Topology
NetXMS discovers and maintains network topology information, giving you visibility into how devices are interconnected. Topology views help you understand the network layout, trace connectivity issues, and visualize the path between devices.
Requirements
For NetXMS to build accurate network topology:
-
All network equipment should be registered in NetXMS
-
Equipment should respond to SNMP
-
Switches should have at least STP enabled
-
LLDP or CDP provides additional and more accurate information
A manual topology poll can be started on any network device to check what topology information is available.
Topology Event Correlation
Based on network topology, NetXMS performs event correlation to reduce alert noise and speed up problem resolution. There are three connectivity states:
- Down (
SYS_NODE_DOWN) -
The server cannot contact the node and either has no topology information for correlation, or has determined that the problem is with the node itself.
- Unreachable (
SYS_NODE_UNREACHABLE) -
The server knows the node cannot be contacted due to an intermediate router or interface failure. This distinction is critical — when an upstream switch fails, all downstream devices are reported as unreachable rather than down, so you see one root cause alarm instead of dozens.
- Up (
SYS_NODE_UP) -
The node is reachable. Generated when a node that was previously down or unreachable becomes contactable again.
This correlation means that if a core switch fails and 50 nodes behind it become unreachable, you get one SYS_NODE_DOWN alarm for the switch and 50 SYS_NODE_UNREACHABLE events (which can be suppressed in the Event Processing Policy) instead of 51 SYS_NODE_DOWN alarms.
Topology-based correlation is controlled by the Events.Correlation.TopologyBased server configuration variable and is enabled by default.
How Topology Is Built
NetXMS uses multiple information sources to build and maintain its network model:
- FDB (Forwarding Database)
-
From the FDB table, NetXMS identifies switch ports where only one MAC address is present — this means something is directly connected. If that device is registered in NetXMS and its MAC address is known (via agent, SNMP, or ARP table from another device), a direct peer relationship is established.
- LLDP
-
When a connected switch sends LLDP packets, the receiving switch stores the information in its LLDP neighbor table. NetXMS reads this table and identifies the device with a specific LLDP ID connected to each port. Both devices must be polled via SNMP so that LLDP IDs can be matched.
- CDP
-
Similar to LLDP, but using Cisco Discovery Protocol. Provides neighbor information on Cisco and some compatible devices.
- STP
-
The STP table on a switch has limited information — only about peers on the path to the root bridge. NetXMS reads this data to establish additional peer relationships.
- NDP / EDP
-
On supported devices, NetXMS also reads NDP (Nortel Discovery Protocol) and EDP (Extreme Discovery Protocol) neighbor tables.
- Other sources
-
Some network device drivers provide topology information directly, and administrators can define links manually.
| The Interfaces tab for a node includes a "Peer Discovery Protocol" column that shows how each peer relationship was determined. |
Topology Types
NetXMS discovers two types of topology:
Layer 2 (Data Link) Topology
Layer 2 topology shows physical switching connections between network devices. It reveals which switch port a device is connected to, how switches interconnect, and the overall switching fabric of your network.
L2 topology is discovered using protocols like LLDP, CDP, STP, and by analyzing MAC address tables (FDB). Discovery happens automatically during topology polls — no manual configuration is needed from operators.
Layer 3 (Network) Topology
Layer 3 topology shows logical routing relationships between subnets and routers. It illustrates how IP subnets are connected through routers and Layer 3 switches.
L3 topology is built from IP routing tables and interface address information collected from network devices.
Viewing Topology
Node Connection Point
For an end node, the switch port it is connected to is shown in the Topology section of the node’s Overview page. The information appears only after you run Update connection point information in that section — until then it shows "Connection point information not retrieved yet".
To explore the connections of a network device, build an ad-hoc topology map: right-click the node and choose one of the maps under Topology maps (Layer 2, IP, or Internal Communication topology).
Network Maps
Network maps provide a broader topology visualization. There are several types of maps available:
Automatically Generated Maps
NetXMS can generate ad-hoc topology maps from any node: right-click the node and choose an entry from the Topology maps submenu. The submenu is available only for nodes with a valid primary IP address (and for the management server node); the map is built with the selected node as its root.
- Layer 2 topology
-
Shows switching topology around the selected node. Devices are connected by lines representing physical links.
- IP topology
-
Shows Layer 3 routing topology. Displays subnets as connection points between routers.
- Internal communication topology
-
Shows how NetXMS server communication with this node flows (directly or through proxy agents).
Custom Maps
Administrators can create custom network maps with manually placed objects and connections. These maps appear under the Network Maps root in the Maps perspective.
