Sign in to manage your network
Enter the 6-digit code from your authenticator app.
This account needs a new password before continuing.
| Since | Rule | Hostname |
|---|
Last 7 days — added, removed, and raw up/down movement, shown here immediately, independent of each device's notification delay.
| When | Device | Event | Detail | Actions |
|---|
Known MikroTik devices and their live status.
| Status | IP | System Identity | Version | Model | Last Checked | Actions |
|---|
Ping-only devices — no RouterOS sync, config, or backups. Just reachability monitoring and notes.
| Status | IP | Label | Last Checked | Actions |
|---|
Accounts provisioned onto every managed device.
| Username | Group | Actions |
|---|
Manage who can access this console.
A temporary password is emailed directly to the new account — you'll never see or set it yourself. They'll be asked to set their own password on first login.
| Username | Role | 2FA | Actions |
|---|
Every notification actually attempted, successful and failed, most recent first.
| When | Channel | Event | Status | Details |
|---|
Scheduled tasks, run automatically by a system account.
Runs exactly like "Backup All Online Devices" — backs up every currently-online device and sends the usual completion notification. Executed by a system account, not a real technician login.
Device monitoring, mail, notifications, IP ranges, and model images.
How often the background poller does a quick TCP check on every known device. Lower values catch outages faster but generate more traffic — 10s is a good default for a small fleet.
Outgoing SMTP settings used for password emails, OTP approvals, and email notifications. Leave password blank to keep the current one.
Off — no messages sent anywhere. Testing — sent to your test bot/chat only. Production — sent to the real techs group.
Who receives email notifications (comma-separated) — separate from the technician-creation OTP approval list. Requires Mail Setup to be configured under Settings → Mail Setup.
Choose which events notify on which channel. More channels can be added here later.
| Event |
|---|
| Range | Label | Actions |
|---|
Set a default map image per hardware model — used automatically for any device on the Network Map that doesn't have its own specific image set.
| Model | Image | Actions |
|---|
SSH port used by the web terminal (Manage → Terminal). Uses the same MikroTik API username and password already configured for the app — no separate credentials to set up.
Used for live port traffic (Mb/s) shown on Network Map links. Requires SNMP enabled on your devices and matching this community string.
Used by "Add Fresh Device" on the Devices tab — NTP servers to configure, and which subnets SSH/FTP/API/Winbox get restricted to.
Creates a new site — technicians can edit an existing location's details (except its name) from Manage → Locations, but only admins can add new ones.
External DNS names or internet IPs to ping-monitor and graph on the Service Monitoring page — your upstream gateway, a peering point, 1.1.1.1, 8.8.8.8, etc. Separate from your managed device fleet. Checked every 5 seconds; if the last 12 checks (~1 minute) are all above the latency threshold or timed out, a notification fires (once, not repeatedly, until it clears) — configurable per event under Notifications.
| Label | Host | Latency Threshold | Alerts | Status | Actions |
|---|
Shown on the login screen, top-left of the sidebar, and in the header of every notification email. Paste a link to an image — a square or wide logo with a transparent background works best. Leave blank to use the default "WaddleNet" text wordmark.
Define which public IP ranges belong to you here. Every time a device's Manage modal is opened, any IP address it reports gets checked against these ranges — anything that falls inside one is automatically documented under Documentation → IP Addresses, with no need to trigger it manually. Private ranges aren't tracked by this yet.
| CIDR | Label | Added By | Actions |
|---|
Flag which devices are our border/peering routers — only these get checked for BGP session info (every ~15 minutes), not the whole fleet.
| Router | Note | Actions |
|---|
These wipe ALL auto-discovered documentation of the given type, across every device — not a single entry. Nothing about your actual network configuration changes; anything still genuinely in use simply gets re-documented automatically the next time each device's Manage modal is opened. Manually-configured items (planned VLAN ranges, configured public IP ranges) are NOT affected by either of these.
Sites, with circuit numbers, backhaul provider, and site contact details. Technicians can edit details here; adding a new location is under Maintenance → Settings (admins only).
| Name | Circuit | Backhaul | Contact | Devices | Actions |
|---|
People, companies, and site contacts worth having details for — site contacts are pulled from each location's own details.
Site contacts (marked with a pill) are managed from Locations — click Manage on one to jump there.
| Name | Company / Location | Phone | Notes | Devices | Actions |
|---|
Central asset/paperwork record per device — every known device gets one automatically. Click one to view or fill it in.
For devices completely unmonitored elsewhere in the system — e.g. client-owned equipment we set up but don't manage or ping.
| Name | IP | Type | Status |
|---|
Every document uploaded across every device's documentation, in one searchable place — no need to hunt through devices one at a time.
| File | Device | Size | Uploaded | By | Actions |
|---|
Domains whose SSL certificate we watch — checked automatically every few hours via a live TLS handshake, so expiry and issuer stay accurate without manual re-entry after each renewal.
| Domain | Label | Expires | Days Left | Issuer | Last Checked | Actions |
|---|
BGP sessions on our border routers, checked automatically every ~15 minutes. Configure which routers count as border routers under Settings → Peering.
| Router | Session | Remote ASN | Remote Address | State | Prefixes | Notes | Last Checked | Actions |
|---|
Public IP addresses discovered on devices, automatically documented whenever they fall inside a range configured under Settings → Public IP Documentation.
