QS-WAN · Fleet

Remote device management that shows you which part broke

Remote device management runs from one browser tab. Every gateway shows up as a live card with nine indicators, and the tunnel, the VPN server and the control channel each get their own. Pairing, config checks, per-gateway settings and over-the-air updates run from that same screen.

What it is

One green light is three questions nobody asked

The gateway is up is a sentence doing far too much work. A gateway can hold its VPN tunnel open while the control channel to the console is dead. It can answer heartbeats while its config file has drifted away from what the console thinks it says. It can be reachable, correctly configured, and two versions behind. Those are three different faults with three different fixes, and a console that rolls them into one status dot has already decided which one you are allowed to see. So you refresh the page to see if it goes green, the way you press a lift button that is already lit. Then somebody gets in a car.

Nine live indicators per gateway

state, server, ws, tunnel, hb, ccd_ip, update status, and current Users, Download and Upload. They are listed separately because they fail separately. Power control and the per-gateway actions sit on the same card.

Pairing, with the waiting made visible

New gateways land in a queue. A hardware gateway waits for you to hit Accept. A software gateway sits at waiting for device claim until its claim code is used, and the remaining validity of that code is on screen, so nobody has to guess whether it is still good.

Sync, settings and updates

Check compares what a gateway is actually running against what the console says it should be, and reports three findings: a missing file, an IP that does not match, and a file that is out of date. Updates run one at a time or across the fleet, and the list polls every 30 seconds.

The mechanism

Break a signal. Then roll the nine into one dot and watch it lie.

Every button here breaks one real signal and leaves the others alone, because that is how they behave. The last button is the one to try: it collapses the nine indicators into a single averaged dot, and the dot keeps reading up.

Lisbonv4.2.1stateserverwstunnelhbccd_ipupdateuserstraffic9 of 9 healthyupPortov4.2.1stateserverwstunnelhbccd_ipupdateuserstraffic9 of 9 healthyupFarov4.2.1stateserverwstunnelhbccd_ipupdateuserstraffic9 of 9 healthyupnine signals, because they fail separately
27 signals across 3 gateways, all healthy

Three gateways, Lisbon, Porto and Faro, each drawn as a card with the nine live indicators the console actually shows: state, server, ws, tunnel, hb, ccd_ip, update, users and traffic. Switching off the control channel on Porto dims its ws signal while its tunnel stays up, because those two fail independently. A config drift on Faro dims ccd_ip, and being two versions behind dims update. The last control rolls all nine indicators into a single dot per gateway, and that single dot reads up on all three cards while the faults are still there. That is the argument of this page: an averaged status has already decided which fault you are allowed to see.

Why this exists

Four things that go wrong without it

One dot has already chosen what you see

A status computed from several checks is easier to design and it is wrong on exactly the morning you need it. Three failures need three lights.

Somebody gets in a car to find out which it was

The drive is not the diagnosis. It is what happens when the diagnosis is not available from a desk, and it costs an afternoon each time.

The config drifted and nothing said so

A gateway can answer heartbeats all day while running a file the console no longer recognises. Nothing in a single status dot notices that.

Are we up to date is answered with a shrug

Without a per-gateway version check, patch status is a promise to find out. That is the answer that costs the most in an assessment.

What you get

The same nine lights, read two very different ways

The person who runs the network wants to know which of three faults it is before anyone gets in a car. The person who signs the invoice wants to know what those car journeys cost across a year.

For the network

Three faults, three lights

A tunnel that is up, a control channel that is dead and a config file that has drifted are three different problems with three different fixes.

Diagnosis from a browser tab

Check Update, Sync Check and the nine indicators answer from your desk what used to need a drive and an afternoon. You still might have to go out there. You will just know why before you leave.

You read the file you are shipping

Gateway settings render the config and the derived values rather than hiding them behind nine friendly toggles, and overrides are visible as overrides.

For the business

Fewer trips, fewer lost afternoons

Every fault identified in a browser is a site visit that does not happen. This is the line item that shrinks first and nobody ever notices, because it is made of things that stopped happening.

Patch status with a date on it

Check Update and Update to a named version run per gateway from the console, so whether you are up to date becomes a screen you show rather than a promise to find out.

Nothing new in the rack

This is part of the console you already run. No extra appliance, no re-addressing, no maintenance window to buy it, and nothing leaves the building.

How it works

Three steps, and the first happens without you

The connection holds, and nobody files a ticket

Your colleague in accounts is working with the QNova Client connected, which is the entire extent of their involvement in this page. If the gateway behind them goes away, the client moves to another one and they keep typing. When something genuinely is wrong, the diagnostics view explains it in words rather than an error code. What they never see is the fleet: no cards, no indicators, no version numbers, because none of that is their job.

The same gateway, with the context the laptop never had

That gateway is on your screen as a card, and the card tells you which part broke rather than that something did. QS-WAN and the client hold one authenticated connection per device, with a handshake signed using ML-DSA, a ping every 30 seconds and a certificate check every 30 seconds, so gone quiet is a measured fact and not a hunch. One connection per device is quieter than it sounds and matters more: there is no second, older session still hanging around and still taking orders.

