Topology

NetXMS discovers and maintains network topology information, giving you visibility into how devices are interconnected. Topology views help you understand the network layout, trace connectivity issues, and visualize the path between devices.

Requirements

For NetXMS to build accurate network topology:

  • All network equipment should be registered in NetXMS

  • Equipment should respond to SNMP

  • Switches should have at least STP enabled

  • LLDP or CDP provides additional and more accurate information

A manual topology poll can be started on any network device to check what topology information is available.

Topology Event Correlation

Based on network topology, NetXMS performs event correlation to reduce alert noise and speed up problem resolution. There are three connectivity states:

Down (SYS_NODE_DOWN)

The server cannot contact the node and either has no topology information for correlation, or has determined that the problem is with the node itself.

Unreachable (SYS_NODE_UNREACHABLE)

The server knows the node cannot be contacted due to an intermediate router or interface failure. This distinction is critical — when an upstream switch fails, all downstream devices are reported as unreachable rather than down, so you see one root cause alarm instead of dozens.

Up (SYS_NODE_UP)

The node is reachable. Generated when a node that was previously down or unreachable becomes contactable again.

This correlation means that if a core switch fails and 50 nodes behind it become unreachable, you get one SYS_NODE_DOWN alarm for the switch and 50 SYS_NODE_UNREACHABLE events (which can be suppressed in the Event Processing Policy) instead of 51 SYS_NODE_DOWN alarms.

Topology-based correlation is controlled by the Events.Correlation.TopologyBased server configuration variable and is enabled by default.

How Topology Is Built

NetXMS uses multiple information sources to build and maintain its network model:

FDB (Forwarding Database)

From the FDB table, NetXMS identifies switch ports where only one MAC address is present — this means something is directly connected. If that device is registered in NetXMS and its MAC address is known (via agent, SNMP, or ARP table from another device), a direct peer relationship is established.

LLDP

When a connected switch sends LLDP packets, the receiving switch stores the information in its LLDP neighbor table. NetXMS reads this table and identifies the device with a specific LLDP ID connected to each port. Both devices must be polled via SNMP so that LLDP IDs can be matched.

CDP

Similar to LLDP, but using Cisco Discovery Protocol. Provides neighbor information on Cisco and some compatible devices.

STP

The STP table on a switch has limited information — only about peers on the path to the root bridge. NetXMS reads this data to establish additional peer relationships.

NDP / EDP

On supported devices, NetXMS also reads NDP (Nortel Discovery Protocol) and EDP (Extreme Discovery Protocol) neighbor tables.

Other sources

Some network device drivers provide topology information directly, and administrators can define links manually.

The Interfaces tab for a node includes a "Peer Discovery Protocol" column that shows how each peer relationship was determined.

Topology Types

NetXMS discovers two types of topology:

Layer 2 topology shows physical switching connections between network devices. It reveals which switch port a device is connected to, how switches interconnect, and the overall switching fabric of your network.

L2 topology is discovered using protocols like LLDP, CDP, STP, and by analyzing MAC address tables (FDB). Discovery happens automatically during topology polls — no manual configuration is needed from operators.

Layer 3 (Network) Topology

Layer 3 topology shows logical routing relationships between subnets and routers. It illustrates how IP subnets are connected through routers and Layer 3 switches.

L3 topology is built from IP routing tables and interface address information collected from network devices.

Viewing Topology

Node Connection Point

For an end node, the switch port it is connected to is shown in the Topology section of the node’s Overview page. The information appears only after you run Update connection point information in that section — until then it shows "Connection point information not retrieved yet".

To explore the connections of a network device, build an ad-hoc topology map: right-click the node and choose one of the maps under Topology maps (Layer 2, IP, or Internal Communication topology).

Network Maps

Network maps provide a broader topology visualization. There are several types of maps available:

Automatically Generated Maps

NetXMS can generate ad-hoc topology maps from any node: right-click the node and choose an entry from the Topology maps submenu. The submenu is available only for nodes with a valid primary IP address (and for the management server node); the map is built with the selected node as its root.

Layer 2 topology

Shows switching topology around the selected node. Devices are connected by lines representing physical links.

IP topology

Shows Layer 3 routing topology. Displays subnets as connection points between routers.

Internal communication topology

Shows how NetXMS server communication with this node flows (directly or through proxy agents).

Custom Maps

Administrators can create custom network maps with manually placed objects and connections. These maps appear under the Network Maps root in the Maps perspective.

