Enter the 6-digit code from your authenticator app.
This account needs a new password before continuing.
Two-factor authentication is required on every account. Scan this with your authenticator app to continue.
Can't scan it? Enter this key manually:
| Since | Rule | Hostname |
|---|
Last 7 days — added, removed, and raw up/down movement, shown here immediately, independent of each device's notification delay.
| When | Device | Event | Detail | Actions |
|---|
| Status | IP | System Identity | Version | Model | Last Checked | Actions |
|---|
Ping-only devices — no RouterOS sync, config, or backups. Just reachability monitoring and notes.
| Status | IP | Label | Last Checked | Actions |
|---|
| Username | Group | Actions |
|---|
| Picture | Username | Role | 2FA | SSH Tunnel User | Failed Logins | Actions |
|---|
Every notification actually attempted, successful and failed, most recent first.
| When | Channel | Event | Status | Details |
|---|
Scheduled tasks, run automatically by a system account.
Runs exactly like "Backup All Online Devices" — backs up every currently-online device and sends the usual completion notification. Executed by a system account, not a real technician login.
Device monitoring, mail, notifications, IP ranges, and model images.
How often the background poller does a quick TCP check on every known device. Lower values catch outages faster but generate more traffic — 10s is a good default for a small fleet.
Outgoing SMTP settings used for password emails, OTP approvals, and email notifications. Leave password blank to keep the current one.
Off — no messages sent anywhere. Testing — sent to your test bot/chat only. Production — sent to the real techs group.
Who receives email notifications (comma-separated) — separate from the technician-creation OTP approval list. Requires Mail Setup to be configured under Settings → Mail Setup.
Choose which events notify on which channel. More channels can be added here later.
| Event |
|---|
| Range | Label | Actions |
|---|
Set a default map image per hardware model — used automatically for any device on the Network Map that doesn't have its own specific image set.
| Model | Image | Actions |
|---|
Each map is its own independently-drawn canvas — its own devices, positions, and links. With more than one map, named subtabs appear above the Network Map so you can switch between them; with just one, it behaves exactly as it always has.
SSH port used by the web terminal (Manage → Terminal). Uses the same MikroTik API username and password already configured for the app — no separate credentials to set up.
Used for live port traffic (Mb/s) shown on Network Map links. Requires SNMP enabled on your devices and matching this community string.
Daily ONT/port health polling via SmartOLT — warn when an online ONT's receive optical power is weaker than this threshold.
Working default (-27 dBm) is near the low end of typical GPON receiver sensitivity — adjust once you've cross-checked a known-good ONT's reading against the OLT's own CLI.
Mass ONT outage alert — how many MORE ONTs offline than the last check (every 15 min), on a single OLT, counts as worth alerting on.
Both this and a PON port going fully dark are configurable, separate alerts — see Settings → Notifications to toggle email/Telegram for each.
Minimum ONTs a PON port must normally carry for it going fully dark to page anyone — a lightly-loaded port (e.g. one customer) still shows as down on the Dashboard either way, it just won't send an email/Telegram for it.
Reboot grace period — after an OLT comes back reachable, how many minutes to hold back its PON port alerts (down, recovered, and mass outage) while its line cards are likely still booting. Also always skips these alerts outright while the OLT itself is unreachable.
Pulls AbuseIPDB's highest-confidence reported-abusive IPs 4x/day and keeps a chosen address list in sync on selected MikroTiks. WaddleNet only ever manages the IPs inside this one named list — it never creates or touches firewall rules, so wire the list into your own rules on the device yourself.
Leave this off while you're setting things up — use "Test Connection" here and "Sync Now" under Settings → Danger Zone to check everything works first, then switch it on.
Which MikroTiks get kept in sync with the address list above. Unchecking a device stops WaddleNet touching it going forward — entries already there are left to clear via their own 7-day timeout rather than being wiped immediately.
Used by "Add Fresh Device" on the Devices tab — NTP servers to configure, which subnets SSH/FTP/API/Winbox get restricted to, and (optionally) a syslog server to point remote logging at.
Leave the IP blank to skip remote logging setup entirely on fresh devices — nothing is configured unless this is filled in.
Creates a new site — technicians can edit an existing location's details (except its name) from Manage → Locations, but only admins can add new ones.
External DNS names or internet IPs to ping-monitor and graph on the Service Monitoring page — your upstream gateway, a peering point, 1.1.1.1, 8.8.8.8, etc. Separate from your managed device fleet. Checked every 5 seconds; if the last 12 checks (~1 minute) are all above the latency threshold or timed out, a notification fires (once, not repeatedly, until it clears) — configurable per event under Notifications.
| Label | Host | Latency Threshold | Alerts | Status | Actions |
|---|
Shown on the login screen, top-left of the sidebar, and in the header of every notification email. Paste a link to an image — a square or wide logo with a transparent background works best. Leave blank to use the default "WaddleNet" text wordmark.
