QS-WAN · Network Map

Network mapping software that changes the network, not just a picture of it

QS-WAN puts your gateways, VLANs, LANs and the links between sites on a single map. Every edge carries a state: unidirectional, bidirectional, disabled or zero trust. Click an edge and you turn that communication on or off. It is part of the console, not a drawing you maintain.

What it is

The diagram on the shared drive is already wrong

Most teams have a network diagram somewhere. It was accurate the week it was drawn. Since then a VLAN got added, a site picked up a second gateway, and somebody opened a path between two subnets for a project that ended last year. That is not sloppiness. It is what happens when the picture lives in one tool and the network lives in another. A diagram has no way of noticing that something changed, so it sits there being confidently out of date, and people keep using it because it is the only picture there is.

Gateways, VLANs and LANs

Each one as its own object, across every site you run. The map is drawn from the configuration of the console, so it shows what the network is currently set up to do rather than what somebody drew.

The edges between them

This is the part people actually came for. A line means one segment can reach another, and the line is the same object that is being enforced.

A legend that means something

Unidirectional, bidirectional, disabled and zero trust are four different facts about a link, and the map keeps them as four different things instead of one vague line.

The bill arrives later. An auditor asks which segments can reach which, and the honest answer takes two days and three people. Or something breaks, and whether that machine can reach finance gets answered from memory.

The mechanism

Run discovery, click an edge, and watch the legend earn its keep

The sixth object on this map is drawn with a dashed outline and reads not scanned yet, because nothing has looked there. That is a different fact from nothing being there, and drawing them the same way is how people end up trusting an empty corner of a diagram.

Gateway Lisbonsite 1Gateway Portosite 2Finance VLAN10.20.4.0/24Field ops VLAN10.20.9.0/24Server LAN10.0.30.0/24, 14 hostsAdjacent LANnot scanned yetUnidirectionalBidirectionalDisabledZero trust
6 objects, 1 not scanned yet

The map holds two gateways, one in Lisbon and one in Porto, the site link between them, a Finance VLAN on 10.20.4.0/24, a Field ops VLAN on 10.20.9.0/24, and a server LAN on 10.0.30.0/24 with fourteen hosts. A sixth object is drawn with a dashed outline and reads not scanned yet, because discovery has never run on that gateway. Running adjacent LAN discovery turns it into a real segment with an address range and connects it with an edge. Clicking the edge from Finance to the server LAN switches that communication off, and the state is applied in both directions at once. Turning on zero trust for Finance changes the state of its edge to zero trust, which is a separate fact from the direction and is drawn as a separate fact.

Why this exists

Four things that go wrong without it

The picture and the network are two products

The moment the map is a separate purchase from the thing enforcing the rules, the two start disagreeing, and only one of them is right.

The audit question costs two days

Which segments can reach which is asked in every assessment, and reconstructing it from a diagram, a firewall and somebody memory is where the time goes.

Nobody knows about the subnet from the acquisition

It exists, it is reachable, and it is not on any drawing. It turns up in an incident rather than on a map, which is the expensive order.

An empty corner gets read as safe

A blank area of a diagram looks identical whether nothing is there or nothing has looked. People trust the blank, and one of those two readings is wrong.

What you get

One map, two entirely different reasons to want it

The person who runs the network wants to stop answering whether that machine can reach finance from memory. The person who signs the invoice wants to know what a wrong answer costs. It happens to be the same map that settles both.

For the network

No second tool to open

The map and the enforcement are the same system, so changing a path is not a translation exercise between a diagram, a firewall and what you remember. You click the edge you are already looking at.

Drift has nowhere to hide

The picture comes from the configuration, so if the map is wrong, the network is wrong. That is uncomfortable in a useful way.

The segments you forgot turn up

Adjacent LAN discovery scans the gateway side and host discovery fills in the hosts, so the subnet that arrived with an acquisition shows up on a map instead of in an incident.

For the business

The audit answer takes minutes

Which segments can reach which becomes a screen you show, rather than two days and three people reconstructing it.

Nothing is bought and nothing moves

The map is part of the console you are already running. No new appliance, no re-addressing, no maintenance window, and nothing leaves the rack.

One console instead of two products

A map that is a separate purchase from the thing enforcing the rules will eventually disagree with it. Here there is nothing to reconcile, because there is only one of them.

How it works

Three steps, and nobody has to be chased for any of them

Someone connects, and never sees a map

Your colleague in accounts opens the QNova Client and presses connect. If the connection fails, the client names the reason for them, a revoked certificate, an unreachable server, a port collision, and applies its own fix where it has one, instead of producing a generic error with your phone number attached. What they never get is the topology: no map, no list of segments, no address ranges. That is deliberate, because a topology is a very good list of things to try next.

The same connection, with the context they never had

It shows up in QS-WAN, and the map tells you what it means: which segment the device sits behind, and every edge leading out of that segment. Discovery fills in the rest, the adjacent LANs on the gateway side and the hosts on them, so the segment a site engineer built on a Friday appears as an object rather than as a surprise. Where discovery has never run, the map says exactly that.