Custom maps can include:
-
Specific nodes and their connections
-
Background images (floor plans, geographical maps, rack diagrams)
-
Decorative elements (labels, shapes, images)
-
Status-driven coloring
Reading Topology Maps
Color Coding
Objects on topology maps follow the standard NetXMS status color scheme:
-
Green — normal operation
-
Cyan — warning
-
Yellow — minor problem
-
Orange — major problem
-
Red — critical problem (device may be down)
-
Dark blue — unknown status
-
Light gray — unmanaged
By default, links between devices are drawn in a fixed color determined by the link type or the map default — link color does not reflect status. Status-based or utilization-based link coloring can be configured for individual links or for the whole map.
Ports View
The Ports view shows a graphical layout of a device’s ports grouped by slot. It is available only for nodes with bridge capability.
Ports can be colored by one of three display modes: State, Status, or VLANs. A VLAN table next to the layout lists each VLAN’s ID, name, ports, and interfaces.
This view is especially useful for:
-
Seeing port states across the whole switch at a glance
-
Checking which ports belong to a specific VLAN
Finding Connection Paths
NetXMS can trace the network path between two devices using the Trace path submenu of the node context menu. The submenu is available only for nodes with a valid primary IP address:
-
/ — path from the NetXMS server to this node
-
/ — path from a node chosen in the object selection dialog to this node
-
/ — path from this node to a node chosen in the object selection dialog
Route items trace the IP routing (Layer 3) path; L2 path items trace the switching (Layer 2) path.
To identify the physical location of a network connection — for example, which switch and port a server is plugged into — check the Topology section on the node’s Overview page (see above) or use the MAC address search described below.
Connection point search results (also used by the MAC and IP address searches) include the following columns:
| Column | Description |
|---|---|
Seq. |
Sequence number of the result row. |
Node |
Name of the end node object. |
Interface |
Name of the node’s interface object. |
MAC |
Interface’s MAC address. |
NIC vendor |
Vendor of the network adapter, determined from the MAC address. |
IP |
Interface’s IP address. |
Switch |
Name of the switch node object. |
Switch IP |
IP address of the switch. |
Port |
Name of the interface object representing the switch port. |
Index |
Interface index of the switch port. |
Type |
Connection type — direct (no other devices detected on the same switch port), indirect (other devices detected on the same port; virtual machines and their hosts always show as indirect), wireless (connected through a wireless access point), or unknown. |
MAC Address Search
NetXMS can locate any known MAC address in the network, even if the device is not managed. This is a standalone search view — open MAC Address Search in the Tools perspective.
Enter a MAC address and NetXMS searches all known FDB tables to find which switch port the MAC address was last seen on. If the device with the given MAC address is managed by NetXMS, additional details (node name, interface) are displayed.
IP Address Search
Similarly, you can search for any known IP address using the IP Address Search view in the Tools perspective. NetXMS searches ARP tables and interface configurations across all managed devices to locate where the IP address is present.
Both MAC and IP address search results are displayed in the same connection point results view as the switch port search. Both views require the Search network system access right — without it, the view reports access denied.
Using Topology for Troubleshooting
Topology information is valuable for diagnosing network problems:
- Identifying affected devices
-
When a switch fails, the topology view shows which downstream devices are affected. NetXMS uses topology data for root cause analysis — it can determine that multiple device failures are caused by an upstream switch being down.
- Tracing connectivity
-
If a device is unreachable, use the topology view to check whether intermediate switches and routers are operational.
- Verifying physical connections
-
Compare the discovered topology with your expected cabling to identify misconnections or missing links.
- Checking redundancy
-
L2 topology maps show redundant links, helping you verify that failover paths are in place. The STP state of each port is shown in the STP state column of the Interfaces view.
Topology Data Sources
The accuracy and completeness of topology views depend on what protocols are available on your network devices:
| Source | What It Shows | Requirements |
|---|---|---|
LLDP |
Most accurate neighbor information with port identification |
LLDP must be enabled on network devices |
CDP |
Cisco-proprietary neighbor information |
CDP must be enabled (Cisco devices) |
NDP |
Nortel Discovery Protocol neighbor information |
NDP must be enabled (Nortel/Avaya devices) |
EDP |
Extreme Discovery Protocol neighbor information |
EDP must be enabled (Extreme Networks devices) |
STP |
Spanning tree topology and port roles |
STP/RSTP must be active on switches |
FDB (MAC tables) |
Switch port associations inferred from MAC addresses |
SNMP access to switches |
Routing tables |
Layer 3 routing topology |
SNMP or agent access to routers |
Device driver |
Vendor-specific topology information provided by network device drivers |
Supported device driver |
Manual |
Links defined manually by an administrator |
None |
If topology views appear incomplete, contact your administrator to verify that the relevant protocols are enabled on network devices and that NetXMS has the necessary SNMP access. Topology configuration is described in the Administrator Guide.