Ontech ICTM platform

Network monitoring software for availability, addressing and traffic

Know which devices are up, which addresses are in use, how devices are configured and what the traffic is doing.

What is network monitoring?

Network monitoring is the continuous checking of network devices, addresses and traffic so faults, conflicts and suspicious activity are found before they disrupt users. Ontech ICTM monitors device availability and latency with scheduled ICMP ping, manages IP addressing with subnet scans and conflict detection, backs up device configurations over SSH and analyses NetFlow, IPFIX and sFlow records.

A network can fail loudly, when a link or switch goes down, or quietly, when duplicate IP addresses cause intermittent faults, a configuration change is lost, or a compromised host starts sending data somewhere it should not. Good network monitoring covers all of these, not only whether a device answers.

ICTM approaches the network from four angles: availability (is each device reachable and how fast), addressing (which IPs are allocated, free or in conflict), configuration (a stored copy of each device's running configuration) and traffic (flow records exported by routers, switches and firewalls, analysed for signs of attack).

Documentation sits alongside the monitoring: topology, VLANs and wireless networks are recorded and drawn as a map, and bandwidth figures you supply feed a capacity forecast, so the network team works from one place.

What ICTM does for network monitoring

Device availability and latency

Ping monitored devices over ICMP on a schedule, record uptime and latency, and raise an alert after repeated failures. Manual and bulk ping tests help when troubleshooting.

IP address management

Manage subnets and IP allocations, detect address conflicts, and scan a subnet with an nmap ping sweep that records responding hosts with MAC address and hostname.

Configuration backups

Pull each device's running configuration over SSH and store it, so you have a known-good copy before and after changes.

Flow collection and network detection

Receive NetFlow v5/v9, IPFIX and sFlow exports and analyse them for port scans, command-and-control beaconing, lateral movement, DNS tunnelling, data exfiltration and brute-force attempts.

Topology, VLAN and wireless records

Document devices, links, VLANs and wireless networks and view them as a topology map maintained by your network team.

Capacity forecasting

Apply a linear trend to the bandwidth figures you provide to estimate when a link will cross warning or critical thresholds.

FortiGate firewall monitoring

Test the connection to a FortiGate, read its CPU and memory figures and synchronise its traffic logs into ICTM.

Firewall rule audits

Parse FortiGate, Palo Alto, Cisco ASA, pfSense and iptables configurations, run twelve rule checks, score the rule set and produce a PDF report with AI commentary for reviewers.

WireGuard remote access

Set up a WireGuard server on the ICTM host, add and remove peers, and generate client configurations with QR codes for remote staff.

ICTM modules: Network Dashboard · Network Monitoring · Ping Test · IPAM Dashboard · IP Subnets · IP Conflicts · Config Backups · Network Topology · VLAN Management · Wireless Networks · Capacity Planning · Firewall Management · Firewall Security Audit · WireGuard VPN · Network Detection & Response

What ICTM monitors on the network, and how

WhatHow ICTM does itWhat you get
Device availabilityScheduled ICMP pingUptime, latency and an alert after repeated failures
IP address spaceRecorded allocations plus nmap ping sweeps of subnetsLive hosts with MAC and hostname; IP conflicts
Device configurationSSH pull of the running configurationStored configuration backups
Traffic behaviourNetFlow v5/v9, IPFIX and sFlow collectionFlow records and detections such as scans, beaconing and exfiltration
Firewall rule setsParsing of FortiGate, Palo Alto, Cisco ASA, pfSense and iptables configurationsRule findings, a score and a PDF report
Link capacityLinear trend on bandwidth figures you supplyEstimated date a link reaches warning or critical levels

Use cases

Branch connectivity

See at a glance which branch routers and links are reachable and how latency is trending.

Troubleshooting intermittent faults

Find duplicate IP addresses and unknown hosts on a subnet before chasing hardware problems.

Safe configuration changes

Back up a device's configuration before a change window so it can be compared or restored afterwards.

Spotting unusual traffic

Use flow detections to find hosts that are scanning, beaconing or moving unusual volumes of data.

Firewall review for an audit

Produce a scored, documented review of firewall rule sets as evidence for security and compliance audits.

Benefits

Faster fault isolation

Availability, addressing and configuration data in one place shorten the path from symptom to cause.

Security from network data

Flow analysis turns traffic you already export into detections for common attack behaviour.

Recoverable configurations

Stored device configurations reduce the impact of failed changes and hardware replacement.

Documented network

Topology, VLAN and IP records give new staff and auditors an accurate picture of the network.

Frequently asked questions

Which protocols does ICTM use to monitor the network?

ICTM uses ICMP ping for availability and latency, nmap ping sweeps for subnet scans, SSH to back up device configurations, and NetFlow v5/v9, IPFIX and sFlow for traffic analysis. For FortiGate firewalls it also connects to the device to read CPU, memory and traffic logs.

What is the difference between network monitoring and network detection and response?

Network monitoring asks whether devices and links are working. Network detection and response (NDR) asks whether the traffic itself looks malicious — for example a host scanning the network or beaconing to an external server. ICTM does both: ping and IPAM for availability and addressing, flow analysis for detection.

Can ICTM draw a network topology map?

Yes. You record devices, links, VLANs and wireless networks and ICTM draws them as a topology map. The map reflects what your team records, so it doubles as network documentation for new staff, change planning and audits.

How does ICTM detect IP address conflicts?

ICTM keeps a record of subnets and allocated addresses and flags conflicts where the same address is allocated more than once. Subnet scans with an nmap ping sweep show which hosts actually respond, with MAC address and hostname, so you can compare what is live against what is recorded.

Which firewalls can ICTM audit?

ICTM parses rule sets from FortiGate, Palo Alto, Cisco ASA, pfSense and iptables, runs twelve rule checks such as overly permissive rules, scores the result and produces a PDF report. Live CPU, memory and traffic-log collection is available for FortiGate.

Does network monitoring raise data-protection questions?

It can, because flow records contain IP addresses that may relate to people. ICTM pseudonymises IP addresses in flow data, supports access and erasure requests by purging a person's flow records, and deletes flow data, alerts and baselines on default retention periods of 30, 180 and 365 days.

See network monitoring in Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.