See it live · the reachability walk-through

Six read-only questions,
asked of your own network

This is the exact demo — every step is a single read-only path-lookup on your live snapshot. No agent, no scan, no change. Watch reachability re-rank the risk in front of you.

◆ addresses & device names scrubbed for this page · the live demo runs on your real snapshot · read-only, describe-only
"Forget CVEs for a second. Who can reach the management plane of your firewalls? Whoever reaches a firewall's admin plane can rewrite your segmentation. Let's ask your network."
1
Data centre → firewall management
the good boundary
Blocked
"Good news first, and it matters. From your data centre — blocked. Your Juniper firewall drops it. Someone built that boundary on purpose, and it holds. So we know this control exists in your network."
passing: nonezone-firewall denynamed enforcing rule
2
Headquarters / branch → same firewall management
the blast radius
Reaches
"Now from your headquarters. From a branch. From your DR site. Sixteen of your twenty sites can open an admin session straight to this firewall's management plane. Only the data centre is firewalled off. So the security of your entire segmentation fabric is only as strong as the weakest laptop in any branch — the precondition is already open."
passing: allno control on pathNIST 800-53 SC-7(15)
3
The "critical" firewall → data centre
the CISA-KEV box everyone patches
Blocked
"This is the box your feed screams about — the CISA-KEV 'critical.' Into the data centre — blocked at a named ACL. The scary one is contained."
passing: noneACL denynamed enforcing rule
4
The forgotten end-of-support device → data centre
flagged by no CVE feed
Wide open
"A device most people forgot is still on the network — old, end-of-support, no feed flags it. Same question, into the same data centre. There it is — crown-jewel server, reached. A clean six-hop path, not one ACL, not one zone-firewall. Your platform already flags this device red for end-of-support — it just never connected 'end-of-support' to 'wide-open path to the crown jewels.'"
passing: all~6 hopszero ACL / zone-firewall
the re-ranking · this is the product

The device everyone was patching is contained. The device nobody was watching owns your data centre. Same question, two answers. CVSS would never surface that — your network just did.

Why this is trustworthy

Read-only, always

Every step is a path-lookup — a read over your existing snapshot. Nothing is scanned, launched, or changed. The same segregation-of-duties boundary you're built on.

It's your own computation

Each verdict is IP Fabric's own forwarding calculation off your route + ACL tables — a block dies at a named control; an open path has none. The asymmetry is the signal.

A path, not a claim

We show a network-layer path to the target — not that a service answered, and never "exploitable." We surface the precondition and the blast radius; the exploit question is exactly what this forces you to ask.

The method, not the numbers

On a lab the numbers are illustrative; on your production snapshot it finds the device whose reachability contradicts its risk ranking — wherever that is.