Then you decide, and the console tells you the truth about what it did

Run Sync Check to find out whether it is a missing file, a mismatched IP or a stale one, and Sync to close the gap. Push the update from the same card, or sweep the fleet, with the list polling every 30 seconds so nobody is leaning on the refresh key. Where the command channel is down, settings are blocked instead of accepting edits they cannot deliver, and with the Tower Connection off a change saves, says so on screen, and converges when the gateway is reachable again.

Before you start

You need the gateways you already run and a browser. Everything on this page is part of the console, so there is nothing to install and nothing to rack.

In detail

The channel underneath it, and the estate you declare on top of it

Channel

One authenticated connection per device

None of this exists without a live path to the device. The console and the client hold one authenticated WebSocket per device. The handshake is signed with ML-DSA and has ten seconds to complete, with a replay window of plus or minus 30 seconds. After that it is a ping every 30 seconds, a 90 second read deadline, and a certificate check every 30 seconds. Eight message types, five close codes, one connection per device.

That last one is quieter than it sounds and matters more. One connection per device means there is no second, older session still hanging around and still taking orders.

Assets

The estate you declare, in the same console

An asset here is a piece of your infrastructure that you declare. Nothing is inferred and nothing shows up by accident. You view and edit declared assets spanning all your gateways from one screen, you attach a device to the asset it belongs to, and in User Management every device carries its state badges plus the name of its asset.

It lives here because a register kept in a separate tool drifts, and keeping two systems honest is nobody favourite job. The console already holds the gateways, the user profiles and the device certificates, so attaching a device to an asset is a change inside the system that issued that certificate rather than a note about it. The inventory filters by gateway, searches, and exports to CSV, which is still the format every auditor asks for.

Where this earns its place

Four mornings this changes

A site goes quiet on a Friday afternoon

The card says the tunnel is up and the control channel is down. That is one fault, not three, and you know it before deciding whether anyone drives anywhere.

A new gateway arrives at a branch

It lands in the pairing queue. You hit Accept, or the claim code gets used, and the remaining validity of that code is on screen rather than guessed at.

An auditor asks whether the fleet is patched

Check Update per gateway answers with versions rather than with a promise to find out before the end of the week.

Somebody asks what that gateway is actually running

The settings screen renders the file and the derived values, with overrides visible as overrides. You read what you are about to ship.

Works better with

What feeds the cards, and what the cards let you do

The device side of the same heartbeat: the rolling graph and the connection details the person at the keyboard can read out to you.

What the control channel makes reachable. Read the plain note there on where assisted remote desktop is in its integration phase.

Where the algorithm choices for the whole fleet live, and where the documented cryptographic inventory per subsystem is explained.

How a device gets its identity in the first place, which is what the pairing queue and the claim code on this page are the gateway version of.

What this does not do

The limits, because they are what make the rest believable

A green response is not proof a device obeyed

The database is authoritative and delivery is best effort. Green tells you the intent was recorded, not that a laptop shut since Friday has already done it. With the Tower Connection off, changes save but are not pushed, and the console says so.

The Control Tower summary card is partial

It shows the version of the first gateway, not a fleet-wide figure. Use the per-gateway Check Update for the real answer, and do not read that card as a rollout report.

Rotating the certificate authority is a scheduled operation

It needs every gateway online and it restarts the VPN service on each one. That belongs in a maintenance window, not in a Tuesday afternoon.

Assisted remote desktop is in integration, not finished

An administrator can take a supported session from the console, and it works, and it is not productised. If taking over a screen remotely is the reason you are reading this page, ask us for its current state before you sign anything. And nobody here watches your fleet: this is a product, not a managed service.

Questions people ask

The ones that come up first

What is remote device management in QS-WAN?

It is the fleet screen. Every gateway appears as a live card with nine indicators, and pairing, config checks, per-gateway settings and over-the-air updates all run from the same place. It is part of the console rather than a separate tool.

Why nine indicators instead of one status?

Because they fail separately. A gateway can hold its tunnel open while the control channel is dead, answer heartbeats while its config has drifted, and be reachable, correct and two versions behind. One averaged dot has already chosen which of those you are allowed to see.

What does the sync check actually compare?

What a gateway is running against what the console says it should be running. It reports three findings: a file that is missing, an IP that does not match, and a file that is out of date. Sync closes the gap.

If the button goes green, is the change live?

Not necessarily. The database is authoritative for what you asked, and delivery is best effort. A gateway with its Tower Connection off saves the intent, says so on screen, and converges when it is reachable again.

Where did the security asset management page go?

Here. Declaring the estate is part of running the fleet, so it is one page on the site. You declare assets, they span every gateway on one screen, devices attach to the asset they belong to, and the inventory filters, searches and exports to CSV. Nothing is discovered for you: anything you never tell the console about is not on the list.

Can you take over a screen remotely?

An administrator can take a supported session from the console, and it is in its integration phase rather than finished. We would rather write that here than let you find out in a demo, so ask us for its current state if that is what you are buying for.

Tell us about the last time somebody had to drive to a site.

We open the fleet screen on a console shaped like yours, break a signal while you watch, and show you which of the nine noticed. It is free, it lasts as long as you want, and there is nothing to sign.

Scroll to Top