R12.3-2026Apr21
Built-in NCT Tables (Logical Nodes)
The following table lists the NCT Table properties/attributes for logical nodes (case-sensitive).
| No. | Table Name | Vendor | Device / Platform Type | Driver | Technical Description |
|---|---|---|---|---|---|
| 1 | ARP Table | Aruba Networks | SD-WAN / WAN Edge | Aruba Orchestrator | Collects Address Resolution Protocol mappings from Aruba SD-WAN branch and campus devices managed via Aruba Orchestrator. Maps IP addresses to MAC addresses across WAN edges and SD-WAN overlays, supporting network path tracing and endpoint visibility in hybrid branch deployments. Resolves L2 adjacency for routed overlay and underlay interfaces. Enables detection of ARP conflicts and stale entries across distributed sites. |
| 2 | ARP Table | VMware AVI Networks | Application Delivery Controller | AVI | Captures ARP bindings learned by AVI (VMware Avi Load Balancer) Service Engines deployed in inline or one-arm mode. Reflects the IP-to-MAC resolution state for virtual services, pool members, and management interfaces. Critical for understanding how Avi reaches backend servers and validates Layer 2 reachability in east-west and north-south traffic paths within load-balanced application tiers. |
| 3 | ARP Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures ARP bindings across virtual and physical leaf switches managed by the Big Cloud Fabric controller. Reflects dynamic L2 resolution entries for tenant workloads and fabric endpoints. Enables path analytics by associating IP endpoints with physical or virtual switch ports, critical for verifying fabric connectivity and diagnosing endpoint reachability in BCF environments. |
| 4 | ARP Table | Check Point | Next-Gen Firewall | CheckPoint R80 API | Collects ARP cache entries from Check Point Security Gateways via the R80 management API. Maps IP-to-MAC resolution states for interfaces and adjacent hosts. Used to validate forwarding decisions, diagnose connectivity failures, and correlate firewall policy hits with physical endpoint identities. Supports L2 adjacency validation for firewall-to-router and firewall-to-server paths. |
| 5 | ARP Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures ARP bindings from the ACI fabric's endpoint database and leaf node ARP caches. Reflects IP-to-MAC resolution for endpoints connected to EPGs and bridge domains. ACI proxies ARP within bridge domains to minimize flood traffic; this table provides visibility into both proxy and direct ARP entries across the fabric, enabling endpoint tracking and path validation within ACI overlay networks. |
| 6 | ARP Table | Cisco | Next-Gen Firewall (FTD) | Cisco FMC | Collects ARP cache entries from Firepower Threat Defense (FTD) devices managed by Firepower Management Center. Captures IP-to-MAC mappings at the firewall's interfaces, enabling correlation of security events with physical endpoints. Supports network path analysis in FTD-managed perimeter and segmentation environments, including validation of next-hop adjacency for firewall routing. |
| 7 | ARP Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Retrieves ARP cache data from Meraki MX security appliances and MS switches via the Meraki Dashboard API. Maps IP-to-MAC entries for local LAN segments, providing endpoint visibility across cloud-managed branch networks. Supports troubleshooting and validation of client connectivity in Meraki-managed sites, including VLAN-specific ARP isolation and cross-VLAN gateway resolution. |
| 8 | ARP Table | Citrix / NetScaler | ADC Management Platform | Citrix ADM | Collects ARP entries from Citrix ADC (NetScaler) instances managed by Application Delivery Management. Reflects IP-to-MAC mappings for virtual IPs, backend servers, and management interfaces. Supports load balancer path analysis and validates L2 reachability between ADC instances and application backends, ensuring proper resolution for SNIP and MIP addresses. |
| 9 | ARP Table | Citrix SD-WAN | SD-WAN Appliance | Citrix SDWAN | Captures ARP cache entries from Citrix SD-WAN appliances at branch, hub, and data center sites. Maps IP-to-MAC resolutions for WAN overlay and LAN-side interfaces, enabling underlay/overlay path correlation. Supports connectivity diagnostics across Citrix SD-WAN deployments, including validation of gateway ARP state on both WAN transport and LAN access links. |
| 10 | ARP Table | Extreme Networks | Cloud-Managed Switch / AP | ExtremeCloud IQ | Collects ARP bindings from Extreme Networks switches and access points managed via ExtremeCloud IQ cloud controller. Resolves IP-to-MAC for connected endpoints across campus and branch sites. Supports client tracking, network path visualization, and connectivity troubleshooting in Extreme-managed environments, with visibility into VLAN-specific ARP tables across managed switch fabric. |
| 11 | ARP Table | Fortinet | Fortinet Management Platform | FortiManager | Collects ARP cache entries from FortiGate devices managed through FortiManager. Provides IP-to-MAC mapping for interfaces and adjacent network devices across distributed enterprise deployments. Supports policy correlation, endpoint tracking, and path verification in Fortinet-managed security and routing environments. Useful for validating adjacency in VDOM-segmented FortiGate deployments. |
| 12 | ARP Table | Fortinet | NGFW / UTM Appliance | FortinetFortiGate | Captures ARP entries directly from FortiGate firewalls via CLI or API. Maps IP addresses to MAC addresses for directly connected hosts and adjacent routers on all FortiGate interfaces and VDOMs. Enables hop-by-hop path tracing, validates next-hop adjacency for routing, and correlates security events with physical endpoints. Essential for troubleshooting firewall connectivity in perimeter and internal segmentation deployments. |
| 13 | ARP Table | Palo Alto Networks | Next-Gen Firewall | Palo Alto Panorama | Collects ARP cache data from Palo Alto Networks firewalls managed by Panorama. Captures IP-to-MAC mappings at firewall data-plane interfaces across distributed deployments. Used for path verification, endpoint identification, and correlating security policy enforcement with physical network topology. Supports virtual system (vsys) aware endpoint tracking in multi-tenant Palo Alto deployments. |
| 14 | ARP Table | Ivanti Pulse Secure | VPN / Zero-Trust Gateway | PulseSecure API | Collects ARP bindings from Pulse Connect Secure (VPN gateway) and Pulse Policy Secure appliances. Maps IP-to-MAC for VPN tunnel endpoints and internal network interfaces, enabling visibility into remote access connectivity. Validates L2 reachability for VPN-connected clients and supports path analysis through Pulse VPN gateway architectures. |
| 15 | ARP Table | VMware VeloCloud | SD-WAN Edge | VeloCloud SD-WAN | Captures ARP cache entries from VeloCloud Edge devices at branch and data center sites. Resolves IP-to-MAC for LAN, WAN, and overlay interfaces, supporting overlay path analytics, underlay verification, and endpoint reachability analysis. Used to validate gateway ARP state for both internet and MPLS underlay links, as well as LAN-side default gateway resolution. |
| 16 | ARP Table | Versa Networks | SD-WAN / Multi-Tenant NFV | Versa SD-WAN | Collects ARP entries from Versa FlexVNF appliances at branch and hub sites. Maps IP-to-MAC for tenant VRF interfaces and physical underlay connections. Used for SD-WAN path analysis, validating adjacency for application-aware routing, and diagnosing connectivity in multi-tenant Versa deployments, including per-VRF ARP isolation and underlay peer validation. |
| 17 | ARP Table | Cisco Viptela | Cisco SD-WAN Edge | Viptela SD-WAN | Captures ARP bindings from vEdge and cEdge routers in the Cisco SD-WAN fabric. Maps IP-to-MAC for service-side (LAN) and transport-side (WAN) interfaces, enabling full path visualization from site to site. Validates OMP overlay routes with physical L2 adjacency and supports per-color transport link ARP verification in Cisco SD-WAN environments. |
| 18 | ARP Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Reflects ARP suppression entries and learned ARP bindings from the NSX-T distributed data plane. NSX-T uses ARP proxy and suppression to reduce broadcast flooding in overlay segments. Maps IP-to-MAC for virtual machines and containers attached to NSX-T logical segments, providing full east-west visibility into endpoint IP-MAC bindings across the NSX-T transport zone. |
| 19 | AWS ELB Listener Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures configuration of listeners on Elastic Load Balancers (ALB, NLB, CLB) via the AWS API. Each listener defines a port/protocol combination and associated routing rules for inbound traffic. Used to analyze load balancer traffic entry points, validate protocol handling, and model traffic paths from clients to backend targets. Includes HTTPS listener SSL policy and certificate associations. |
| 20 | AWS ELB Target Group Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects target group configurations including registered targets (EC2, IP, Lambda), health check settings, and load balancing algorithms from AWS ELB. Models the backend server pool for each listener rule, enabling analysis of traffic distribution across application tiers and validation of health-based routing decisions. Captures deregistration delay and stickiness policy settings. |
| 21 | AWS Endpoint Service Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Reflects PrivateLink endpoint service configurations created by service providers in AWS. Includes service names, availability zones, and acceptance settings for private connectivity. Models secure, private service consumption across VPCs without internet exposure, supporting PrivateLink topology analysis and validation of service endpoint visibility across VPC boundaries. |
| 22 | AWS ENI Interface Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures all ENI (Elastic Network Interface) configurations across AWS accounts and regions. Each ENI represents a virtual NIC attached to EC2 instances, Lambda functions, or managed services. Includes IP addresses, MAC, security groups, and attachment details, providing the foundational layer for modeling AWS network paths and interface-level security group enforcement. |
| 23 | AWS Firewall Policy Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects AWS Network Firewall policy configurations, including stateless and stateful rule group associations, default actions, and logging settings. Provides visibility into centralized firewall enforcement points within VPCs, enabling analysis of allowed and denied traffic flows across the AWS network topology. Supports compliance validation for centralized firewall architectures. |
| 24 | AWS Firewall Stateful Rule Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures stateful inspection rules within AWS Network Firewall rule groups. These rules define protocol, source/destination criteria, and actions for connection-tracked traffic. Enables deep inspection of allowed application-layer flows and supports compliance validation of east-west and north-south traffic policies. Includes Suricata-compatible rule strings for IDS/IPS-mode stateful inspection. |