Define which public IP ranges belong to you here. Every time a device's Manage modal is opened, any IP address it reports gets checked against these ranges — anything that falls inside one is automatically documented under Documentation → IP Addresses, with no need to trigger it manually. Private ranges aren't tracked by this yet.
| CIDR | Label | Added By | Actions |
|---|
Flag which devices are our border/peering routers — only these get checked for BGP session info (every ~15 minutes), not the whole fleet.
| Router | Note | Actions |
|---|
URLs for external tools embedded directly in the portal, under the External Tools nav item. LibreNMS, AS-Stats, and Akvorado are reached only through WaddleNet's own login. PagerDuty doesn't allow iframe embedding at all, so it's handled separately below via its own API instead.
Pulled via PagerDuty's own API and shown as a calendar under the External Tools nav item, since PagerDuty doesn't allow iframe embedding. Create an API key under PagerDuty → Integrations → API Access Keys.
One WireGuard peer per tunnel — a client's own core router, or one of our MikroTiks deployed on-site. A single tunnel can carry several sites at once (e.g. one aggregator MikroTik relaying multiple clients), as long as their real subnets don't collide with each other.
| Name | Port | Status | Sites | Server Public Key | Actions |
|---|
Each site gets its own auto-assigned shadow subnet, so it never matters if two sites' real ranges happen to collide (e.g. both left on the RouterOS default 192.168.88.0/24).
| Name | Tunnel | Real Subnet | Shadow Subnet | Telegram | Enabled | Actions |
|---|
NVRs, cameras, kiosks (PoE MikroTiks), and switches inside a site's LAN — always addressed by real IP; the shadow IP WaddleNet actually talks to is computed automatically. Use "Scan" on a site above to discover what's alive before adding devices one by one.
| Name | Type | Site | Real IP | Shadow IP | Status | Monitored | Actions |
|---|
These wipe ALL auto-discovered documentation of the given type, across every device — not a single entry. Nothing about your actual network configuration changes; anything still genuinely in use simply gets re-documented automatically the next time each device's Manage modal is opened. Manually-configured items (planned VLAN ranges, configured public IP ranges) are NOT affected by either of these.
Sites, with circuit numbers, backhaul provider, and site contact details. Technicians can edit details here; adding a new location is under Maintenance → Settings (admins only).
| Name | Circuit | Backhaul | Contact | Devices | Backhaul Circuits | DWDM Links | Actions |
|---|
| Provider | Link Type | Site A | Site B | Circuit ID | Capacity | Primary/Failover | Actions |
|---|
| SO Number | Location | Customer/Supplier | Ordered By | Service / Description | Device | Actions |
|---|
| Location A | Location B | Label | Ports | Vendor / Model | Channels | Actions |
|---|
Site contacts (marked with a pill) are managed from Locations — click Manage on one to jump there.
| Name | Company / Location | Phone | Notes | Devices | Actions |
|---|
| Name | IP | Type | Status |
|---|
| File | Device | Size | Uploaded | By | Actions |
|---|
| Domain | Label | Expires | Days Left | Alert (days before) | Issuer | Last Checked | Actions |
|---|
| Domain | Registration Expires | Source | Alert (days before) | Subdomains Found | Last Synced | Actions |
|---|
| Subdomain | Type | Value | Root Domain | First Seen | Last Seen | SSL Tracked | Actions |
|---|
| Router | Session | Remote ASN | Remote Address | State | Prefixes | Notes | Last Checked | Actions |
|---|
| IP Address | Source | Interface / User | Description | Device | Actions |
|---|
| VLAN ID | Friendly Name | Planned Name | Devices | Actions |
|---|
| Range | Friendly Name | Deployment | Reserved By | Actions |
|---|
Everything not currently deployed or reserved, grouped into consecutive blocks.
| Range | Size |
|---|
Warranty/support expiry reminders are emailed automatically 30 days before (and if already passed), to the recipients configured in Mail Setup.
Can be pulled live from the device — see "Fetch from Device" below.
Three separate roles — who to call about the device itself is often a different person from who to call for site access, and the site contact gets a backup in case the first doesn't answer.
Primary IP — this is the device's known management IP (VLAN 1500), same as tracked under Devices.
Operating System — live RouterOS version, same as shown throughout the app.
