NetDoctor
Deterministic, offline-first network diagnostics for Cisco environments.
NetDoctor ingests switch and firewall configurations, detects rogue devices through MAC intelligence, and runs deterministic rules and step-by-step playbooks that produce findings with cited evidence. It is fully offline and read-only.
A five-stage pipeline collects artifacts or runs read-only SSH collection through async Scrapli, parses them with 27 dedicated Cisco IOS and IOS-XE parsers, normalises everything into a canonical snapshot that separates configured from observed state, evaluates rules against a six-layer baseline, and presents findings in dashboards and topology graphs.
Every finding carries provenance: which artifact, which line, which parsed field, which baseline value. Same inputs, same outputs, every time. A local model can add plain-language commentary, but it is never a source of truth and no data ever leaves the machine.
The security model is deliberate: no arbitrary CLI, no write commands, no AI as a source of truth. A Cisco-aware redactor strips secrets before any export, credentials are encrypted at rest with AES-256-GCM, and a seven-tab admin dashboard covers RBAC, a credential vault, scheduled backups and a forensic security audit. 689 tests pin parser output and rule behaviour.
27 structured Cisco IOS and IOS-XE parsers
120+ deterministic checks, every finding citing its evidence
Read-only SSH collection via async Scrapli with per-device locks
Six-layer baseline merge with a clear winning source per rule
Site topology graph from CDP and LLDP with role-based hierarchy
Offline MAC intelligence: OUI vendor lookup, flap and rogue detection
AES-256-GCM credential vault, RBAC and scheduled PostgreSQL backups
689 unit and integration tests with golden fixtures