| 25 | AWS Firewall Stateless Rule Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects stateless (packet-level) rules from AWS Network Firewall rule groups. These rules match on packet headers without connection tracking and define priority-ordered permit/deny actions. Used to model first-pass filtering of traffic before stateful inspection, analyzing basic ACL behavior and identifying default action handling in AWS firewall deployments. |
| 26 | AWS NAT Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures NAT Gateway configurations including elastic IP associations, subnet placement, and connectivity state. NAT Gateways provide scalable outbound internet access for private subnet resources. Models outbound path translation in AWS, enabling analysis of egress routing for private workloads, validating NAT gateway availability zone coverage, and monitoring NAT bandwidth utilization. |
| 27 | AWS Network ACL Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects subnet-level access control list configurations with numbered inbound and outbound rules. Unlike security groups, NACLs are stateless and evaluate all traffic independently. Used to model subnet boundary policies, identify conflicting or overly permissive rules, and validate subnet-level traffic filtering. Supports compliance audits for defense-in-depth network segmentation in AWS VPCs. |
| 28 | AWS Palo Alto Cloud NGFW FQDN Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures FQDN-based allow/deny list entries configured in Palo Alto Cloud NGFW deployments on AWS. These entries enable DNS-based policy enforcement for outbound traffic. Supports analysis of application-aware security policies that use domain names rather than static IP addresses, enabling dynamic policy scoping for SaaS and cloud service access. |
| 29 | AWS Palo Alto Cloud NGFW Global Post Rules Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Reflects post-rulestack global security policies applied after local rules in Palo Alto Cloud NGFW on AWS. These rules enforce organization-wide security baselines and cleanup policies. Models the final enforcement layer in the Palo Alto policy evaluation chain for AWS traffic, ensuring consistent enterprise-wide security posture after tenant-specific rules are evaluated. |
| 30 | AWS Palo Alto Cloud NGFW Global Pre Rules Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures pre-rulestack global policies evaluated before local rulestacks in Palo Alto Cloud NGFW on AWS. These rules enforce enterprise-wide security mandates that override local configurations. Models top-of-policy enforcement in distributed Palo Alto NGFW deployments on AWS, ensuring centrally managed policies take precedence over delegated local rulestack configurations. |
| 31 | AWS Palo Alto Cloud NGFW Local Rulestack Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects the full local rulestack configuration for Palo Alto Cloud NGFW instances deployed in AWS, including security rules, NAT rules, and associated objects for tenant-specific policy. Enables per-deployment policy analysis and validation of application-layer security. Supports compliance checks and shadow rule detection within individual AWS deployment rulestacks. |
| 32 | AWS Palo Alto Cloud NGFW Prefix List Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures named prefix lists used as address objects within Palo Alto Cloud NGFW rule definitions on AWS. Prefix lists group IP ranges for reuse across multiple rules. Supports analysis of address-based policy objects and validates CIDR coverage in NGFW security policies, enabling audits of IP range scoping in cloud firewall configurations. |
| 33 | AWS Route Dependency Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Models routing dependencies between AWS constructs including VPCs, subnets, Transit Gateways, and VPN connections. Captures how route tables reference attachments and propagation sources, enabling end-to-end path analysis across complex multi-VPC architectures. Identifies potential routing loops, black-hole conditions, and missing propagation configurations in AWS network topologies. |
| 34 | AWS Security Group Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects all security group configurations including inbound and outbound rules across AWS accounts and VPCs. Security groups act as stateful virtual firewalls for EC2 and other resources. Enables modeling of micro-segmentation policies, analysis of overly permissive rules (0.0.0.0/0), and validation of east-west traffic controls. Supports compliance audits and least-privilege analysis in AWS environments. |
| 35 | AWS Transit Gateway Attachments Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures all attachments to AWS Transit Gateways including VPC attachments, VPN connections, Direct Connect gateways, and peering connections. Models the hub topology of inter-VPC and hybrid connectivity. Enables analysis of TGW routing domains, ECMP configurations, and traffic flow paths across AWS regions and accounts in hub-and-spoke architectures. |
| 36 | AWS Transit Gateway Route Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects routing entries within TGW route domains, including static and propagated routes for each attachment. Central to modeling multi-VPC routing in AWS hub-and-spoke architectures, enabling full path analysis from source VPC through TGW to destination VPC or on-premises network. Supports analysis of route domain segmentation and blackhole route insertion. |
| 37 | AWS Virtual Route Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Represents the effective routing view of AWS networking, combining VPC route tables, Transit Gateway routes, and VPN/Direct Connect propagated routes into a unified forwarding model. Used to calculate actual packet forwarding paths across AWS networks, including longest prefix matching and routing priority evaluation across all route sources. |
| 38 | AWS VPC Peering Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Captures all VPC peering connection configurations, including requester and accepter VPC details, CIDR ranges, and connection status. Models peer-to-peer connectivity, detects overlapping CIDR issues, and validates route propagation for peered network paths. Includes cross-account and cross-region peering visibility, supporting full topology analysis of AWS VPC mesh architectures. |
| 39 | AWS VPC Route Table | Amazon Web Services | Public Cloud (AWS) | Amazon AWS | Collects the actual route table entries associated with each subnet in a VPC, including local routes, internet gateway routes, NAT gateway routes, and VPN/TGW propagated routes. Primary forwarding table for packet-level path analysis within AWS VPCs. Determines next-hop for all traffic leaving a subnet and is foundational for AWS network path computation. |
| 40 | Azure AppGW Backend Pools Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures the set of backend targets (VMs, IP addresses, FQDNs, or App Service endpoints) registered in each Application Gateway backend pool. Backend pools define the server groups to which Application Gateway routes application traffic. Models application tier composition and validates load balancing topology, including mixed backend types across different Azure services. |
| 41 | Azure AppGW Http Setting Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects Application Gateway HTTP settings including backend port, protocol, cookie-based affinity, connection drain, and custom health probe associations. Defines how traffic is forwarded to backend pools. Used to analyze backend protocol handling and session persistence configuration, including HTTPS re-encryption settings for end-to-end SSL in Azure Application Gateway deployments. |
| 42 | Azure AppGW Listener Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures listener configurations on Azure Application Gateway including frontend IP, port, protocol (HTTP/HTTPS), and SSL certificate associations. Listeners define inbound traffic entry points for the gateway. Models the front-end exposure of applications and SSL termination policy for inbound application traffic, including multi-site hosting via host header matching. |
| 43 | Azure AppGW Rule Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects routing rules that bind listeners to backend pools via HTTP settings in Azure Application Gateway. Rules can be basic (one-to-one) or path-based (URL routing). Models application traffic routing logic, enabling analysis of how inbound requests are distributed across backend application tiers based on URL path patterns. |
| 44 | Azure AppGW Translation Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures URL rewrite rules and redirect configurations applied by Azure Application Gateway. These rules modify request/response headers or redirect traffic based on conditions. Enables visibility into application-layer traffic transformation within Azure gateway deployments, including header insertion, URL rewriting, and HTTP-to-HTTPS redirects. |
| 45 | Azure Cloud NGFW PAN Additional Prefixes To Private Traffic Range Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures additional custom private IP prefixes configured in Palo Alto Cloud NGFW deployments on Azure. Extends the default RFC 1918 private traffic classification for policy enforcement purposes. Used to model custom traffic categories in hybrid or multi-cloud environments where non-standard private ranges are used for Azure workloads. |
| 46 | Azure Cloud NGFW PAN Destination Network Address Translation Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures destination NAT rules configured in Palo Alto Cloud NGFW on Azure. DNAT rules translate inbound public IP addresses to private backend servers. Models inbound traffic flows through NAT, enabling analysis of service exposure and inbound traffic path in Azure-hosted Palo Alto firewall deployments with public-to-private IP translation. |
| 47 | Azure Cloud NGFW PAN Local Rulestack Certificates Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures SSL/TLS certificates associated with local rulestacks in Palo Alto Cloud NGFW on Azure. These certificates are used for SSL forward proxy and inbound inspection. Supports analysis of certificate-based security policies in cloud-native NGFW deployments, including certificate chain validation and expiry monitoring. |
| 48 | Azure Cloud NGFW PAN Local Rulestack FQDN List Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects domain-based address objects used within Palo Alto Cloud NGFW local rulestacks on Azure. FQDN lists enable DNS-resolved dynamic policy matching. Models application-layer policy based on domain names rather than static IPs, supporting analysis of SaaS access controls and dynamic threat-feed-driven policy in Azure Palo Alto NGFW environments. |
| 49 | Azure Cloud NGFW PAN Local Rulestack Prefix List Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures named CIDR prefix lists used as address objects in Palo Alto NGFW local rulestacks on Azure. Prefix lists simplify policy management by grouping IP ranges. Enables analysis of IP-based policy scoping within tenant-specific Palo Alto NGFW rule definitions and validates CIDR coverage across rule objects. |
| 50 | Azure Cloud NGFW PAN Local Rulestack Rules Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects the complete security rule set within local rulestacks configured for Palo Alto Cloud NGFW on Azure. Rules define application, source, destination, and action for tenant traffic. Enables end-to-end policy analysis and compliance validation for Azure-deployed Palo Alto NGFW, including rule ordering, shadow detection, and application identification coverage. |
