QS-WAN · The control plane

QS-WAN: the console you run the whole network from

QS-WAN is the control plane. One browser tab that holds every gateway, every enrolled device, every policy and the evidence that any of it happened. It is the piece about 1% of an organisation ever opens, and the reason the other 99% never need a dashboard at all.

QS-WAN Network Map: the Control Tower, two gateways, their teams and the devices behind them
01 · Centralised control

Centralised control, and what that actually means

Every gateway shows as a live card with nine indicators: state, server, websocket, tunnel, heartbeat, assigned IP, update status, and current users, download and upload.

Nine indicators per gateway

Those separate on purpose.

The tunnel, the VPN server and the control channel can fail independently, and a product that shows you one green light for all three is hiding the failure you need to see.

One honest limit, said up front.

The database is authoritative; delivery out to gateways and clients is best effort. A green response tells you the intent was recorded. It does not tell you a laptop that’s been shut since Friday has already obeyed it. When the device comes back, it converges.

02 · Gateways

Managing a fleet of gateways

A gateway comes two ways, and the console treats them the same either way.

On-premise

Hardware at the site: your own, or a unit we ship you.

Virtual, in your cloud

The same gateway, running in your cloud instead of a rack.

Gateway Sync

Checks what a gateway is actually running against what you asked for, and pushes the difference.

Gateway settings

They show you the rendered configuration file, not a form that hides it. Overrides are visible.

When Tower Connection is off, changes save but don't get pushed.

The console says so. The intent is recorded and it converges when the gateway is reachable again.

03 · Network Map

The Network Map

The network drawn as a picture: gateways, VLANs, the LANs next door, discovered hosts, and how traffic is allowed to move between them.

It's the fastest way to answer the question that usually takes three people and a spreadsheet, which is “can this device reach that server, and why”.

Gateway VLAN VLAN LAN HOSTS
  • Bidirectional
  • Unidirectional
  • Disabled
04 · Security Dashboard

The Security Dashboard

Eight tabs, and the one people look at first is the risk score.

QS-WAN Security Dashboard overview with the risk score and the event timeline
indicators
0

The score is built from 19 indicators and it explains itself line by line.

You can see which indicator moved it and by how much. A number you can’t take apart is a number nobody trusts twice.

Also in there: RMF assessments and the ATO lifecycle, a POA&M register, and a compliance crosswalk that maps one control to several frameworks at once so you stop answering the same question four times.

Privacy: the console is yours, and so is the access to it.

Run QS-WAN on your own infrastructure or in your private cloud and every gateway, device, policy, risk score and audit record stays in your installation. The accounts that can open it are the administrators you create, signing in locally or against your own directory.

We are not a security operations centre.

Nobody at QuantumNova watches your network. The dashboard is yours, the score is yours, and the alerts land in your console, not on our desk.

05 · Scanning

Scanning, built into QS-WAN

Runs nmap

Network Scanner

Runs nmap with presets, so you don’t have to remember flags.

Scans web apps

Web Scanner

Scans your web applications and shows alerts, discovered URLs and technical detail.

Agent telemetry

Host Endpoint Monitoring

Part of QS-WAN, fed by telemetry from the agent on each machine.

QS-WAN Host Endpoint Monitoring mapping alerts to MITRE ATT&CK tactics and techniques

Host Endpoint Monitoring gives you

06 · Audit trail

Events and the audit trail

Every security event lands in a feed you can filter, and every administrator action is written down.

This is the part that turns a security tool into evidence.

When an auditor asks who changed the firewall rule and when, the answer is a query, not an archaeology project.

07 · Company Policy

Company Policy

One signed policy, pushed to the fleet:

8 of 12

Reactive lockdown arms on 8 of the 12 rules.

Not all twelve. If a page tells you every rule triggers automatic revocation, that page is wrong.

08 · WANDA

WANDA, the governed assistant

WANDA is an assistant built into the console. The thing that makes it usable in a regulated environment is that it shows you exactly which fields it would send, before it sends them.

languages
0
09 · Languages

Languages, said precisely

The QS-WAN console ships in 15 languages. Two exceptions, and they matter if language is a formal requirement for you: the Security Dashboard and the 13 Host Endpoint Monitoring pages are English only.

10 · Licensing and administrators

Licensing and administrators

Platform licensing and registration live in the console, alongside per-device licensing, so the thing that generates the bill and the thing that shows the bill are the same screen.

Administrators sign in
QS-WAN administrator sign-in screen with the Login with Entra ID option
Request a demo

See it on your own network

A demo runs about 30 minutes and we point it at your setup, not a sandbox we prepared earlier.

Scroll to Top