All work
Live·Network diagnostics

NetDoctor

Offline Cisco diagnostics that show their evidence.

01 · Try it

Play with it, right here.

A working demo with sample data. Nothing here touches a real system.

acc-sw3sample analysis
Sample data · nothing leaves your browser
  1. Collect1 config · 72 lines
  2. Parse8 interfaces · 4 VLANs
  3. Normalise1 snapshot
  4. Evaluate122 checks
  5. Present5 findings

Pipeline: Done · 5 findings · 117 checks passed

acc-sw3.cfg72 lines · read-only
1! acc-sw3 · running-config · sample
2version 17.9
3service timestamps log datetime msec localtime
4service password-encryption
5hostname acc-sw3
6!
7clock timezone EET 2 0
8ip domain name site-a.example
9!
10vlan 10
11 name USERS
12vlan 20
13 name PRINTERS
14vlan 30
15 name VOICE
16vlan 99
17 name MGMT
18!
19spanning-tree mode rapid-pvst
20spanning-tree extend system-id
21!
22interface Port-channel1
23 description UPLINK core-sw1 Po11
24 switchport mode trunk
25 switchport trunk allowed vlan 10,20,99
26!
27interface GigabitEthernet1/0/1
28 description DESK 2.14
29 switchport mode access
30 switchport access vlan 10
31 switchport voice vlan 30
32 spanning-tree portfast
33!
34interface GigabitEthernet1/0/7
35 switchport mode access
36 switchport access vlan 10
37 switchport voice vlan 30
38 spanning-tree portfast
39!
40interface GigabitEthernet1/0/12
41 description MEETING ROOM 2
42 switchport mode access
43 switchport access vlan 10
44 spanning-tree portfast
45 spanning-tree bpduguard enable
46!
47interface GigabitEthernet1/0/24
48 description AP-2F-EAST
49 switchport mode access
50 switchport access vlan 99
51 spanning-tree portfast
52!
53interface GigabitEthernet1/0/49
54 description UPLINK core-sw1 Gi1/0/3
55 channel-group 1 mode active
56!
57interface GigabitEthernet1/0/50
58 description UPLINK core-sw1 Gi2/0/3
59 channel-group 1 mode active
60!
61interface Vlan99
62 ip address 10.99.0.13 255.255.255.0
63!
64ip default-gateway 10.99.0.1
65logging host 10.99.0.20
66snmp-server community <removed> RO
67!
68line vty 0 4
69 login local
70 transport input telnet ssh
71!
72end

117 checks passed

HIGH

Gi1/0/12 err-disabled by BPDU guard

Rule
STP-012 · BPDU guard tripped
Baseline
Edge ports may trip BPDU guard, with err-disable recovery configured
Observed
Gi1/0/12 err-disabled (bpduguard) since 09:41 · no recovery configured
Evidence
acc-sw3.cfg, line 45

Why it matters. Someone plugged a switch or a looped cable into Meeting room 2. BPDU guard shut the port to protect the network, so the room stays offline until somebody re-enables it.

Next step. Find and unplug what is on Gi1/0/12, then bounce the port. Consider errdisable recovery for bpduguard. NetDoctor only suggests; it never changes a device.

Site topologybuilt from CDP and LLDP neighbour tables · sample site

Select a device to see how it was discovered.

02 · The real thing

net-doctor.vercel.app, as it is today.

The real website. Switch between desktop and phone, then open it for the full experience.

A screenshot of the real site as it is today. It does not allow being embedded, so it opens in a new tab.

03 · Overview

Overview

Role
Creator
Year
2025
Platforms
Web · local
Status
Live

NetDoctor reads switch and firewall configurations, spots rogue devices from MAC data and runs deterministic checks and step-by-step playbooks. Every finding comes with its evidence. It works fully offline and never changes a device.

A five-stage pipeline collects the configs, or pulls them over read-only SSH, parses them with 42 dedicated Cisco IOS and IOS-XE parsers, builds one clean snapshot that separates what is configured from what is observed, checks it against a layered baseline, and shows the results as dashboards and topology maps.

Every finding is traceable: which file, which line, which value, which rule. The same input always gives the same output. An optional local model can explain a finding in plain words, but it is never the source of truth, and no data leaves the machine.

Safety is built in: no arbitrary commands and no write access. Secrets are stripped before any export, stored credentials are encrypted, and 689 tests keep the parsers and rules honest.

04 · What it does

7 things it does well.

  • 42 Cisco IOS and IOS-XE parsers
  • 120+ deterministic checks, each citing its evidence
  • Read-only SSH collection
  • Site topology from CDP and LLDP
  • Offline MAC intelligence: vendor lookup, flapping and rogue devices
  • Encrypted credential vault, roles and scheduled backups
  • 689 automated tests
05 · Built with

Built with

  • Python
  • Next.js
  • TypeScript
  • PostgreSQL
  • Cisco IOS
  • Scrapli
Next project Device Info One click tells you if a work laptop is ready: sign-in, VPN, network, security and hardware.
cosmin# show version

Cosmin Trică Software (NOC-K9), Version 2026, RELEASE SOFTWARE (fc1)

Technical Support: cosmin.trica@outlook.com

Compiled in Craiova, Romania

 

ROM: first boot 2016, IT support

cosmin uptime is 10 years

System image file is "flash:/noc-universalk9.ccna.bin"

Last reload reason: curiosity

 

Helpdesk & NOC Operator, Prysmian · CCNA · studying for CCNP

11 projects on board: 3 network tools, 8 apps

 

InterfaceStatusDescription
NOCupMonitoring, incidents, change windows
RoutingupCisco IOS · OSPF · VPN & IPsec
SwitchingupVLAN · STP · AP provisioning
AppsupSwift & SwiftUI · Next.js & React · Supabase & PostgreSQL

 

Configuration register is 0x2102

Esc to exit