| 51 | Azure Cloud NGFW PAN Private Source NAT Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures private SNAT rules configured in Palo Alto Cloud NGFW on Azure. Translates source IPs for east-west or internal traffic flows without using public IPs. Supports analysis of internal NAT behavior and traffic path modeling within Azure private networks using Palo Alto NGFW as a centralized NAT and inspection point. |
| 52 | Azure Cloud NGFW PAN Source Network Address Translation Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures all source NAT rules in Palo Alto Cloud NGFW deployments on Azure, including both public and private translations. SNAT rules modify source IPs for outbound or inter-segment traffic. Models outbound traffic transformation and supports egress path analysis in Azure Palo Alto NGFW environments, validating IP identity for outbound flows. |
| 53 | Azure Firewall Application Rule Collection Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures FQDN and URL-based application rules within Azure Firewall rule collections. These rules enforce Layer 7 outbound access controls based on destination domain names and protocols. Enables analysis of application-aware egress filtering policies enforced by Azure Firewall, including threat intelligence-based FQDN blocking and web categories. |
| 54 | Azure Firewall DNAT Rule Collection Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects destination NAT rules that translate inbound traffic from public IPs to private backend resources via Azure Firewall. DNAT rules expose services hosted behind Azure Firewall. Models inbound service access through the firewall and supports analysis of NAT-based service publishing across Azure Firewall standard and premium tiers. |
| 55 | Azure Firewall Network Rule Collection Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures Layer 3/4 network rules defining allowed or denied traffic by IP, port, and protocol across Azure Firewall policy. Network rules enforce connectivity between subnets, VNets, and external networks. Central to modeling east-west and north-south traffic policy in Azure hub-and-spoke architectures, including forced-tunneling and inter-spoke traffic inspection. |
| 56 | Azure LoadBalancer Backend Pools Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures the set of backend NICs or IP addresses registered in each Azure Load Balancer backend pool. Backend pools define the target servers for load-balanced traffic flows. Models application tier composition and validates backend health and connectivity for Azure internal and public load balancers, including NIC-based and IP-based backend configurations. |
| 57 | Azure LoadBalancer Inbound NAT Rules Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects direct port-forwarding rules that map specific frontend IP/port combinations to individual backend VMs. Enables direct access to specific VMs without load balancing. Models point-to-point NAT paths and is commonly used for management access to backend instances, including RDP and SSH port forwarding through Azure Load Balancer. |
| 58 | Azure LoadBalancer Load Balancing Rules Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures rules that distribute inbound traffic across backend pool members based on a hash algorithm. Each rule defines frontend IP/port, backend pool, health probe, and session persistence settings. Models the traffic distribution logic for Azure load-balanced application workloads, including HA ports configuration for NVA deployments. |
| 59 | Azure LoadBalancer Outbound Rules Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures outbound SNAT rules defining how backend pool members reach the internet using frontend IP addresses. Manages outbound port allocation and IP assignment for private instances requiring internet egress. Models outbound path translation in Azure network topologies, including SNAT port exhaustion risk analysis for high-connection workloads. |
| 60 | Azure MSEE ARP Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures ARP bindings at the Azure ExpressRoute edge routers (MSEE), reflecting IP-to-MAC resolution for ExpressRoute private and Microsoft peering connections. Critical for validating Layer 2 adjacency between on-premises CE routers and Azure MSEE, essential for ExpressRoute path analysis and BGP session establishment troubleshooting. |
| 61 | Azure MSEE Route Summary Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Provides an aggregated view of routes exchanged via BGP on ExpressRoute circuits, summarizing prefixes received from and advertised to on-premises networks. Enables quick assessment of route exchange health across ExpressRoute peerings and validates routing coverage in hybrid Azure/on-premises deployments, including ECMP path availability. |
| 62 | Azure MSEE Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures the detailed BGP routing table at the Azure ExpressRoute edge, including all prefixes received from and sent to on-premises peers. Enables full path analysis for hybrid connectivity, route origin validation, AS path inspection, and detection of route leaks or prefix conflicts in ExpressRoute environments with multiple peerings. |
| 63 | Azure NATGW NAT Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures the translation state and IP pool configuration for Azure NAT Gateway deployments. Provides scalable outbound internet access for private subnet resources with deterministic IP assignment. Models outbound path translation, SNAT port allocation, and egress IP identity for Azure private workloads, including SNAT port utilization monitoring. |
| 64 | Azure Private Endpoints Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures all private endpoint configurations, mapping Azure PaaS services (Storage, SQL, Key Vault, etc.) to private IP addresses within VNets. Private endpoints eliminate public exposure of Azure services. Models private service access paths, enabling topology analysis of PrivateLink-based connectivity within Azure and validating DNS resolution for private endpoint FQDNs. |
| 65 | Azure Route Server BGP Advertised Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures routes that Azure Route Server advertises to connected NVA BGP peers. Route Server acts as a BGP route reflector in Azure. Models what routing information Azure is propagating to NVAs, essential for validating dynamic route exchange in NVA-based hub architectures and detecting prefix coverage gaps in advertised routes. |
| 66 | Azure Route Server BGP Learned Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects routes received by Azure Route Server from NVA BGP peers. These learned routes are programmed into VNet route tables, enabling NVA-injected routes to influence Azure packet forwarding. Critical for validating NVA-driven routing in Azure hub-and-spoke and Virtual WAN architectures with third-party NVA route injection. |
| 67 | Azure Route Server BGP Peers Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures BGP peer configurations associated with Azure Route Server, including NVA peer IP addresses, ASN, and session state. Provides visibility into the BGP peering fabric between Azure Route Server and NVA devices, enabling session health monitoring and routing adjacency validation for NVA-based SD-WAN and firewall deployments. |
| 68 | Azure VHub Effective Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures the computed routing table as applied to connected spokes and gateways from a Virtual WAN hub. Includes routes from all sources: static, propagated, and BGP-learned. Used for end-to-end path analysis across Azure Virtual WAN topologies, validating actual packet-forwarding behavior and identifying routing conflicts in Virtual WAN hub configurations. |
| 69 | Azure VHub Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures the configured route tables within Azure Virtual WAN hubs, including static routes and propagation settings for connected VNets and branches. Route tables define routing policy applied to traffic flowing through the Virtual WAN hub, enabling analysis of hub-based routing segmentation and traffic steering for east-west and branch traffic. |
| 70 | Azure VNet Network Security Groups Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures NSG rule configurations for all NSGs in a VNet, including inbound and outbound rules with priority, protocol, port, and source/destination definitions. NSGs provide subnet and NIC-level stateless packet filtering. Models micro-segmentation and network access control in Azure environments, supporting rule priority conflict analysis and compliance audits. |
| 71 | Azure VNet Peering Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures all VNet-to-VNet peering configurations, including peered VNet IDs, address spaces, and settings like gateway transit and use of remote gateways. Models peer-to-peer connectivity and validates routing reachability across peered networks. Includes cross-subscription and cross-region peering visibility for full Azure network topology analysis. |
| 72 | Azure VNet Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures user-defined route (UDR) configurations applied to subnets within Azure VNets. UDRs override default Azure routing to steer traffic through NVAs, firewalls, or custom next-hops. Primary basis for modeling traffic steering policy in Azure network topologies, including forced tunneling and internet breakout configurations. |
| 73 | Azure VNG BGP Advertised Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures routes that Azure Virtual Network Gateway advertises to on-premises or peer BGP neighbors via VPN or ExpressRoute. Provides visibility into what Azure is announcing to connected networks, enabling validation of route distribution and detection of misconfigured or missing prefixes in hybrid connectivity scenarios. |
| 74 | Azure VNG BGP Learned Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects routes received by Azure VPN/ExpressRoute Gateway from BGP peers. Represents on-premises or peer network prefixes being imported into Azure. Enables analysis of hybrid routing, validation of prefix advertisement from on-premises, and detection of routing convergence issues in Azure VPN and ExpressRoute deployments. |
| 75 | Azure VNG BGP Peering Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures BGP peering session details for Azure Virtual Network Gateway, including peer IP, ASN, and session state for VPN and ExpressRoute connections. Provides visibility into the BGP control plane for hybrid Azure connectivity, enabling adjacency health monitoring and BGP session validation for both active/active and active/standby gateway configurations. |
| 76 | Azure VNIC Effective Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures the computed forwarding table applied to a specific virtual NIC, combining system routes, UDRs, BGP-learned routes, and NSG-filtered paths. Represents the actual routing behavior for a VM's network interface. Essential for per-VM path analysis and troubleshooting connectivity issues, providing the ground truth forwarding view for individual Azure VM instances. |
