UplivraUplivra
Uplivra is in beta and online purchasing is paused. Apply to test it: testers get a license on request and 10% off when purchasing opens.

Home › Install guides › Supported devices, protocols and connectors

Install guide · Administrators and buyers

Supported devices, protocols and connectors

Which makers, protocols and connectors Uplivra supports, and which are tested on real equipment.

Uplivra Technologies LLC · Guide for Uplivra 26.10 · Updated 4 October 2026 · Latest version: https://uplivra.com/guides/support-matrix.html

Download this guide as a PDF

  • "Lab-tested" means checked against real equipment or a real service account.
  • Unless a row says so, support is implemented and tested against simulators or mocks, not yet on real equipment.

1. Devices and makers

Key:

  • Y: vendor-specific support.
  • G: generic (standard MIBs, or guided steps without vendor code).
  • —: none.

What each column covers:

  • Firmware: Uplivra copies the image over SFTP/SCP and shows the maker's install commands. It never installs or reboots the device itself.
Maker / OSSNMPConfig backupFirmwareVulnerability matchingPort profilesAAA templateQoS statsRoute lookupLLDP/CDPPassword rotation
Cisco IOS / IOS-XEYY + restoreYYIOS-XETACACS+, RADIUS, 802.1XCBQOS + DiffServYLLDP + CDPY
Cisco NX-OSYYYY—TACACS+DiffServYLLDP + CDPY
Cisco ASAGYYY——GYGY
Cisco IOS XRG—version onlyY——G—G—
Juniper JunosGY + restoreYYEXTACACS+, 802.1XDiffServYLLDPY
Arista EOSGY + restore———TACACS+GYLLDPY
Aruba AOS-CXGYYYYTACACS+, 802.1XGYLLDPY
ArubaOS-Switch / ProCurveYYYY—TACACS+G—LLDPY
ArubaOS controllersG—version onlyY——————
Fortinet FortiOSYYYY—TACACS+; FortiSwitch 802.1XGYLLDPY
Palo Alto PAN-OSY (version)YYY—TACACS+GYGreminder only
MikroTik RouterOSYYYY—RADIUS, 802.1XGYLLDPY
Ubiquiti EdgeOS / VyOSGYversion onlyEdgeOS only——GYG—
Ubiquiti UniFiGYversion only—————G—
SonicWall SonicOSGYversion onlyY—————reminder only
pfSense / OPNsenseGYversion onlyY——————
Ruckus / Brocade FastIronGcustom commandversion onlyY—TACACS+——GY
Extreme EXOSG—version onlyY————G—
Dell OS10G—version only——TACACS+——GY
Huawei VRPG————TACACS+——GY
VMware ESXiG—version onlyY——————
Other SNMP devices (Meraki, Netgear, TP-Link, APC and Eaton UPS)G (APC UPS: Y)—version only—————G—
Windows serversWinRM/WMI; PowerShell over SSH—version only——————Y
Linux serversSSH (/proc, df)key filesversion only——pam-radius———Y

Not matched for vulnerabilities: Windows, Linux, Arista EOS, VyOS.