Automatically discovered (both VLAN interfaces and bridge VLAN filtering) every time this device's Manage modal is opened — nothing to trigger manually. Anything added here manually is never touched or removed by that.
| VLAN ID | Friendly Name | Actions |
|---|
Same backups shown on this device's Manage modal — kept here too so everything about this device lives in one place.
| Date | Filename | Size | By | Actions |
|---|
Sign-off letters, manuals, install photos — any file type, 20MB max.
| File | Size | Uploaded | By | Actions |
|---|
Every login, current and past — who's logged in, from where, and when. Includes Wall Display Mode sessions, which can be terminated here regardless of which account is logged in.
| User | Role | Type | IP | Logged In | Last Seen | Logged Out | Status | Actions |
|---|
| Location(s) | Note | Start | End | Status | Created By | Actions |
|---|
Configured under Settings → External Tools.
LibreNMS URL isn't configured yet — set it under Settings → External Tools.
Configured under Settings → External Tools.
AS-Stats URL isn't configured yet — set it under Settings → External Tools.
Configured under Settings → External Tools.
Akvorado URL isn't configured yet — set it under Settings → External Tools.
PagerDuty isn't configured yet — set an API key and pick at least one schedule under Settings → External Tools.
The splice/build team technician on call to help the standby tech with fibre breaks. Weekday and weekend get separate people, both drawn from the same rotation order below — no swap ledger; reorder the roster if someone needs to cover.
| Week Start Date | Week End Date | Monday - Thursday | Friday - Sunday |
|---|
Log it when a technician covers someone else's standby shift, so it's clear who owes who.
| Date(s) | Days | Covering | Covered | Note | Logged by |
|---|
Every action taken through this console, most recent first.
| When | User | Action |
|---|
Health of the server this app runs on, and the background task pipeline behind device/service monitoring — useful for telling "the server is struggling to keep up" apart from "it's actually a network issue at the destination."
This is what actually runs device pings, service-monitor checks, and everything scheduled in the background. If the worker is offline or the queue is consistently backed up, monitoring checks can run late or get skipped entirely — which can look identical to a real network problem in the graphs, even though nothing at the destination changed.
IPs currently blocked from SSH after repeated failed login attempts. Admin-only — this is visibility into fail2ban, not a way to ban/unban from here.
Password and two-factor authentication for your own account.
Shown in the account menu, top right. Defaults to the first letter of your username if you don't set one.
Requires your current password, and a 2FA code too if you have it enabled.
Protect your account with an authenticator app (Google Authenticator, Authy, 1Password, etc.).
Scan with your authenticator app, then enter the 6-digit code it shows to confirm.
Your account is protected. Disabling requires your current authenticator code.
Sign in with your device's fingerprint, face, or PIN instead of typing a password — this works alongside everything above, it doesn't replace it. Add one from any device you sign in from regularly.
| Device | Added | Last Used |
|---|
| Time | Device | Topics | Message |
|---|
AbuseIPDB's highest-confidence abusive IPs, synced to your chosen MikroTiks' address list. API key, threshold, and target devices are under Settings → AbuseIPDB; on-demand Sync Now is under Settings → Danger Zone.
Pick which devices get synced under Settings → AbuseIPDB.
| Device | Entries on device | Last synced | Status |
|---|
Most recently added to the list, newest first.
| IP address | Confidence | Added |
|---|
No longer on AbuseIPDB's qualifying list, so cleared from the address list too — most recent first.
| IP address | Removed |
|---|
No CCTV sites yet — set one up under Settings → CCTV Tunnels & Sites first.
No Google Maps API key configured yet. Add one under Settings → CCTV Tunnels & Sites to enable the Site Map.
| Name | Real IP | Status |
|---|
Sent only to this site's own Telegram group and/or email recipients — never the main fleet channel technicians watch.
| Time | Event | Message | Status |
|---|
Controls what this site's own Telegram group and email recipients get notified about — entirely separate from the main fleet's notification settings.
| Event | Telegram |
|---|
Grants a customer-role account read-only access to this site — their own view shows only the site(s) they've been granted, nothing else in WaddleNet, and no editing anywhere.
| Username | Granted |
|---|
Generates a signed-off handover PDF covering the selected cameras — select fewer than all cameras for a partial/phased handover, the document's wording adjusts automatically.
Automatically backs up every RouterOS device (kiosk/switch/site router) and exports every camera/NVR's configuration on a recurring schedule — for this site specifically, not the whole fleet.
Downloads the single most recent backup for every device at this site, bundled into one ZIP file — strictly this site's own devices only.
Live view of what's actually configured on the device right now — not stored here, but anything new gets quietly added to its Documentation page too.
| Port | Description | Status | ONTs | Online | Offline | Offline (Power) | Offline (Other) | High Atten. |
|---|
| Created | Filename | Size | By | Actions |
|---|
Most recent 500 lines — for full search and history, use the Syslog page.
| Time | Topics | Message |
|---|
| SO Number | Location | Customer/Supplier | Ordered By | Service / Description | Actions |
|---|
Output Voltage
Input Voltage
Battery Capacity
Battery Voltage
| ONT | PON # | Name | Status | Optical (dBm) | Last Down Cause |
|---|
Choose which update channel to check against.