For addresses held back for a rainy day or a specific reason, not currently in use anywhere.
| IP Address | Source | Interface / User | Description | Device | Actions |
|---|
Every known VLAN, deduplicated across devices — the same VLAN naturally shows up on many devices, so this picks whichever friendly name was used most often for it.
For VLANs reserved for a site-specific reason, not currently deployed on any device.
| VLAN ID | Friendly Name | Planned Name | Devices | Actions |
|---|
Reservations are combined live with what's actually deployed on devices, so a plan automatically reflects deployment progress with no manual syncing. A range can be reserved even if part or all of it is already deployed elsewhere — this just labels its intended purpose.
Leave End VLAN ID blank to reserve just a single ID.
| Range | Friendly Name | Deployment | Reserved By | Actions |
|---|
Everything not currently deployed or reserved, grouped into consecutive blocks.
| Range | Size |
|---|
Warranty/support expiry reminders are emailed automatically 30 days before (and if already passed), to the recipients configured in Mail Setup.
Can be pulled live from the device — see "Fetch from Device" below.
Three separate roles — who to call about the device itself is often a different person from who to call for site access, and the site contact gets a backup in case the first doesn't answer.
Primary IP — this is the device's known management IP (VLAN 1500), same as tracked under Devices.
Operating System — live RouterOS version, same as shown throughout the app.
Automatically discovered (both VLAN interfaces and bridge VLAN filtering) every time this device's Manage modal is opened — nothing to trigger manually. Anything added here manually is never touched or removed by that.
| VLAN ID | Friendly Name | Actions |
|---|
Same backups shown on this device's Manage modal — kept here too so everything about this device lives in one place.
| Date | Filename | Size | By | Actions |
|---|
Sign-off letters, manuals, install photos — any file type, 20MB max.
| File | Size | Uploaded | By | Actions |
|---|
Ping-based latency and packet loss for external DNS names and internet IPs — upstream gateways, peering points, public resolvers. Targets are configured under Maintenance → Settings → Service Monitoring (admins only).
Every login, current and past — who's logged in, from where, and when. Includes Wall Display Mode sessions, which can be terminated here regardless of which account is logged in.
| User | Role | Type | IP | Logged In | Last Seen | Logged Out | Status | Actions |
|---|
Mute down/recovery notifications for a location during planned work — up/down events are still logged, just not notified.
| Location(s) | Note | Start | End | Status | Created By | Actions |
|---|
Every action taken through this console, most recent first.
| When | User | Action |
|---|
Health of the server this app runs on, and the background task pipeline behind device/service monitoring — useful for telling "the server is struggling to keep up" apart from "it's actually a network issue at the destination."
This is what actually runs device pings, service-monitor checks, and everything scheduled in the background. If the worker is offline or the queue is consistently backed up, monitoring checks can run late or get skipped entirely — which can look identical to a real network problem in the graphs, even though nothing at the destination changed.
IPs currently blocked from SSH after repeated failed login attempts. Admin-only — this is visibility into fail2ban, not a way to ban/unban from here.
Password and two-factor authentication for your own account.
Shown in the account menu, top right. Defaults to the first letter of your username if you don't set one.
Requires your current password, and a 2FA code too if you have it enabled.
Protect your account with an authenticator app (Google Authenticator, Authy, 1Password, etc.).
Scan with your authenticator app, then enter the 6-digit code it shows to confirm.
Your account is protected. Disabling requires your current authenticator code.
Manually placed devices, with your own port-to-device links. Drag to arrange, scroll to zoom, Shift+drag to select multiple.
Centralized log viewer across all devices.
LibreNMS, Akvorado, and AS-Stats, embedded.
Live view of what's actually configured on the device right now — not stored here, but anything new gets quietly added to its Documentation page too.
| Created | Filename | Size | By | Actions |
|---|
Sampled roughly every 60 seconds. Red markers along the bottom indicate packet loss. The 7-day and 30-day views show hourly averages with the min/max range shaded behind.
Which management integration this device uses. Support for other vendors is planned but not yet built — shown here for visibility only, not yet changeable.
Set a model here to reuse that model's default map image (Settings → Model Images).
Choose which update channel to check against.
How long this device must be unreachable before an "offline" alert fires — useful for sites with generator or UPS backup where a brief mains flicker shouldn't page anyone.
One-time setup for a brand-new or factory-reset MikroTik: creates this app's own API user (verified working before anything else changes), locks down IP services and SNMP to your management subnets (removing the default unrestricted "public" SNMP community), sets NTP, system identity, and RoMON, then removes the original admin account. Requires a management IP address already configured on the device, reachable from this server.
| IP | Identity | Image URL |
|---|
| IP | Identity |
|---|
A static, unmonitored entity — a client, an upstream/IX provider — just a label and a link to a real port. No live status.
Ping-only monitoring — no RouterOS login, no sync. Good for switches, APs, or any other IP device you just want to keep an eye on.
Run a ping, traceroute, or curl to see output here.