| 77 | Azure VPN GW BGP Advertised Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures routes being advertised by the Azure VPN Gateway to on-premises VPN peers via BGP. Provides visibility into Azure-side route distribution for site-to-site VPN connections, enabling validation of prefix coverage and detection of missing or incorrect route advertisements in Azure S2S VPN deployments. |
| 78 | Azure VPN GW BGP Learned Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Collects on-premises prefixes received by the Azure VPN Gateway from BGP-enabled VPN peers. Represents the on-premises network visibility within Azure. Supports hybrid path analysis and validation of on-premises route propagation into the Azure routing fabric, including detection of missing prefixes from on-premises BGP neighbors. |
| 79 | BGP Advertised Route Table | Aruba Networks | SD-WAN / WAN Edge | Aruba Orchestrator | Captures BGP prefixes advertised by Aruba branch and WAN edge devices to their BGP peers via Aruba Orchestrator. Provides visibility into routing information distributed by Aruba-managed devices, enabling validation of route propagation in hybrid WAN and campus environments and verifying that expected prefixes are being announced. |
| 80 | BGP Advertised Route Table | Check Point | Next-Gen Firewall | CheckPoint R80 API | Captures BGP prefixes advertised by Check Point Security Gateways to their routing peers. Check Point gateways can participate in BGP for dynamic routing in perimeter and internal segmentation deployments. Enables analysis of route distribution from firewall cluster nodes and validates BGP policy for prefix filtering. |
| 81 | BGP Advertised Route Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures routes advertised by Google Cloud Routers to connected peers via BGP, including on-premises networks via Cloud Interconnect or Cloud VPN. Models Google's contribution to hybrid routing, enabling validation of prefix advertisement from GCP into on-premises or multi-cloud environments and detecting route origin issues. |
| 82 | BGP Advertised Route Table | Microsoft | Public Cloud (Azure) | Microsoft Azure | Captures all routes advertised by Azure routing components (VPN Gateway, ExpressRoute Gateway, Route Server) to BGP peers. Provides a unified view of Azure-originated route advertisements into hybrid and multi-cloud topologies, enabling route coverage analysis and detection of missing or conflicting prefix advertisements. |
| 83 | BGP Route Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures BGP routing entries on Meraki MX appliances configured with BGP peering. Meraki MX supports BGP for site-to-site routing with SD-WAN overlays or upstream routers. Enables analysis of dynamic routing behavior in cloud-managed branch deployments, including BGP next-hop validation and prefix acceptance from upstream ISP or MPLS providers. |
| 84 | Contract Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures inter-EPG communication contracts defining allowed traffic flows between endpoint groups. ACI contracts are the primary access control mechanism, replacing traditional ACLs with policy-based segmentation. Enables analysis of whitelist-based connectivity policies, security group permissions, and east-west traffic authorization in ACI fabrics, including provider/consumer contract relationships. |
| 85 | Control Connections Table | Cisco Viptela | Cisco SD-WAN Edge | Viptela SD-WAN | Captures the state of DTLS/TLS control plane sessions between vEdge/cEdge routers and SD-WAN controllers (vSmart, vBond, vManage). Reflects the operational health of SD-WAN fabric orchestration. Essential for verifying control plane connectivity and diagnosing SD-WAN fabric issues, including detecting controller connectivity failures and certificate validation problems. |
| 86 | COOP Endpoint Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures endpoint records distributed by the Council of Oracle Protocol (COOP) from leaf nodes to spine nodes. COOP synchronizes endpoint location information (IP-to-MAC-to-port mapping) across the ACI fabric's spine proxy. Used for fabric-wide endpoint tracking and overlay forwarding path analysis, validating that endpoints are correctly registered in the spine proxy database. |
| 87 | Endpoint Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures registered endpoints within the Big Cloud Fabric, including VMs and physical hosts connected to virtual or physical leaf switches. Maps endpoint identities (IP, MAC) to fabric attachment points (switch, port, VLAN). Used for endpoint location tracking and traffic path computation in BCF environments across multi-tenant overlay networks. |
| 88 | Enterprise Route Table | VMware VeloCloud | SD-WAN Edge | VeloCloud SD-WAN | Captures routes aggregated at the enterprise level across all VeloCloud Edge deployments, including LAN prefixes, overlay routes, and BGP-learned routes. Represents the full routing view within a VeloCloud SD-WAN organization, enabling path analysis from any site to any destination including MPLS, internet, and overlay paths. |
| 89 | EPG Contract Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures the association between Endpoint Groups and their consumed or provided contracts within the ACI policy model. Maps which EPGs communicate via which contracts, enabling analysis of allowed communication paths between application tiers. Validates segmentation policy in ACI multi-tier deployments and identifies unauthorized or missing contract relationships. |
| 90 | External EPG Mapping Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures External Bridge Domain and External Routed Network EPG configurations, mapping external IP subnets to ACI policy domains. External EPGs define how traffic from outside the fabric is classified into policy constructs. Enables path analysis for north-south traffic between external networks and ACI workloads, validating L3Out configuration and prefix classification. |
| 91 | FHRP Table | Cisco Viptela | Cisco SD-WAN Edge | Viptela SD-WAN | Captures First Hop Redundancy Protocol (HSRP/VRRP) state on Cisco SD-WAN WAN edges at branch sites. Reflects active/standby gateway state for LAN-side hosts. Enables analysis of gateway failover behavior and validates redundant default gateway configuration, including tracking active vs. standby WAN edge roles for LAN-connected clients. |
| 92 | Filter Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures filter entries defining the Layer 4 match criteria (protocol, source/destination port) used within ACI contracts. Filters are the atomic building blocks of ACI security policy. Enables detailed analysis of what traffic is permitted or denied by ACI contracts, supporting policy audit and compliance validation for east-west micro-segmentation in ACI. |
| 93 | Global Endpoint Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Reflects the fabric-wide endpoint database maintained by spine nodes, aggregating all known endpoints with their IP, MAC, EPG, and physical attachment information. Provides a unified view of all active endpoints across the ACI fabric, enabling full-fabric path computation, endpoint lifecycle tracking, and detection of duplicate IP or MAC entries in the ACI endpoint database. |
| 94 | Google Cloud NAT Mapping Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures active Cloud NAT translation entries for Google Cloud Router-associated NAT gateways. Maps internal VM source IPs and ports to external NAT IP and port allocations. Supports analysis of outbound connectivity paths for private Google Cloud VMs and validates SNAT port pool utilization and NAT gateway capacity planning. |
| 95 | Google Cloud Router BGP Sessions Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures BGP peering session state for Cloud Routers, including peer IP, ASN, and session status for Cloud Interconnect and Cloud VPN connections. Provides visibility into the BGP control plane for Google's hybrid connectivity solutions, enabling adjacency health monitoring and session diagnostics for multi-path hybrid routing. |
| 96 | Google Cloud Router VLAN Attachment Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures VLAN attachment configurations for Cloud Interconnect circuits in Google Cloud. VLAN attachments define the Layer 2 connection between Google's network and customer on-premises equipment. Models the physical and logical attachment topology for dedicated and partner interconnect deployments, including bandwidth allocation and pairing key associations. |
| 97 | Google Cloud VPN Tunnels Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures VPN tunnel configurations for Classic and HA VPN gateways in Google Cloud. Includes local/remote gateway IPs, IKE configurations, traffic selectors, and tunnel status. Models site-to-site VPN connectivity between Google Cloud and on-premises or multi-cloud environments, including HA VPN redundancy and dynamic routing via BGP. |
| 98 | Google Dedicated Interconnect Physical Connections Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures the physical port and facility details for dedicated interconnect circuits between Google's colocation facilities and customer networks. Reflects circuit capacity, connection state, and assigned ports. Models the physical underlay of hybrid connectivity for large-scale Google Cloud deployments requiring dedicated bandwidth. |
| 99 | Google Dedicated Interconnect VLAN Attachment Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures VLAN-level logical connections for dedicated interconnect circuits, including VLAN IDs, bandwidth allocations, and associated Cloud Router configurations. Models the Layer 2-to-3 boundary for dedicated interconnect, enabling analysis of VLAN segmentation and routing policy for hybrid paths requiring dedicated private connectivity. |
| 100 | Google Firewall Policies Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures hierarchical firewall policy configurations applied at the organization, folder, or VPC level in Google Cloud. Firewall policies allow centralized management of network access controls across multiple projects. Enables analysis of inherited and delegated firewall rules across Google Cloud's resource hierarchy, supporting enterprise-wide security governance. |
| 101 | Google Firewall Rules Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Collects all VPC firewall rules configured in Google Cloud projects, including ingress and egress rules with source/destination tags, service accounts, and CIDR-based matching. Google Cloud firewall rules are stateful and applied at the VM instance level. Models east-west and north-south access controls for GCP workloads, supporting micro-segmentation analysis. |
| 102 | Google Load Balancer Backend Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures backend service and instance group configurations for Google Cloud load balancers. Includes backend VM groups, health check associations, capacity settings, and balancing modes. Models the server pool composition for GCP load balancers and validates backend health and traffic distribution, including managed instance group auto-scaling integration. |
| 103 | Google Load Balancer Forwarding Rules Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures forwarding rule configurations that define the frontend IP, port, and protocol for Google Cloud load balancers. Forwarding rules are the entry points for load-balanced traffic. Models the traffic entry topology for GCP applications and maps frontend IPs to backend services across global and regional load balancer types. |