How long this device must be unreachable before an "offline" alert fires — useful for sites with generator or UPS backup where a brief mains flicker shouldn't page anyone.
One-time setup for a brand-new or factory-reset MikroTik: creates this app's own API user (verified working before anything else changes), locks down IP services and SNMP to your management subnets (removing the default unrestricted "public" SNMP community), sets NTP, system identity, and RoMON, then removes the original admin account. Requires a management IP address already configured on the device, reachable from this server.
| IP | Identity | Image URL |
|---|
| IP | Identity |
|---|
A static, unmonitored entity — a client, an upstream/IX provider — just a label and a link to a real port. No live status.
Drag it into place afterward if it's not quite right.
A simplified direction cone, not the camera's true optical field of view - just enough to see at a glance which way it's aimed.
A community string just for this site's kiosks/switches/site router - separate from the main fleet's shared one - used to poll this Site Map's link traffic.
Ping-only monitoring — no RouterOS login, no sync. Good for switches, APs, UPS/inverters, or any other IP device you just want to keep an eye on.
Provisioned onto every managed device.
Mutes down/recovery notifications for the selected locations — up/down events are still logged, just not notified.
For devices completely unmonitored elsewhere in the system — e.g. client-owned equipment we set up but don't manage or ping.
Registration expiry comes from the Route 53 Domains API if AWS is the actual registrar, falling back to a best-effort WHOIS lookup otherwise — requires AWS credentials configured under Settings → Domain Tracker.
For addresses held back for a rainy day or a specific reason, not currently in use anywhere.
| Channel | Status | Customer / Reference | Notes |
|---|
For VLANs reserved for a site-specific reason, not currently deployed on any device.
Leave End VLAN ID blank to reserve just a single ID.
A temporary password is emailed directly to the new account — you'll never see or set it yourself. They'll be asked to set their own password on first login.
Any incoming log line whose topics or message contains one of these keywords (case-insensitive) gets flagged on the Syslog page and sends a Telegram notification — with a 30-minute cooldown per device/keyword, so a repeating issue doesn't flood you with the same alert.
| Keyword | Description | Enabled |
|---|
Tunnel created. Give whoever's configuring the remote side (the client's own router, or one of ours deployed on-site) these details:
Combine the port above with this server's known public IP/hostname for the remote side's Endpoint. Once you add a Site to this tunnel, its real subnet becomes the AllowedIPs the remote side should route to us.
Tunnel and real subnet can't be changed after creation — delete and re-add the site if either needs to change.
Used to log into this site's kiosks/switches/site router (via RouterOS API) to fetch their real identity and, later, control PoE ports. Leave blank if this site has no RouterOS-capable devices you want to manage this way yet.
Used to log into this site's cameras/NVRs (via ISAPI) for model/firmware auto-fill, NVR HDD health, and live snapshots. A specific device can override this individually if it has a different login.
Paste this whole block into the remote router's Terminal (Winbox or SSH) — no firewall changes needed there, it only ever dials out to us.
Site and real IP can't be changed after creation — delete and re-add the device if either needs to change.
Leave blank to use the site's shared Hikvision login — only set this if this specific device has a different one.
Pinging every address on this site's real subnet — can take up to 15-20 seconds for a full /24.
Scanning...
Paste rows straight from your pre-site-visit planning sheet — devices get registered even if not online yet, so you can watch them come online as installers wire the site up. Columns: name, ip, device_type, serial_number, parent_ip, notes. device_type is one of nvr / camera / kiosk / switch / site_router / other. parent_ip links a device to its parent by IP (e.g. a camera's kiosk) — safer than by name, since the same switch model legitimately repeats across kiosks.
Paste this into a terminal — Mac, Linux, or Windows PowerShell all work, it's the same command everywhere — and leave that window open. It won't print anything or return you to a prompt; that's expected, not stuck — it's just holding the tunnel open.
| Name | Status | PoE | Comment |
|---|
| Time | Topics | Message |
|---|
RouterOS backup, kept here per device.
| Filename | Size | Created |
|---|
Loading...
Worst case, based on every connected camera's configured maximum bitrate recording continuously — actual retention depends on real activity on each stream, since most cameras use variable bitrate that's usually well below this ceiling.
Reboots this device and waits for it to come back online — this can take a couple of minutes.
No actions available for this device type yet.
Last 30 days, most recent first.
| When | Typed | IP Address |
|---|
Run a ping, traceroute, or curl to see output here.