NODE64 Sonar: your network measured from the outside

An agent on the server knows the inside view. Whether a service is really reachable from the internet, how long the path there takes and whether the nameserver answers the same way everywhere – only an outside look can tell. That is what Sonar does: measurements from other locations against your own systems.

Voluntary, tightly limited and logged without gaps: Sonar measures only what somebody ordered, and only against targets whose ownership has been proven.

Why the outside view is missing

Most monitoring tools sit on the system they watch. They see exactly what is visible from the inside – and reliably miss the questions that matter when something goes wrong.

What your system knows about itself

Which services run, which ports are bound, what the firewall rules say, which packages are installed. All correct – and all a statement about intent, not about reality. A port forwarding in the router, a forgotten rule at the provider or a second path into the network appear nowhere in the configuration.

What only the outside shows

Whether the service answers when somebody knocks from the internet. How long a packet takes to reach you and across which networks. Whether your certificate is valid on the way there. Whether your name resolves the same over IPv4 and IPv6. Those are measurements, not assumptions – which is why a finding of “port probably open” becomes a proven result in NODE64.

What Sonar measures

Eight measurement types, each with a clear question. They run once or on a schedule, from one probe or from several at the same time.

Ping

Does the system answer, how fast, and are packets lost? The baseline for reachability and latency.

Traceroute

Which path do packets take to reach you – and where does it stall?

MTR

Route and packet loss together, hop by hop. Shows which section of the path actually loses traffic.

DNS

Does your name resolve the same everywhere, over IPv4 and IPv6, and how long does the answer take?

HTTP(S)

Does the site answer from outside, with which status and how fast?

TLS certificate

Is the certificate valid, who does it belong to, and how long does it still run?

Port reachable

Is this exact port reachable from outside? One port, one connection attempt – against your own systems only.

NTP offset

How far has your clock drifted from the reference? A wrong time breaks certificates, protocols and logins.

Recurring measurements build a history: latency and loss as a curve, the route as a hop list, DNS answers in plain text. And where a measurement backs a finding, the finding links straight to the result.

How a measurement runs

1

Prove the target

Measurements only run against systems that are provably yours.

Proof works through a connected device or a DNS TXT record. On top of that there is a short, NODE64-curated list of public anchors – services explicitly built for measurement traffic. Internal and private address ranges are excluded on principle, and the target is checked again before every single measurement.

2

Order the measurement

Type, target, schedule and who should measure – in one form.

Once or on an interval. As the source you pick a NODE64 anchor, your own devices, random probes, or probes in a given country or network. Several probes at once show whether a problem is on your side or on the way there.

3

Read the result

Numbers instead of guesses – and a history for recurring measurements.

Every result names the executing probe, the time and the measurement profile. Results are kept for as long as your plan provides, and really deleted afterwards.

Who measures

Sonar has no data centres full of measurement nodes of its own. It measures from where the participants are – that is the whole point.

Probes: devices of participants

Any device running the NODE64 agent can become a probe and carry out measurements for others.

  • Off by default. You decide per device and can switch it off again at any time – in the dashboard or locally in the configuration.
  • The ceilings live inside the agent itself. They hold even if the NODE64 server asks for something else – your device cannot be turned into a weapon, not even by us.
  • You see every job your device took on. You do not see who ordered it – and the customer does not see your address.

Anchors: fixed NODE64 nodes

So that measuring works from day one, even without someone else’s probe in range.

  • An anchor is not a special kind of device but an ordinary one, with the same agent and the same hard limits.
  • An anchor belongs to NODE64 itself: its participation is infrastructure, not a voluntary contribution like a probe's.
  • Anchors can also be measured as a target – which shows how your connection sees a known counterpart.

What Sonar is not

A measurement network without controls would be a distributed attack tool. The boundary is therefore drawn tightly, permanently and regardless of plan:

  • Not a port scanner. There are no port ranges – only a check of exactly one port with exactly one connection attempt, and only against your own systems.
  • Not a remote vulnerability scan. No logins are attempted, no credentials guessed, no content evaluated.
  • No load testing. Small packets, fixed timeouts, limited hop count, low frequency – no flood, no large payloads.
  • No measurements against internal or private address ranges, and no sharing of measurement data with third parties.

Protection for target systems

Even legitimate single measurements by many users can add up unintentionally. Several layers work against that at the same time:

  • Multi-level ceilings per target, per probe, per account and globally. The per-target ceiling applies across all users – it is the most important one of all.
  • Automatic pattern detection: many targets in the same network, rapidly changing targets, targets that never answer, sudden jumps in frequency. Anything conspicuous is throttled, with a deadline rather than forever.
  • A log without gaps: who ordered, which probe executed, against which target, when and with what profile. Without this log no complaint can be investigated.
  • A global blocklist and an open reporting path for operators of target systems – subdomains included, and no justification required.

Seeing measurement traffic in your log? This page explains what it is and how to opt out.

Data protection

Measurement results contain target addresses, and an IP address is personal data. They are therefore treated like everything else: processing and storage exclusively in Germany, retention according to your plan, really deleted afterwards. The measurement originates from the connection of the executing probe – the customer does not learn who owns it, and the probe operator does not learn who ordered it.

Privacy · Measurement network in the help

The rest of NODE64 already runs

Install the agent, connect devices, see findings – none of that needs Sonar. And when the measurement network starts, your account is already there: proving targets and ordering the first measurement is a matter of minutes.