| 104 | Google Load Balancer Host and Path Rules Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures URL map configurations defining host-based and path-based routing for Google Cloud HTTP(S) load balancers. These rules direct traffic to different backend services based on URL patterns. Enables analysis of application traffic routing logic in GCP Layer 7 load balancing deployments, supporting multi-service routing and traffic splitting. |
| 105 | Google Partner Interconnect Physical Connections Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures physical connectivity details for partner interconnect circuits, reflecting the service provider's connection to Google's network. Models the physical underlay of partner-mediated hybrid connectivity without requiring customer colocation at Google facilities. Includes partner service provider, bandwidth, and connection state. |
| 106 | Google Partner Interconnect VLAN Attachment Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures VLAN attachment configurations for partner interconnect circuits, including VLAN IDs, bandwidth tiers, and pairing keys. Models the Layer 2 logical connections through a partner provider to Google Cloud, enabling analysis of partner interconnect topology for hybrid path analysis and bandwidth management. |
| 107 | Google VPC DNS Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures Cloud DNS zone and record configurations within Google Cloud VPCs, including private DNS zones, peering zones, and forwarding zones. DNS configuration directly influences service discovery and traffic routing. Enables analysis of DNS-based service resolution paths and validates DNS configuration for GCP workloads including private zone inheritance. |
| 108 | Google VPC Endpoint Group Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures network endpoint group (NEG) configurations in Google Cloud, including GCE VM NEGs, serverless NEGs, Private Service Connect NEGs, and internet NEGs. NEGs are the flexible backend building blocks for GCP load balancers. Models heterogeneous backend topologies in GCP applications including containers, serverless, and hybrid targets. |
| 109 | Google VPC Instance Group Members Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures individual VM instances within managed and unmanaged instance groups in Google Cloud. Maps VMs to their containing groups with health and status information. Enables analysis of compute group composition and validates instance availability for load-balanced applications, including auto-healing and auto-scaling state visibility. |
| 110 | Google VPC Instance Group Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures managed and unmanaged instance group configurations in Google Cloud, including group size, template, and associated autoscaling policies. Instance groups are the primary compute backend for GCP load balancers and managed deployments. Models compute cluster topology for application path analysis and capacity planning. |
| 111 | Google VPC Peerings Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures VPC network peering configurations in Google Cloud, including peer network IDs, active state, and route exchange settings. Models peer-to-peer connectivity topology and validates route exchange for peered GCP networks. Supports analysis of transitive peering restrictions and custom route import/export policies in GCP VPC mesh architectures. |
| 112 | Google VPC PSC Endpoints Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures Private Service Connect (PSC) endpoint configurations in Google Cloud VPCs, mapping private endpoints to Google-managed or partner services. PSC endpoints provide private access to services without internet exposure. Models private service access paths in GCP, analogous to AWS PrivateLink, supporting endpoint topology analysis. |
| 113 | Google VPC Routes Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures all routes in Google Cloud VPC routing tables, including default routes, static routes, peering routes, and BGP-learned dynamic routes. Primary forwarding basis for GCP path analysis. Determines next-hop for traffic from any VM to any destination within or outside the VPC, including priority-based route selection and tag-based route scoping. |
| 114 | Google VPC Subnets Table | Google Cloud Platform | Public Cloud (GCP) | Google Cloud | Captures subnet configurations within Google Cloud VPCs, including CIDR ranges, region, secondary IP ranges (for GKE), and Private Google Access settings. Defines the IP addressing and network segmentation within GCP. Foundational for path and addressing analysis, including alias IP range validation for container workloads. |
| 115 | Handoff Assignments Table | VMware VeloCloud | SD-WAN Edge | VeloCloud SD-WAN | Captures the configuration of how VeloCloud Gateways hand off traffic to MPLS or internet underlay networks, including BGP session parameters and route exchange with carrier networks. Models the WAN provider integration points in VeloCloud deployments, enabling analysis of gateway-to-carrier routing and underlay prefix exchange. |
| 116 | Interface Group Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures logical groupings of physical and virtual switch interfaces used for policy application within Big Cloud Fabric. Interface groups simplify policy attachment to multiple ports. Models the fabric's interface topology and is used to analyze how physical ports are organized for tenant workload connectivity and traffic policy enforcement. |
| 117 | IPsec VPN Table | Check Point | Next-Gen Firewall | CheckPoint R80 API | Captures site-to-site VPN tunnel configurations and state from Check Point Security Gateways. Includes encryption domains, IKE phase settings, tunnel status, and SA lifetime information. Models VPN topology between Check Point gateways and remote peers, enabling path analysis for encrypted inter-site traffic and detection of mismatched tunnel configurations. |
| 118 | IPsec VPN Table[Real-time] | Aruba Networks | SD-WAN / WAN Edge | Aruba Orchestrator | Captures live state of IPsec VPN tunnels managed by Aruba Orchestrator, including tunnel status, SA lifetimes, and traffic statistics. Real-time designation indicates dynamic polling from device state rather than configuration. Enables active monitoring of VPN health, session visibility, and rapid diagnosis of VPN connectivity failures in Aruba-managed WAN environments. |
| 119 | IPsec VPN Table[Real-time] | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures live IPsec tunnel state from Meraki MX appliances, including AutoVPN spoke-to-hub and third-party VPN tunnel status. Real-time data reflects current connectivity rather than configured intent. Enables monitoring of VPN fabric health across cloud-managed Meraki branch deployments, including per-site tunnel health in hub-spoke AutoVPN topologies. |
| 120 | IPsec VPN Table[Real-time] | VMware VeloCloud | SD-WAN Edge | VeloCloud SD-WAN | Captures live state of IPsec tunnels used for third-party VPN connections from VeloCloud Edges. Complements the SD-WAN overlay mesh with visibility into static IPsec peer connectivity. Real-time data enables active monitoring of hybrid VPN fabric health in VMware SD-WAN environments with third-party device integration. |
| 121 | IPsec VPN Table[Real-time] | Versa Networks | SD-WAN / Multi-Tenant NFV | Versa SD-WAN | Captures live IPsec tunnel state from Versa FlexVNF appliances, including phase 1/2 SA status and traffic counters for encrypted WAN links. Real-time collection reflects current operational state. Enables monitoring of Versa SD-WAN encrypted overlay tunnel health, including per-VRF tunnel status in multi-tenant Versa deployments. |
| 122 | IPsec VPN Table[Real-time] | Cisco Viptela | Cisco SD-WAN Edge | Viptela SD-WAN | Captures live IPsec/GRE tunnel state from vEdge and cEdge routers, including BFD liveness and SA status for data plane tunnels in Cisco SD-WAN. Real-time collection reflects current fabric health. Enables per-tunnel granularity monitoring of Cisco SD-WAN encrypted overlay connectivity, including color-specific tunnel health. |
| 123 | Kubernetes Ingress Rule Table | Kubernetes / CNCF | Container Orchestration | Kubernetes Cluster | Captures Ingress resource rules from Kubernetes clusters, defining host-based and path-based HTTP/HTTPS routing to backend services. Ingress rules configure Layer 7 routing policy for external access to cluster workloads. Models application traffic entry paths into Kubernetes and is used for service reachability analysis across Ingress controller implementations. |
| 124 | Kubernetes Ingress Virtual Route Table | Kubernetes / CNCF | Container Orchestration | Kubernetes Cluster | Captures computed virtual routing entries derived from Ingress resources, reflecting how Ingress controllers translate Ingress rules into actual forwarding decisions. Provides the operational routing view for Kubernetes Ingress, enabling path analysis from external clients through the Ingress controller to backend pods and services. |
| 125 | Kubernetes Node Port Table | Kubernetes / CNCF | Container Orchestration | Kubernetes Cluster | Captures NodePort service configurations in Kubernetes clusters, including service port, node port allocation, and target pod port mappings. NodePort services expose cluster workloads on all node IPs at a static port. Models external access paths via node-level port forwarding and validates direct node access to services from external clients. |
| 126 | Kubernetes Node Virtual Route Table | Kubernetes / CNCF | Container Orchestration | Kubernetes Cluster | Captures per-node routing entries used for pod network connectivity, including pod CIDR assignments and CNI-managed routes. Reflects how pods on different nodes communicate across the cluster network fabric. Models the L3 routing topology within Kubernetes node networks for east-west path analysis, including CNI overlay and underlay routes. |
| 127 | Kubernetes Service Backend Table | Kubernetes / CNCF | Container Orchestration | Kubernetes Cluster | Captures the endpoint slices and backend pod IPs associated with each Kubernetes Service. Maps services to their current healthy pod backends based on label selectors and readiness state. Enables analysis of runtime service-to-pod binding, validating that traffic directed to a service reaches the correct application instances after pod scheduling changes. |
| 128 | Kubernetes Service Virtual Route Table | Kubernetes / CNCF | Container Orchestration | Kubernetes Cluster | Captures the virtual IP (ClusterIP) routing entries maintained by kube-proxy or eBPF-based CNI for Kubernetes Services. Reflects how ClusterIP traffic is DNAT'd to backend pod IPs. Models the service mesh routing layer within Kubernetes and enables path tracing from service VIP to actual pod endpoints across all nodes. |
| 129 | Logical Router Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures logical router configurations within Big Cloud Fabric, including tenant VRFs, routing protocols, and interface attachments. Big Switch logical routers provide L3 routing between tenant segments. Models the L3 topology of the BCF overlay and enables inter-segment path analysis within multi-tenant deployments, including tenant route isolation. |
