade.
- A match is possible, not proven: mark false positives Not affected (false positive) with a note.
Zero-days (on CISA's list in the last 30 days, or critical/high with no fixed version) on covered devices raise one high-priority alert and a ticket straight away. A finding resolves by itself when the device reports a version that isn't affected. Full guide: Vulnerability scanning.
MSP routing basics
For MSPs reaching many customer networks from one data center. The full design is in MSP design: routers, customers and your server.
- Master collectors in your data center take connections from customers' collectors over HTTPS 443 (or SSH). Install with the MSP master collector choice.
- Router mode (the MSP router install choice) adds FRRouting, nftables, strongSwan, keepalived and conntrackd. Configure it on the collector's page › Router.
- A VRF per customer. Under Customer hand-offs, each customer gets a VRF (
c-name), a port, VLAN or GRE tunnel protected by IPsec, your hand-off address, an external network the customer chooses (your traffic is translated into it, so overlapping customer addresses are fine), and BGP or static routes. - Firewall per VRF: allow only what monitoring needs.
- Router pairs share a virtual address (keepalived) and connection state (conntrackd) over a dedicated sync link. Between data centers, link pairs with a GRE/IPsec tunnel, MPLS and BGP VPNv4.
- Applying safely: Check and save checks the whole configuration with the routing and firewall tools first. If the router can't reach Uplivra for 3 minutes after a change, it puts the previous configuration back. On the router:
sudo uplivra system statusandsudo uplivra system rollback. - Customers' site servers report through the router's hand-off address over HTTPS; tick Their site server and collectors report to you through this hand-off.
| Problem | Check |
|---|---|
| BGP stays down | AS numbers and password match; TCP 179 allowed on the hand-off |
| Tunnel won't come up | Same IPsec suite on both ends (try compatible); UDP 500 and 4500 allowed |
| Customer collector can't connect | It reaches the master on TCP 443 and trusts its fingerprint or CA |
Ports to open
| Port | From → to | For |
|---|---|---|
| TCP 443 | Collectors → server (or site server, master collector) | Everything the collector reports |
| UDP 161 | Collector → devices | SNMP polling |
| UDP 162 | Devices → collector | SNMP traps |
| UDP/TCP 514 | Devices → collector or log collector | Syslog |
| UDP 2055, 6343 | Routers and firewalls → collector | NetFlow/IPFIX, sFlow |
| TCP 22 | Collector → devices | Configuration backups, restores, image copies, SSH checks |
| UDP 4717 | Collector → collector | Site-to-site tests |
The complete list, incoming and outgoing for every kind of computer, is in Ports and firewall rules. On any Uplivra computer, uplivra ports prints the rules it needs.