◂ writeups // michaelz.dev

The Device on Port 8 Was My Router

My network map got clickable today. Tap the router, the access point, the switch, any of its twelve ports or any device, and the detail unfolds underneath: who's connected, how strong their signal is, how much traffic each port carries, how often each link dropped in the last day. Before I'd even shipped it, it told me to go and find a mystery device on port 8. Port 8 is my router.

What the map knows

The map already existed. A collector visits the router, the access point and the switch every five minutes and writes down everything it sees: which devices are on Wi-Fi and on which band, which are wired and on which switch port, which link speed each port negotiated. The switch also runs a metrics exporter, so I have per-port traffic and a counter of how many times each link has gone down and come back up.

The click-through just joins those two sources per device, adds the known pitfalls from my notes for that box, and runs a few deterministic checks: a port that keeps flapping, a client with a weak signal, a port carrying traffic nobody can name.

The first real finding was a good one. The bedroom TV's port had gone down and up four times in 24 hours, on a 100 Mb link. That's a TV going in and out of standby, which is fine, but it's exactly the kind of thing I'd never have seen without a counter, and it would look identical to a bad cable.

False alarm one: the boxes that weren't there

The router and the switch both showed up as "? not in the inventory". For a second that looks alarming: the two most important boxes on the network, unknown.

The reason is simple once you see it. The collector lists the devices it sees through those boxes. It doesn't list the boxes it reads from. The router can't appear in the router's own list of clients. The observer isn't in its own observations.

The wrong fix would have been to mark them green by default. Absent is not the same as healthy, and that default is how dashboards end up lying. So "online" for those boxes now has to come from evidence, and the panel says which: the router and access point are up because they answered the collector in a fresh run; the switch is up because its exporter answers. If neither is true, the state is unknown, shown in grey, never green.

The thing doing the looking is never in the picture it takes.

False alarm two: the mystery device on port 8

The switch view then said: "Port 8 carries traffic from 2 MAC addresses the collector cannot name. Find out what is plugged in there." That's a reasonable check. An unnamed device on a wired port is exactly what you'd want flagged in a home network.

Except port 8 is the trunk to the router, carrying the IoT and guest VLANs alongside the main LAN. It's written down in my own notes on the switch. The router is invisible to the collector for the reason above, so its port looked like a stranger's.

The first draft of the check was noisier still. Two other ports were flagged as "5 addresses, only 1 named" and "7 addresses, only 3 named". Those were a Proxmox host carrying its containers and the access point carrying its Wi-Fi clients. Extra addresses behind a named box are normal; that's what a host or an access point is.

So the check changed in two ways. It now only flags a port where nothing can be named, which is the case that actually matters. And trunks are a fixed fact: port 8 shows as "router (trunk)", with a comment pointing at the note it came from, so the day the cabling changes, the next person (me) knows where to look.

Saying what you don't know

The switch exports metrics; the router and the access point don't. So their radio channels, transmit power, uptime and roaming state aren't collected anywhere. Rather than leave those fields blank, which reads as "nothing to report", each panel ends with a plain line: not collected for this box: radio channels, uptime, roaming state. An empty field and a missing measurement look identical unless you say which one it is.

What I'd take from this

  • An observer never shows up in its own observations. If your inventory comes from the routers, the routers need another source of truth for "up".
  • Absent is unknown, not healthy. When something is missing from the data, show grey and say why, never a reassuring default.
  • A check that sends you hunting has to know your topology. Write the trunks down once, as data, and point at where they came from.
  • Flag the case that matters, not every anomaly. "Nothing here can be named" is a finding; "more addresses than names" behind a host is just how hosts work.
  • Say what you don't measure. A blank field looks like "fine".

Comments

◂ all writeups michaelz.dev ▸