Then you click the edge, and it is true in both directions

Click the line between two segments and the communication turns off, applied symmetrically, so there is no half-open path left behind because one side changed and the other was forgotten. Zero trust is its own control here and does not depend on the tunnel mode, so a VLAN running in split tunnel can still be default-deny. If the control channel of a gateway is down, the console says the intent is recorded and converges when the gateway is reachable, instead of handing you a green tick it has not earned.

Before you start

You need the gateways you already run. The map is part of the console, so there is nothing to buy, nothing to rack and nothing to re-address.

In detail

What most network mapping tools get wrong

Read-only

Watching is not the same as changing

Most network mapping software is read-only by design. It watches, it draws, and then you go somewhere else to make the change. That gap is where drift comes from. It is the same split you see across network software in general, between the tools that show you the network and the tools that change it.

Here the map and the enforcement are the same system. Access decisions stop being a translation exercise between a diagram, a firewall and a memory, because the same edge you are looking at is the one being enforced. That is the plain version of network access control.

Discovery

The LANs nobody told it about

Adjacent LAN discovery scans what sits on the gateway side of the network, and host discovery fills in the hosts on those LANs. You get the segments you forgot, the ones that arrived with an acquisition, and the one a site engineer built on a Friday.

One detail is worth its own paragraph. When discovery has never been run on a gateway, the map says exactly that instead of showing you empty space. Not scanned yet and nothing there are different facts, and drawing them the same way is how people end up trusting a blank area of a diagram.

Where this earns its place

Four mornings this changes

An assessor asks which segments reach which

You open the map and turn the screen round. It is the configuration, so there is nothing to reconstruct and nobody to ask.

A site engineer built something on a Friday

Discovery finds the segment on the gateway side and it appears as an object with a range, not as a surprise during an incident three months later.

A project ended and the path is still open

You find the edge on the map and click it. Both directions close together, so nothing is left half open because one side was forgotten.

Two subnets should never have been talking

The edge either exists or it does not, and the absence is the rule. There is no exception list for anyone to maintain or to lose.

Works better with

What the map is drawn from, and what it is used for

Where the segments and the edges get built in the first place. The map is what they are drawn on, so the two are the same object seen twice.

The rules that hang on each segment, per gateway and per user, plus who is allowed to arrive and at what hours.

The honest version of multi-site today. The cluster view of the map is still partial, and this is where the subject actually lives.

What the map is mostly used to reason about: which people reach which segment, and from where they are working this week.

What this does not do

The limits, because they are what make the rest believable

It is not network monitoring software

The map shows what is allowed and what is connected. It is not a flow-by-flow record of what moved, and anything that reads like one on this page would be us overselling it.

It only sees what a gateway can reach

Discovery works from the gateway outward. A segment with nothing of ours near it does not appear by magic, and we would rather it stayed absent than showed up as a guess.

A change is recorded first and delivered second

The console is authoritative on what you asked for. Getting that to a gateway or a device is best effort, so a green response proves the intent is saved, not that a laptop in somebody bag has caught up. With the control channel down, changes save but do not push.

The cluster view is partial, and we would rather say it

There is a second view for organisations running more than one gateway, and it needs at least two gateways and two discovered segments before it shows anything useful. The matching tab in Gateway Configuration still says coming soon. Until those two agree, treat multi-site as a use case and not a finished feature.

Questions people ask

The ones that come up first

What is network mapping software?

It is software that draws your network as objects and links rather than as a picture somebody maintains. In QS-WAN the map holds gateways, VLANs, LANs and the links between sites, and it is drawn from the configuration of the console, so it shows what the network is currently set up to do.

Is this a monitoring tool?

No. The map shows what is allowed and what is connected, not a flow-by-flow record of what moved. If you want throughput and sessions, that is network traffic monitoring, and it is a different screen with different evidence behind it.

What happens when I click an edge?

The communication on that edge turns on or off, and it is applied symmetrically. Both directions, one action. You cannot leave a half-open path behind because you changed one side and forgot the other side existed.

Is zero trust the same as the tunnel mode?

No. It is its own control, and it does not depend on the tunnel mode, so a VLAN running in split tunnel can still be default-deny. On the map they are two different facts about the same link and are drawn as two different facts.

Will it find segments I do not know about?

On the gateway side, yes. Adjacent LAN discovery scans what sits there and host discovery fills in the hosts. A segment with nothing of ours near it will not appear, and where discovery has never run the map says not scanned yet rather than showing empty space.

Does it work across several sites?

Partly, and we would rather be plain about it. There is a cluster view for more than one gateway, it needs at least two gateways and two discovered segments to show anything useful, and the matching tab in Gateway Configuration still says coming soon. Multi-site is a use case today, not a finished feature.

Bring the diagram you have. We will show you the one that is true.

You describe the sites and the segments, we draw them on the map and click an edge while you watch. It is free, it lasts as long as you want, and there is nothing to sign.

Scroll to Top