Custom maps can include:

  • Specific nodes and their connections

  • Background images (floor plans, geographical maps, rack diagrams)

  • Decorative elements (labels, shapes, images)

  • Status-driven coloring

Reading Topology Maps

Color Coding

Objects on topology maps follow the standard NetXMS status color scheme:

  • Green — normal operation

  • Cyan — warning

  • Yellow — minor problem

  • Orange — major problem

  • Red — critical problem (device may be down)

  • Dark blue — unknown status

  • Light gray — unmanaged

By default, links between devices are drawn in a fixed color determined by the link type or the map default — link color does not reflect status. Status-based or utilization-based link coloring can be configured for individual links or for the whole map.

Interface names on both ends of a link are shown as labels next to the connectors.

Ports View

The Ports view shows a graphical layout of a device’s ports grouped by slot. It is available only for nodes with bridge capability.

Ports can be colored by one of three display modes: State, Status, or VLANs. A VLAN table next to the layout lists each VLAN’s ID, name, ports, and interfaces.

This view is especially useful for:

  • Seeing port states across the whole switch at a glance

  • Checking which ports belong to a specific VLAN

Finding Connection Paths

NetXMS can trace the network path between two devices using the Trace path submenu of the node context menu. The submenu is available only for nodes with a valid primary IP address:

  • Trace path  Route from NetXMS server / Trace path  L2 path from NetXMS server — path from the NetXMS server to this node

  • Trace path  Route from…​ / Trace path  L2 path from…​ — path from a node chosen in the object selection dialog to this node

  • Trace path  Route to…​ / Trace path  L2 path to…​ — path from this node to a node chosen in the object selection dialog

Route items trace the IP routing (Layer 3) path; L2 path items trace the switching (Layer 2) path.

To identify the physical location of a network connection — for example, which switch and port a server is plugged into — check the Topology section on the node’s Overview page (see above) or use the MAC address search described below.

Connection point search results (also used by the MAC and IP address searches) include the following columns:

Column Description

Seq.

Sequence number of the result row.

Node

Name of the end node object.

Interface

Name of the node’s interface object.

MAC

Interface’s MAC address.

NIC vendor

Vendor of the network adapter, determined from the MAC address.

IP

Interface’s IP address.

Switch

Name of the switch node object.

Switch IP

IP address of the switch.

Port

Name of the interface object representing the switch port.

Index

Interface index of the switch port.

Type

Connection type — direct (no other devices detected on the same switch port), indirect (other devices detected on the same port; virtual machines and their hosts always show as indirect), wireless (connected through a wireless access point), or unknown.

NetXMS can locate any known MAC address in the network, even if the device is not managed. This is a standalone search view — open MAC Address Search in the Tools perspective.

Enter a MAC address and NetXMS searches all known FDB tables to find which switch port the MAC address was last seen on. If the device with the given MAC address is managed by NetXMS, additional details (node name, interface) are displayed.

Similarly, you can search for any known IP address using the IP Address Search view in the Tools perspective. NetXMS searches ARP tables and interface configurations across all managed devices to locate where the IP address is present.

Both MAC and IP address search results are displayed in the same connection point results view as the switch port search. Both views require the Search network system access right — without it, the view reports access denied.

Using Topology for Troubleshooting

Topology information is valuable for diagnosing network problems:

Identifying affected devices

When a switch fails, the topology view shows which downstream devices are affected. NetXMS uses topology data for root cause analysis — it can determine that multiple device failures are caused by an upstream switch being down.

Tracing connectivity

If a device is unreachable, use the topology view to check whether intermediate switches and routers are operational.

Verifying physical connections

Compare the discovered topology with your expected cabling to identify misconnections or missing links.

Checking redundancy

L2 topology maps show redundant links, helping you verify that failover paths are in place. The STP state of each port is shown in the STP state column of the Interfaces view.

Topology Data Sources

The accuracy and completeness of topology views depend on what protocols are available on your network devices:

Source What It Shows Requirements

LLDP

Most accurate neighbor information with port identification

LLDP must be enabled on network devices

CDP

Cisco-proprietary neighbor information

CDP must be enabled (Cisco devices)

NDP

Nortel Discovery Protocol neighbor information

NDP must be enabled (Nortel/Avaya devices)

EDP

Extreme Discovery Protocol neighbor information

EDP must be enabled (Extreme Networks devices)

STP

Spanning tree topology and port roles

STP/RSTP must be active on switches

FDB (MAC tables)

Switch port associations inferred from MAC addresses

SNMP access to switches

Routing tables

Layer 3 routing topology

SNMP or agent access to routers

Device driver

Vendor-specific topology information provided by network device drivers

Supported device driver

Manual

Links defined manually by an administrator

None

If topology views appear incomplete, contact your administrator to verify that the relevant protocols are enabled on network devices and that NetXMS has the necessary SNMP access. Topology configuration is described in the Administrator Guide.