| 130 | MAC Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures the L2 forwarding table entries from ACI leaf nodes, mapping MAC addresses to physical ports and EPG bindings. ACI builds this table through both data-plane learning and COOP distribution. Enables L2 path analysis within ACI bridge domains and validates physical endpoint attachment to the fabric, including VM MAC tracking across vPC ports. |
| 131 | MAC Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures MAC address-to-port mappings from Meraki MS switches via the Dashboard API. Reflects L2 forwarding state for connected clients and devices. Enables endpoint location tracking, L2 path analysis, and troubleshooting of connectivity issues in Meraki-managed campus and branch deployments, including per-VLAN MAC table isolation. |
| 132 | MAC Table | Citrix / NetScaler | ADC Management Platform | Citrix ADM | Captures MAC address forwarding entries from Citrix ADC instances managed through Application Delivery Management. Maps MAC addresses to ADC interfaces, enabling L2 visibility around load balancer data paths. Supports troubleshooting of ARP and L2 forwarding issues in Citrix ADC-managed traffic paths, including VLAN-tagged interface MAC tables. |
| 133 | MAC Table | Citrix SD-WAN | SD-WAN Appliance | Citrix SDWAN | Captures MAC address-to-interface mappings from Citrix SD-WAN appliances. Reflects L2 forwarding state for LAN-connected devices behind SD-WAN WAN edges. Enables endpoint location identification and L2 path analysis in Citrix SD-WAN branch network deployments, including per-VLAN interface MAC tracking. |
| 134 | MAC Table | Fortinet | Fortinet Management Platform | FortiManager | Captures MAC forwarding entries from FortiGate and FortiSwitch devices managed through FortiManager. Maps MAC addresses to physical interfaces and VLANs across Fortinet-managed network environments. Enables L2 path tracing and endpoint location tracking in Fortinet enterprise deployments, including per-VDOM and per-interface MAC table visibility. |
| 135 | MAC Table | Palo Alto Networks | Next-Gen Firewall | Palo Alto Panorama | Captures MAC address-to-interface mappings from Palo Alto Networks firewalls managed by Panorama. Reflects the L2 forwarding state seen by each firewall, enabling correlation of security events with physical endpoint locations. Supports L2 adjacency validation in Palo Alto-managed perimeter and segmentation environments. |
| 136 | MAC Table | CommScope Ruckus | Wireless Controller | Ruckus SmartZone | Captures MAC address-to-AP-port associations for wireless clients connected to Ruckus access points managed by SmartZone. Maps wireless endpoint MAC addresses to their access point and SSID context. Enables wireless client location tracking and L2 path analysis in Ruckus-managed enterprise wireless deployments, including roaming client tracking. |
| 137 | MAC Table | Versa Networks | SD-WAN / Multi-Tenant NFV | Versa SD-WAN | Captures MAC address forwarding entries from Versa FlexVNF appliances at branch and hub sites. Maps MAC addresses to tenant VRF interfaces and physical underlay ports. Enables L2 endpoint tracking and path analysis at the LAN edge of Versa SD-WAN deployments, including per-tenant VRF L2 table isolation. |
| 138 | MAC Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures MAC address bindings in the NSX-T overlay network, including virtual machine MAC addresses mapped to transport node host TEPs. NSX-T uses a distributed control plane to synchronize MAC learning. Models the L2 fabric of NSX-T logical segments and enables VM-to-VM path analysis with MAC-level forwarding visibility. |
| 139 | MAC Table | VMware | Virtualization Platform | VMware vCenter | Captures MAC address-to-virtual switch port mappings for VMs managed by vCenter. Maps VM MAC addresses to their virtual switch (vSwitch/dvSwitch), portgroup, and host context. Enables visibility into the virtual L2 network layer for vCenter-managed workloads, including MAC address conflict detection in virtual environments. |
| 140 | NAT Table | Check Point | Next-Gen Firewall | CheckPoint R80 API | Captures static, dynamic, and hide NAT rule configurations from Check Point Security Gateways. NAT rules define address translation for traffic traversing the firewall. Models inbound and outbound NAT topology, enabling analysis of translated traffic paths and IP identity transformation through Check Point firewalls, including NAT rule priority and conflict analysis. |
| 141 | NAT Table | Citrix / NetScaler | ADC Management Platform | Citrix ADM | Captures NAT configuration from Citrix ADC instances, including LSNAT, SNAT, and VIP-based NAT rules managed through ADM. NAT is central to ADC load balancing and traffic management. Models address translation at the ADC layer and enables path analysis for translated application traffic flows, including RNAT and mapped IP configurations. |
| 142 | NAT Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures NAT rules configured on NSX-T Tier-0 and Tier-1 logical routers, including SNAT, DNAT, reflexive NAT, and no-SNAT rules. NSX-T NAT provides micro-segmentation-aware address translation in the overlay. Models east-west and north-south NAT within NSX-T logical topologies, including per-gateway NAT rule isolation. |
| 143 | NDP Table | Aruba Networks | Cloud Wireless Controller | Aruba Central | Captures IPv6 Neighbor Discovery Protocol bindings from Aruba switches and APs managed via Aruba Central. NDP resolves IPv6 addresses to MAC addresses, analogous to ARP in IPv4. Enables IPv6 endpoint tracking and L2 adjacency validation in Aruba Central-managed IPv6-capable campus networks, including router advertisement tracking. |
| 144 | NDP Table | Aruba Networks | SD-WAN / WAN Edge | Aruba Orchestrator | Captures IPv6 NDP bindings from WAN edge devices managed by Aruba Orchestrator. Maps IPv6 addresses to MAC addresses for overlay and underlay interfaces. Enables IPv6 path analysis and adjacency verification in Aruba SD-WAN environments with IPv6 connectivity, including dual-stack interface NDP validation. |
| 145 | NDP Table | VMware AVI Networks | Application Delivery Controller | AVI | Captures IPv6 Neighbor Discovery entries from Avi Service Engines in AVI Networks (VMware Avi Load Balancer) deployments. Maps IPv6-to-MAC for virtual service endpoints and pool members. Enables IPv6 path validation and L2 adjacency analysis for IPv6-addressed application delivery infrastructure. |
| 146 | NDP Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures IPv6 NDP bindings learned by Big Cloud Fabric switches for tenant workloads using IPv6. Maps IPv6 addresses to MAC addresses across fabric leaf nodes. Enables IPv6 endpoint tracking and path analysis within BCF multi-tenant environments supporting dual-stack and IPv6-only workloads. |
| 147 | NDP Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures IPv6 Neighbor Discovery entries in the ACI fabric's endpoint database. ACI applies NDP suppression in bridge domains similar to ARP suppression, reducing IPv6 control plane floods. Maps IPv6 endpoints to physical attachment points and EPGs within the ACI overlay, supporting dual-stack endpoint tracking. |
| 148 | NDP Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures IPv6 NDP cache entries from Meraki MX and MS devices via the Dashboard API. Maps IPv6-to-MAC for clients and adjacent devices. Enables IPv6 endpoint identification and adjacency verification in Meraki-managed cloud branch environments supporting IPv6 or dual-stack client connectivity. |
| 149 | NDP Table | Extreme Networks | Cloud-Managed Switch / AP | ExtremeCloud IQ | Captures IPv6 NDP bindings from Extreme Networks switches and APs managed via ExtremeCloud IQ. Maps IPv6 addresses to MAC addresses for connected endpoints. Enables IPv6 client tracking and path analysis in Extreme-managed campus and branch network environments with IPv6 or dual-stack deployments. |
| 150 | NDP Table | Fortinet | Fortinet Management Platform | FortiManager | Captures IPv6 NDP cache entries from FortiGate devices managed through FortiManager. Maps IPv6-to-MAC for directly connected hosts and routing neighbors. Enables IPv6 adjacency validation and endpoint identification in Fortinet-managed IPv6 network environments, including per-VDOM NDP table visibility. |
| 151 | NDP Table | Fortinet | NGFW / UTM Appliance | FortinetFortiGate | Captures IPv6 NDP entries directly from FortiGate firewalls via CLI or API. Maps IPv6 addresses to MAC addresses for connected hosts and routing peers. Enables hop-by-hop IPv6 path analysis, validates IPv6 next-hop adjacency, and correlates IPv6 security events with physical endpoints across FortiGate interfaces. |
| 152 | NDP Table | Juniper Networks | AI-Driven Wireless | Juniper Mist API | Captures IPv6 NDP bindings from Juniper switches and APs managed via the Mist cloud platform. Maps IPv6-to-MAC for connected wireless and wired endpoints. Enables IPv6 endpoint tracking and L2 adjacency analysis in Juniper Mist-managed enterprise campus deployments with AI-driven insight correlation. |
| 153 | NDP Table | Palo Alto Networks | Next-Gen Firewall | Palo Alto Panorama | Captures IPv6 NDP cache entries from Palo Alto firewalls managed by Panorama. Maps IPv6 addresses to MAC addresses at firewall interfaces. Enables IPv6 endpoint identification and adjacency verification for Palo Alto-managed security enforcement in IPv6-enabled network environments. |
| 154 | NDP Table | CommScope Ruckus | Wireless Controller | Ruckus SmartZone | Captures IPv6 NDP bindings for wireless clients connected to Ruckus APs managed by SmartZone. Maps client IPv6 addresses to MAC and AP context. Enables wireless IPv6 endpoint tracking and validates IPv6 connectivity for clients in Ruckus SmartZone-managed enterprise wireless networks with IPv6 support. |
| 155 | NDP Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures IPv6 NDP bindings in the NSX-T overlay, including VM IPv6 addresses mapped to MAC and transport node context. NSX-T applies NDP suppression on IPv6 logical segments. Enables IPv6 endpoint tracking within NSX-T virtual networks and supports IPv6 east-west path analysis for dual-stack workloads. |
| 156 | NDP Table | VMware | Virtualization Platform | VMware vCenter | Captures IPv6 NDP mappings for VMs managed by vCenter, associating VM IPv6 addresses with MAC and virtual switch ports. Enables IPv6 endpoint visibility in vCenter-managed virtual environments and supports IPv6 path tracing through the virtual network infrastructure for dual-stack VM deployments. |
| 157 | NSX-T DFW Policy Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures Distributed Firewall policy configurations in VMware NSX-T, including security policy sections, rule order, scope, and enforcement points. The DFW is applied at the vNIC level of each VM, enabling micro-segmentation independent of physical network topology. Models the zero-trust security fabric in NSX-T environments, supporting policy audit and compliance validation. |
| 158 | NSX-T Firewall Rules Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures individual DFW and Gateway Firewall rule entries in VMware NSX-T, including source, destination, service, action, and applied-to scope. Defines allowed and denied traffic at VM-level granularity. Enables complete policy analysis and compliance validation for east-west segmentation in NSX-T environments, including rule conflict and shadow detection. |
