Axon features

One clear view of every site, user and application.

Axon brings network experience, traffic visibility, site-local diagnostics, infrastructure monitoring, alerting and policy into one operations platform — with Simba to investigate the evidence when something breaks.

Multi-site consoleInline or passive per site or at an aggregation nodeUnlimited sites and devices

01 · Operations overview

One starting point for every investigation

The multi-site dashboard combines device, port, uptime and traffic health into a single status view, with a Network Pulse that shows whether a site is stable or currently changing. Recommended next actions turn telemetry into a queue instead of a collection of charts.

  • Site-selectable health, throughput and notification summary
  • Live traffic-ingestion status
  • Unified inventory: Axon switches, endpoints, SNMP and UniFi devices
  • Admin, operator and viewer roles with per-user site access

Fleet view — recreated, representative data. Stale sites are marked, never shown healthy.

02 · Experience and availability

A score you can interrogate, not a black box

The 0–100 Experience Score combines reliability, responsiveness, throughput and local device health — and exposes every metric behind each component.

  • Component scores with a full evidence list
  • Network Pulse: availability, incidents and recent recoveries
  • Scheduled ping, TCP, HTTP and DNS uptime checks from inside the site
  • Uptime history and response-time timelines

Diagnostic story card — trend and health are judged separately, so “stable but bad” is never hidden.

03 · Traffic visibility and intelligence

Turn encrypted flows into useful application context, without decrypting user traffic.

Axon classifies traffic at the edge using novel on-device AI and domain/SNI signals where available. Raw packets stay on site; the control plane receives bounded flow and health telemetry.

See

Start with the application. Drill down to the flow.

Usage by application, category, endpoint, LAN user, domain, country, ASN and provider — down to individual flows and whether each was delivered, blocked or rate-limited.

Trust

Coverage is shown, not assumed

Unattributed traffic is reported and data-availability views prevent missing telemetry from reading as zero traffic.

Investigate

The destination, not just the byte count

Site-local domain-to-IP history, ASN and provider attribution, and risk enrichment against threat intelligence packs — without shipping your traffic inventory to a third-party SaaS.

Axon switching traffic page: 2.4 gigabytes of total traffic across 9,000 active flows, 55 applications and 28 endpoints, with 410.6 megabytes rate-limited and zero blocked. A traffic disposition bar shows delivered 83.2 percent and rate-limited 16.8 percent, above a traffic-over-time chart and a top applications ranking led by Instagram, TLS and YouTube.

Live console — Delivered, rate-limited and blocked shares are measured.

How Axon classifies

Multiple signals. One custom heuristic. Lightweight enough to run on the edge.

Signal 01Layer 7 · bytes

Packet payload

Axon looks at the parts of the packet payload that remain informative under encryption, and combines them with other observable behaviour to triangulate the application.

Signal 02Flow · statistics

Flow fingerprints

Each flow is fingerprinted on characteristics that do not change when the payload is encrypted. These survive QUIC, TLS 1.3 and most circumvention techniques.

Signal 03 · Axon agentOn-device · real-time

Custom on-device heuristic

The signals feed a lightweight AI model that runs directly on the Axon agent. Classification is real-time, in-line, and does not send raw traffic anywhere.

→ Classifies as

instagramgoogleapis · uploadnetflixyoutubespotifywhatsappapple · pushdiscord · voice

First handful of packets · per flow · no raw traffic leaves the agent

04 · Diagnostics and baselines

Test from the site, not from the cloud.

Diagnostics run on the Axon edge device at the affected site, so they measure the path and service experience the customer actually sees. Every test is bounded to protect constrained hardware and metered links.

DNS health

Cold/warm timing across system and public resolvers, failure classification and a hijack/interception canary for captive portals.

HTTP / platform

Capped checks with DNS, connect, TLS and TTFB phases, certificate validity and captive-portal detection.

Path trace

Bounded UDP/ICMP TTL ramp with per-hop RTT and loss, distinguishing intermediate response loss from end-to-end target loss.

Capped speed test

Bounded throughput with latency, jitter, loss and load context. When a cap is hit, the result reads “at least”, never “full capacity”.

Axon diagnostics page with an alert rule for path-trace target loss above 1.2 times the 14-day baseline, and active measurement stories: a speed test story marked stable and healthy with 304.9 megabits per second download and 194.8 up, and a DNS check story marked improving and healthy with p50 of 21 milliseconds and p95 of 26 milliseconds, each with recent run health dots.

Live console — Trend and health are judged separately.

Baselines that respect busy hours

Measurements are separated into busy and quiet conditions with p50/p95 percentiles, so busy-hour degradation is never hidden inside one overall median. Trend and health verdicts are independent, and confidence is reported when history is thin.

From evidence to monitoring in one step

Recurring schedules build baselines automatically, with single-flight protection and intrusive-test safeguards. Any diagnostic story metric can become an alert rule with one action.

05 · Capacity and alerting

Know which uplink saturates first — and what is driving it

WAN capacity planning uses the subscribed service capacity. Saturation minutes, busy hours, p95 trends and projected weeks-to-saturation turn congestion into an evidence-based upgrade decision.

  • p50/p95/max utilisation and saturation minutes per day
  • Application contribution during saturated hours
  • Absolute and 14-day baseline-relative alert rules with debounce
  • In-app inbox, email, Slack, Discord, Teams and signed webhooks
Axon capacity planner listing a WAN uplink with subscribed link speed 300 megabits per second on a 1 gigabit physical link, p50 0.8 percent, p95 20 percent, max 22 percent, zero saturation minutes per day, busiest hours labelled, and a stable trend. The saturation-drivers panel honestly reports no saturation in this window.

Live console — Service capacity is the basis.

06 · Policy and control

Turn visibility into policy — and verify the effect.

Block or rate-limit applications, categories, endpoints, IP ranges and domains. Scope rules globally, by site, switch or device, and schedule them for the days and times they should apply. Axon records what traffic was actually delivered, blocked or limited, so configured intent can be checked against observed effect.

Application-aware

Block or rate-limit by application or category, without maintaining changing IP lists.

Address and domain

IP, CIDR, observed SNI domains and wildcard patterns, plus custom block lists.

Precise scope

Fleet, site, switch or single endpoint, with IP/CIDR qualifiers, time windows and weekday constraints.

Resilient enforcement

Policy is cached at the edge, so enforcement keeps running when the controller link is intermittent.

Axon traffic rules page showing two active rules: a block rule for the Instagram application scoped to a switch with a time-window target, and a 50 megabit per second rate limit for YouTube applying to all traffic, with controls to sync policy to devices.

Live console — One block rule, one rate limit.

07 · Fleet lifecycle

Create a token and install in minutes.

Token-based enrollment assigns each device to the correct site, joins the private management network, validates interfaces and reports progress back to the controller.

  • Bounded enrollment tokens
  • Staged update slots
  • Per-site release channels and staged rollout policy
  • Clean remote decommissioning

See the architecture

Install timeline — recreated, representative data. Failed steps roll back via the transactional installer.

08 · Simba

And when you need an investigator, ask Simba.

Simba reads the same evidence you see — health, traffic, baselines, policy, capacity and recent changes — through typed, site-scoped tools, and explains the likely cause with its caveats attached.