2. Protocols

ProtocolDirection and portNotes
ICMPoutAvailability, latency, loss; traceroute
SNMP v1, v2c, v3out UDP 161v3 auth: MD5, SHA, SHA-224/256/384/512. Privacy: DES, AES-128/192/256.
SNMP traps and informsin UDP 162Only from a known community or v3 user
Syslogin UDP and TCP 514 (port per site)RFC 3164 and 5424. No TLS on the way in.
Syslog forwardingout UDP, TCP or TLS (514/6514)TLS 1.2 or later
NetFlow v5/v9, IPFIXin UDP 2055
sFlow v5in UDP 6343
SSHout TCP 22Config backup, config restore, SSH checks, firmware copy and the browser terminal all check the device's SSH host key. The first key seen is remembered; if it changes, Uplivra stops before signing in until an administrator accepts the new key.
SFTP/SCP (firmware)out 22; optional read-only pull service on 2022TFTP, FTP, HTTP and Telnet are refused
WinRMout TCP 5985/5986NTLM/Negotiate. HTTPS uses TLS 1.2 or later, with an optional pin. No Kerberos.
HTTP/S, DNS, NTP and certificate checksoutCertificate checks support STARTTLS and report TLS 1.0/1.1
DHCProgue-server check out UDP 67; optional DHCP server in UDP 67
TACACS+in TCP 49Unencrypted packets rejected
RADIUSin UDP 1812/1813; CoA out UDP 3799PAP, CHAP, MAB, EAP
RadSecin TCP 2083 (off by default)Mutual TLS, 1.2 or later
802.1Xthrough RADIUSEAP-TLS only (certificates). PEAP and EAP-TTLS are not supported.
Access Control node pairsTCP between nodesMutual TLS 1.3
LDAP / LDAPSout 636, or 389 with StartTLSPlain LDAP refused unless allowed explicitly
OIDC single sign-onout HTTPSAuthorization code with PKCE
SAML—Not supported
SMTP (alerts)out 587/465/25STARTTLS or TLS; username and password (no OAuth2)
IMAP (Service Desk mail-in)out 993/143Username and password (no OAuth2)
Webhooksout HTTPSHMAC-SHA256 signatures
MCP (connect your own AI)in HTTPS 443Read only; one token per connection, limited to what an administrator ticked
Collector to serverout HTTPS 443TLS 1.3 with X25519 + ML-KEM-768 by default, pinned certificate or CA
Web interface and APIin HTTPS 443TLS 1.2 or later by default ("compatible"); TLS 1.3 only when set to "modern"
Collector site testsUDP 4717HMAC-signed; open only during a test
Shared site addressUDP 4718; gratuitous ARPHMAC-signed heartbeats
ACME certificatesout 443Let's Encrypt; Cloudflare DNS-01
Licensing, updates, vulnerability feedout 443licensing.uplivra.com; NVD 2.0 and CISA KEV

3. Connectors

SystemHowAccessTested against
ServiceNowTable and Service Catalog APIs; basic authCreates incidents and changes; reads approvalsmock
Jira Service ManagementService desk REST API; email + API tokenWrite, read approvalmock
FreshserviceAPI v2; API keyWrite, readmock
ZendeskAPI v2; email + tokenWrite, readmock
Generic ticket webhookJSON POST with HMAC; inbound decision callbackWritemock
ConnectWise, HaloPSA, Autotask—Not built—
AWSSTS (role + external ID), EC2, RDS, ELBv2, Lambda, CloudWatch, Health; Uplivra's own SigV4 signingRead onlyfake
AzureARM, Resource Graph, Monitor metrics, Resource Health; service principalRead onlyfake
Microsoft 365 service healthMicrosoft Graph service announcementsRead onlyfake
LDAP / Active DirectoryLDAP v3 (own client), simple bindReadfake server
OIDC (Entra ID, Google, Okta and others)Discovery, authorization code, PKCESign-in onlyfake
Entra ID / Okta directory lookups—Not built (planned)—
HashiCorp VaultKV v2; token or AppRole, optional client certificateReadmock
CyberArk CCPAIMWebService; AppID + client certificateReadmock
Log forwardingSyslog UDP/TCP/TLS; HTTPS JSON lines; Splunk HEC; S3 (with Object Lock); Azure BlobWritemock
EmailSMTPWritefake SMTP server
Slack, Microsoft TeamsIncoming webhooks (Teams Adaptive Card 1.4)Writedelivery not tested
PagerDuty—Not built. Reach it through a generic webhook.—
SMS—Not built (low priority)—
Local AI modelOpenAI-style chat API, private network addresses onlyReadmock
ISE / ClearPass / NPS importCSV uploadImportno test. NPS's own export is XML, so it needs converting first.
Windows DHCP, ISC KeaPowerShell over WinRM; Kea Control AgentReadmock
Stripe (portal only)Customers, checkout, subscriptions; signed webhooksWritemock

No connector has been tested against a live third-party service yet. The only optional real-host tests are WinRM interop, Let's Encrypt Pebble and the PostgreSQL test database.