| 159 | NSX-T Gateway HA Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures high availability state for NSX-T Tier-0 and Tier-1 gateway instances, including active/standby node assignment and HA mode configuration (active/active or active/standby). Gateway HA ensures routing continuity for north-south traffic. Enables monitoring of gateway failover state and validating redundancy in NSX-T routing deployments. |
| 160 | NSX-T Gateway Policy Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures gateway firewall policy configurations for Tier-0 and Tier-1 gateways in VMware NSX-T. Gateway firewall rules control north-south traffic at the perimeter of the NSX-T overlay. Models traffic access controls enforced at routing boundaries between the NSX-T overlay and physical networks, including intra-tier gateway security. |
| 161 | NSX-T Gateway Route Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures routing entries on NSX-T Tier-0 and Tier-1 gateways, including connected, static, and BGP-learned routes. Tier-0 gateways peer with physical infrastructure via BGP; Tier-1 gateways provide tenant-level routing. Models north-south and east-west routing decisions in the NSX-T overlay with per-gateway routing table visibility. |
| 162 | NSX-T Groups Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures security group (NSX-T Group) definitions, including membership criteria based on VM tags, IP sets, MAC sets, or segment ports. Groups are the primary policy scoping construct in NSX-T DFW. Enables analysis of dynamic group membership, validating that workloads are correctly included in intended security perimeters as VMs are provisioned or moved. |
| 163 | NSX-T LB APP Profile Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures Layer 7 application profile configurations for NSX-T load balancers, including persistence profiles (cookie, source IP), connection settings, and SSL passthrough configuration. App profiles define application-specific behavior for load-balanced services. Models session handling and application-aware traffic processing in NSX-T LB deployments. |
| 164 | NSX-T LB Pool Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures load balancer pool configurations in VMware NSX-T, including pool members (VMs/IPs), load balancing algorithm, health monitors, and active/passive member settings. Pools define the backend server groups for NSX-T virtual servers. Models application tier composition and validates backend availability for NSX-T-native load balancing. |
| 165 | NSX-T LB Virtual Service Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures virtual server configurations for NSX-T load balancers, including virtual IP, port, protocol, application profile, and associated pool binding. Virtual services define the frontend entry points for load-balanced applications within the NSX-T overlay. Models L4-L7 service exposure in NSX-T environments with per-tenant VIP visibility. |
| 166 | NSX-T Segment MAC Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures MAC address bindings for endpoints connected to NSX-T logical segments. Maps VM MAC addresses to their segment binding and host transport node. Models the L2 forwarding state within NSX-T overlay segments and enables MAC-level path analysis for east-west traffic in the virtual network, including cross-segment MAC isolation. |
| 167 | NSX-T Segment Neighbor Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures ARP and NDP bindings for endpoints on NSX-T logical segments, including IP-to-MAC mappings learned via ARP suppression or direct resolution. Provides L3 adjacency visibility within NSX-T segments and supports hop-by-hop path analysis for IP traffic between workloads in the NSX-T overlay fabric. |
| 168 | NSX-T Service Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures service object definitions within the NSX-T policy framework, including protocol/port combinations used as match criteria in DFW and Gateway Firewall rules. Services define the traffic types controlled by NSX-T policy. Enables analysis of service-level policy granularity and validates protocol/port coverage in NSX-T security policies. |
| 169 | NSX-T Tunnel Endpoint Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures the VXLAN/GENEVE tunnel endpoint (TEP) configurations for NSX-T transport nodes (ESXi hosts, KVM, Bare Metal). TEPs are the encapsulation endpoints for the NSX-T overlay fabric. Models the underlay-to-overlay binding, essential for full-path analysis of traffic flowing through the NSX-T transport zone including VTEP IP assignments. |
| 170 | NSX-T Virtual Machine Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures VM inventory and NSX-T context for all virtual machines managed by NSX-T, including VM-to-segment attachment, security group membership, and logical port assignment. Bridges vCenter compute topology with NSX-T network policy context, enabling policy-aware VM path analysis and inventory-driven security group validation. |
| 171 | Policy Table | Check Point | Next-Gen Firewall | CheckPoint R80 API | Captures the full security policy rulebase from Check Point Security Management, including access rules, source/destination zones, services, and actions across all policy layers. Check Point policies are layered and ordered. Enables complete firewall policy analysis, rule shadowing detection, and compliance validation for Check Point-managed security environments. |
| 172 | Policy Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures Layer 3/7 firewall rules and group policies from Meraki MX appliances via the Dashboard API. Policies define allowed and blocked traffic for Meraki network segments. Enables analysis of cloud-managed security policy across Meraki branch deployments, including per-SSID wireless policy and group policy rule analysis. |
| 173 | Route Learned Table | Aruba Networks | SD-WAN / WAN Edge | Aruba Orchestrator | Captures dynamically learned routes (BGP, OSPF, static redistribution) on Aruba SD-WAN edge devices as observed by Orchestrator. Unlike the configured route table, reflects the operational routing state derived from route learning processes. Enables validation of dynamic routing convergence in Aruba SD-WAN topologies and detection of route learning failures. |
| 174 | Route Table | Aruba Networks | SD-WAN / WAN Edge | Aruba Orchestrator | Captures the full routing table from Aruba WAN edge appliances managed by Orchestrator, including static and dynamic routes for both overlay and underlay network paths. Central to SD-WAN path computation, enabling analysis of traffic forwarding decisions across the Aruba SD-WAN fabric, including per-VRF routing table isolation. |
| 175 | Route Table | VMware AVI Networks | Application Delivery Controller | AVI | Captures routing entries from Avi Service Engines, including default routes and static routes configured for traffic forwarding. Avi uses routing for management plane connectivity and for reaching backend servers and clients. Enables path analysis in single-arm and inline Avi SE deployments, validating next-hop reachability for virtual service traffic. |
| 176 | Route Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures L3 routing entries from Big Cloud Fabric logical routers, including static and dynamic routes within tenant VRFs. BCF's SDN-based routing is centrally computed and distributed to hardware forwarding elements. Models tenant-level routing topology and enables inter-segment path analysis in BCF multi-tenant environments. |
| 177 | Route Table | Check Point | Next-Gen Firewall | CheckPoint R80 API | Captures the IP routing table from Check Point Security Gateways, including static, connected, and dynamic routes across all routing daemon (Gaia OS) sources. Check Point gateways participate in network routing alongside security enforcement. Enables firewall path analysis, validates routing state for policy enforcement, and diagnoses connectivity through gateway clusters. |
| 178 | Route Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures L3 routing entries from ACI border leaf nodes and L3Out configurations, including routes leaked from tenant VRFs to external networks. ACI routes are computed by APIC and distributed to leaf nodes. Models north-south routing in ACI environments and enables path analysis for external network connectivity via L3Outs. |
| 179 | Route Table | Cisco | Next-Gen Firewall (FTD) | Cisco FMC | Captures routing table entries from Firepower Threat Defense appliances managed by FMC, including static and dynamic routes on all routed interfaces. FTD participates in network routing at the perimeter alongside security enforcement. Enables path analysis for traffic traversing FTD firewalls and validates routing state for policy enforcement. |
| 180 | Route Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures routing table entries from Meraki MX appliances, including static routes, AutoVPN overlay routes, and BGP-learned routes. Enables analysis of branch-to-branch and site-to-cloud routing decisions in Meraki SD-WAN deployments and validates WAN path selection for application traffic across AutoVPN mesh topologies. |
| 181 | Route Table | Citrix / NetScaler | ADC Management Platform | Citrix ADM | Captures routing entries from Citrix ADC (NetScaler) instances managed through Application Delivery Management. ADC instances use routing for SNIP reachability and backend server connectivity. Enables path analysis for ADC-managed application traffic and validates routing to backend server pools and client-facing networks. |
| 182 | Route Table | Citrix SD-WAN | SD-WAN Appliance | Citrix SDWAN | Captures routing entries from Citrix SD-WAN appliances including static, OSPF, and BGP routes for both LAN and WAN segments. Citrix SD-WAN performs intelligent path selection based on routing and application policies. Enables analysis of SD-WAN routing decisions and branch-to-branch path computation across Citrix-managed WAN topologies. |
| 183 | Route Table | Extreme Networks | Cloud-Managed Switch / AP | ExtremeCloud IQ | Captures IP routing entries from Extreme Networks switches managed via ExtremeCloud IQ. Includes static and OSPF routes for inter-VLAN routing and uplink connectivity. Enables path analysis for campus and branch networks managed through the Extreme cloud management platform, validating L3 forwarding state for managed devices. |
| 184 | Route Table | Fortinet | Fortinet Management Platform | FortiManager | Captures routing table entries from FortiGate devices managed through FortiManager, including static, connected, and BGP/OSPF dynamic routes across all VDOMs. FortiGate participates in enterprise routing alongside security enforcement. Enables full path analysis for traffic traversing Fortinet-managed networks and validates routing correctness for policy enforcement. |
| 185 | Route Table | Fortinet | NGFW / UTM Appliance | FortinetFortiGate | Captures the complete IP routing table directly from FortiGate firewalls, including all route sources (static, connected, BGP, OSPF, RIP) across all VDOMs. FortiGate operates as both security and routing device. Foundational forwarding reference for path analysis through FortiGate, validating routing correctness for all traffic policies and segmentation. |
| 186 | Route Table | Progress Kemp | Load Balancer Appliance | Kemp LB | Captures routing entries configured on Kemp LoadMaster appliances, including static routes for backend server and client network reachability. Kemp uses routing to reach virtual service clients and pool members. Enables path analysis for Kemp LB deployments and validates routing to application backends, including return route validation for asymmetric traffic flows. |
| 187 | Route Table | Palo Alto Networks | Next-Gen Firewall | Palo Alto Panorama | Captures IP routing tables from Palo Alto Networks firewalls managed by Panorama, including static, connected, and BGP/OSPF routes per virtual router. Palo Alto firewalls integrate routing with security policy enforcement. Enables firewall path analysis, routing validation, and hop-by-hop path tracing through Palo Alto-managed networks. |
| 188 | Route Table | Ivanti Pulse Secure | VPN / Zero-Trust Gateway | PulseSecure API | Captures routing entries from Pulse Connect Secure and Pulse Policy Secure appliances. Routes define how VPN-connected users and split-tunnel traffic is forwarded. Enables analysis of VPN routing topology, validates tunnel routing for remote access users, and diagnoses connectivity through Pulse VPN gateways including split-tunnel route management. |
| 189 | Route Table | CommScope Ruckus | Wireless Controller | Ruckus SmartZone | Captures routing entries from SmartZone controllers and associated switches, including static routes for management and data plane connectivity. Enables path analysis for traffic in Ruckus-managed enterprise wireless environments and validates network routing for SmartZone-managed infrastructure including VLAN uplink routing. |
| 190 | Route Table | VMware VeloCloud | SD-WAN Edge | VeloCloud SD-WAN | Captures full routing tables from VeloCloud Edge devices, including overlay SD-WAN routes, MPLS routes, internet routes, and LAN static/BGP routes. VeloCloud route tables reflect the outcome of application-aware routing policy and Business Policy rules. Central to SD-WAN path analysis across the VMware SD-WAN fabric. |
| 191 | Route Table | Versa Networks | SD-WAN / Multi-Tenant NFV | Versa SD-WAN | Captures routing entries from Versa FlexVNF appliances per tenant VRF, including SD-WAN overlay routes, BGP/OSPF dynamic routes, and static entries. Versa's multi-tenant architecture maintains per-tenant routing domains. Enables per-VRF path analysis and validates routing within Versa SD-WAN enterprise and service provider deployments. |
| 192 | Route Table | Cisco Viptela | Cisco SD-WAN Edge | Viptela SD-WAN | Captures OMP routes and traditional routing entries from vEdge and cEdge routers in Cisco SD-WAN. Uses OMP to distribute overlay routes from vSmart controllers. Models the full routing topology of Cisco SD-WAN sites and enables end-to-end path analysis across the SD-WAN fabric, including per-color route attributes. |
| 193 | Route Table | VMware | Virtual Network (NSX-T) | VMware NSX-T | Captures routing entries on NSX-T Tier-0 and Tier-1 gateways, reflecting the overlay routing topology for virtual workloads. NSX-T routes are computed by the centralized management plane and distributed to Edge nodes and TEPs. Enables full overlay routing path analysis for north-south and east-west traffic in NSX-T environments. |
| 194 | Route Table | VMware | Virtual Network (NSX-V) | VMware NSX-V | Captures routing entries from NSX-V Distributed Logical Routers (DLR) and Edge Service Gateways (ESG). NSX-V provides distributed routing within vSphere environments. Models the virtual routing topology for NSX-V deployments, enabling path analysis for east-west and north-south traffic in legacy NSX environments requiring migration assessment. |
| 195 | SDWAN OMP Route Table | Cisco Viptela | Cisco SD-WAN Edge | Viptela SD-WAN | Captures OMP (Overlay Management Protocol) route entries distributed by vSmart controllers to vEdge and cEdge routers. OMP is the Cisco SD-WAN control plane protocol, carrying routes, policies, and encryption keys. Represents the authoritative routing view for the Cisco SD-WAN overlay, central to fabric-wide path analysis and policy validation. |
| 196 | Segment Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures logical network segment definitions within Big Cloud Fabric, including tenant-specific Layer 2 broadcast domains with VXLAN-based overlay encapsulation. Segments map to physical switch ports and virtual interfaces. Models the L2 topology for BCF multi-tenant deployments and enables path analysis within and between segments, including VXLAN VNI assignments. |
| 197 | Service Graph Mapping Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures service graph configurations defining insertion of network services (firewall, load balancer, IDS) between EPGs in Cisco ACI. Service graphs steer traffic through service nodes via policy-based redirect. Models service chain topology in ACI, enabling analysis of traffic paths through inserted L4-L7 service devices and PBR rule validation. |
| 198 | STP Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures Spanning Tree Protocol state from Meraki MS switches, including port roles (root, designated, blocking), bridge priority, and root bridge selection. STP prevents L2 loops in multi-switch environments. Enables analysis of L2 topology convergence and validates loop prevention in Meraki-managed switched campus networks, including RSTP and MSTP topology. |
| 199 | Tenant Table | Big Switch Networks | SDN Fabric Controller | Big Switch | Captures tenant configurations within Big Cloud Fabric, defining isolated multi-tenant network domains with their own routing tables, segment associations, and policy scopes. BCF is inherently multi-tenant. Provides the organizational context for all other BCF tables and enables per-tenant network analysis and segmentation validation across shared fabric infrastructure. |
| 200 | Uplink Table | VMware | Virtualization Platform | VMware vCenter | Captures physical NIC-to-virtual-switch uplink configurations for ESXi hosts managed by vCenter, including NIC teaming policies, load balancing algorithms, and failover order. Uplinks define how VM traffic connects to the physical network fabric. Models the virtual-to-physical network boundary and validates NIC redundancy configuration in vCenter environments. |
| 201 | VCG BGP Neighbor Table | VMware VeloCloud | SD-WAN Edge | VeloCloud SD-WAN | Captures BGP peer session details for VeloCloud Gateways (VCG), including peer IP, ASN, session state, and prefix counters for underlay routing with MPLS or internet providers. Enables analysis of gateway-level BGP peering health and validates dynamic routing between VeloCloud Gateways and upstream carriers or IXPs. |
| 202 | Versa Access Circuits Table | Versa Networks | SD-WAN / Multi-Tenant NFV | Versa SD-WAN | Captures WAN access circuit configurations for Versa FlexVNF appliances, including interface type, provider, bandwidth, and circuit health status. Access circuits define the physical WAN links available for SD-WAN path selection. Models the underlay connectivity for Versa SD-WAN and enables WAN link health analysis and capacity planning. |
| 203 | Virtual Server Table | VMware AVI Networks | Application Delivery Controller | AVI | Captures virtual service configurations in AVI Networks (VMware Avi Load Balancer), including VIP, port, application profile, pool associations, and SSL policy. Virtual servers define the frontend endpoints for application delivery. Models L4-L7 service exposure in Avi deployments and enables application traffic path analysis across service engine clusters. |
| 204 | Virtual Server Table | Citrix / NetScaler | ADC Management Platform | Citrix ADM | Captures virtual server (vserver) configurations from Citrix ADC instances managed through Application Delivery Management. Each virtual server defines a VIP, port, protocol, and associated pool binding. Models application entry points in Citrix ADC deployments and enables L4-L7 path analysis for load-balanced applications including CS vservers. |
| 205 | Virtual Server Table | Progress Kemp | Load Balancer Appliance | Kemp LB | Captures virtual service configurations on Kemp LoadMaster appliances, including VIP, port, protocol, balancing algorithm, and backend pool associations. Virtual services define the frontend for load-balanced applications. Models service exposure and traffic distribution logic in Kemp LB deployments, including health check and persistence configuration. |
| 206 | VM Mapping Table | VMware | Virtualization Platform | VMware vCenter | Captures the association between virtual machines and their network topology context, including virtual switch, portgroup, VLAN, and ESXi host placement. Bridges compute and network inventory in vCenter, enabling workload-aware path analysis that correlates VM identity with physical and virtual network topology for connectivity troubleshooting. |
| 207 | VPN Policy Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures VPN routing and split-tunneling policy configurations for Meraki MX appliances, defining which subnets are routed over AutoVPN and which are directed to the internet locally. VPN policies govern SD-WAN traffic steering. Enables analysis of WAN path selection policies in Meraki SD-WAN environments including hub selection and full-tunnel configurations. |
| 208 | VPN Status Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures real-time VPN tunnel operational status for AutoVPN and third-party VPN connections from Meraki MX appliances. Reflects per-tunnel connectivity state, latency, and packet loss metrics. Enables active monitoring of VPN fabric health and supports rapid diagnosis of connectivity failures in Meraki SD-WAN deployments across all AutoVPN spoke sites. |
| 209 | Wireless Endpoint Table | Aruba Networks | Cloud Wireless Controller | Aruba Central | Captures wireless client associations including MAC address, IP, SSID, AP name, signal strength, and authentication state for clients connected to Aruba APs managed via Aruba Central. Enables wireless client tracking, security analytics, and path tracing for WLAN-connected endpoints across centrally managed Aruba wireless infrastructure. |
| 210 | Wireless Endpoint Table | Cisco Meraki | Cloud-Managed Network | Cisco Meraki | Captures wireless client associations from Meraki MR access points via the Dashboard API, including client MAC, IP, SSID, AP, RSSI, and connection state. Enables wireless endpoint visibility, client tracking, and path analysis for Wi-Fi connected devices in Meraki-managed campus and branch environments, including client roaming history. |
| 211 | Wireless Endpoint Table | Juniper Networks | AI-Driven Wireless | Juniper Mist API | Captures wireless client association data from Juniper/Mist APs managed via the Mist cloud platform, including MAC, IP, SSID, AP context, RSSI, and AI-driven client experience metrics. Enables wireless client tracking, AI-driven root cause analysis, and path analysis for Mist-managed Wi-Fi environments with Marvis AI integration. |
| 212 | Zoning Rule Table | Cisco | SDN Fabric (ACI) | Cisco ACI | Captures hardware-programmed zoning rules derived from ACI contracts and filters, as installed on leaf node ASICs in Cisco ACI. Zoning rules are the compiled, enforcement-level representation of ACI policy in TCAM. Enables validation that configured contracts are correctly translated into hardware forwarding entries, ensuring policy enforcement fidelity in ACI environments. |