Canvas
Draw devices, cable them, and run them.
On this page
Every environment lives on a canvas, whether you drew it yourself, deployed it from the Content Hub, generated it with the AI Generator or imported it. Cisco IOL and Dynamips router images, KVM virtual machines and containers share one canvas and can be cabled together in the same environment. Every control, menu row and shortcut is listed in the Canvas reference.

The screen#
- Top bar, left: the back arrow (Back to Environments), the environment name with a pencil to rename it, and a caption such as Environment · 12 devices. While devices change state the caption reads Powering on…, Powering off… or, when only some run, 3 of 5 running.
- Top bar, centre: the time and the CPU and memory use of the appliance, as percentages.
- Top bar, right: four icon buttons, Checkpoints, Snapshot environment, Environment status and the lock, then Power on or Power off for the whole environment. Checkpoints and Snapshot environment are hidden on some editions (see Limits per edition).
- Toolbar, a floating bar at the bottom: select, add a device, connect, undo and redo, align and arrange, zoom, fit view, screenshot, layers, notes, search, diagram, and the More tools menu (…). It fades while you pan, zoom or drag.
- Minimap: a small map of the whole drawing. It shows while the pointer is over the canvas, or always if you pin it.
The canvas receives device state from the appliance as it changes. Refresh (press R) reloads the environment on demand.
Select and move#
- Click a device to select it. Shift+click adds to the selection. Hold Shift and drag on empty canvas to select everything the rectangle touches. Ctrl+A selects everything.
- Drag a device to move it. Positions snap to a 16 pixel grid, and a thin guide line appears when the device lines up with another one. The arrow keys nudge the selection by one pixel, or by 16 with Shift. Positions are saved as you go.
- Drag empty canvas to pan. Scroll to zoom.
- Click a stopped device to open a small menu with Power on and Machine Settings. Double-click a running device to open its console. Double-click a stopped one and ONEP tells you to start it first.
- With one device selected, a bar appears above it with start or stop, console, startup config, reset, delete and a More button for the full menu. With one link selected, the bar offers Capture on this link and Delete link. The bar hides while you drag or pan.
- Press Esc to close an open menu or dialog, or to clear the selection when nothing is open.
Add devices#
- Open Add DeviceChoose the + button on the toolbar, press A, or right-click empty canvas and choose Add device.
- Name itType a name. Names are unique within an environment.
- Pick a class and a roleThe classes are Network, Network Security, Cybersecurity, Servers, Endpoints, OT/ICS, Telco, SD-WAN and Cloud. Choose a class, then a role such as Router, Switch or Firewall. More shows the less common roles of a class.
- Pick an imageThe Image menu lists the images in your Centrum library that match the role. Choose Add.
- Place itONEP places the new device for you. Drag it where you want it.
A device's CPU, memory, disk and network cards come from its image and ONEP's sizing rules. Change CPU and memory, and for virtual machines more, in Device Settings while the device is powered off. When a device has no free interface left, the Connect Devices dialog offers + Add interface.
Switches: native or vendor#
For the Switch role, leave the image on No image to add the native switch, built into ONEP. It needs no image, adds no guest memory, needs no license and has no power state: its menu offers only Change icon… and Remove…. Choosing an image from your library adds a vendor switch instead. A vendor switch costs its own memory and gives you that switch's own behavior: real configuration storage, real show commands and real mirror sessions. Cisco images are bring-your-own-license.
Cable devices#
- Start a linkChoose Connect devices on the toolbar or press C. Or drag from the small circle on one device's edge to another device.
- Pick the endsIn Connect Devices, choose a device and an interface for each end. The list offers only free interfaces. A device cannot be connected to itself.
- Add addresses (optional)Type an IP address for either end, for example
10.0.0.1/24. It is stored with the interface and shown on the link label. - ConnectThe link appears with the real interface name at both ends.
- Several links between the same two devices are drawn side by side.
- Hover a link to see its interface names and the MAC and IP addresses at each end.
- Links are colored by type; the legend is under … > Appearance. While the environment runs, traffic is animated along each link that is up.
- Interface labels hide when you zoom far out, unless you select or hover a device. Show interface labels in the same menu turns them off completely.
Links between devices are separate segments; shared segments are supported (see below). That keeps links apart, and it is what lets you capture the traffic on exactly one link.
On a device, More > Configuration > Disconnect all links unplugs every cable of that device at once, and Reconnect plugs them back. ONEP remembers the links while they are disconnected. The same rule as for deleting a link applies: the device and the devices at the other ends must be powered off, except links to a cloud node.
Shared segments#
To put several devices on one Layer 2 segment, add a native switch and cable each device's interface to it. All devices cabled to the same native switch share one segment. Devices of different kinds (router images, virtual machines and containers) can share the same segment.
Firewalls with more than one leg#
A firewall is not limited to one interface. Give it one leg per segment and cable each leg to a different switch: one towards the protected segment, one towards the cloud node, and more for further segments. You configure the firewall's own rules from its console.
Delete a link#
Select the link and press Delete, use Delete link on the bar above the selected link, or right-click the link and choose Disconnect link. ONEP asks you to confirm.
A link between two devices can only be deleted while both devices are powered off, just as you would not pull a live cable and expect the guest to cope. Power off both ends, then delete the link. The one exception is a link to a cloud node, which you can remove while the environment runs.
The cloud node: the door out#
An environment is sealed by default: no path to the ONEP host, your network or other environments. The only way for devices to reach beyond it is a cloud node. Add one from the Cloud class in Add Device. The dialog asks How should this Cloud connect?:
- NAT: outbound internet access through shared address space (100.64.0.0/10, RFC 6598). Tailscale uses the same range, so avoid overlap. Nothing on your network can reach in.
- Bridge: the environment joins your real network, as if plugged into your switch. Use it only when the environment must reach, or be reached from, your LAN.
The node shows NAT or Bridge under its name. Change the mode later with right-click > Switch to NAT or Switch to Bridge. A cloud node's menu also offers Change icon… and Remove…. A cloud turns on automatically when a device is cabled to it.
The Add Device dialog starts on Bridge. After adding a cloud node, check its mode and set NAT or bridge explicitly rather than relying on the default. An environment you meant to keep behind NAT should never end up bridged onto your LAN.
Power on and off#
- Whole environment: Power on at the top right starts every device. While devices come up the button is disabled and shows progress, for example Starting... 2/5. When devices run it becomes Power off, which stops every device. ONEP reports the result, for example "Environment started — 5 of 5 devices running". The command palette (Ctrl+K) has the same Power on and Power off command.
- One device: Power on and Power off in the device menu, the start or stop button on the bar above a selected device, the power button on its row in the Environment status panel, or Power on in the quick menu of a stopped device.
- Several devices: select them, right-click one, and choose Start, Stop or Restart.
- Force power off ends a device at once, after a confirmation. Restart (More > Power) power cycles it.
- Reset... returns a device to its first boot. See Reset a device.
See Environments for starting and stopping from the environment list.
The device menu#
Right-click a device for its menu. What appears depends on the kind of device, the state it is in and your edition. The More row opens a submenu of grouped rows when the pointer rests on it; it is not reachable with the keyboard alone. Rows marked Depends on edition are hidden or locked on some editions; see Limits per edition.
| Row | What it does | Applies to |
|---|---|---|
| Power on · Power off | Start or stop the device. | All |
| Suspend · Resume | Freeze the device in memory and continue later. The row reads Resume while the device is suspended. | Virtual machines |
| Force power off | End the device at once, without a clean shutdown. ONEP asks you to confirm. | All |
| Open console | Serial, desktop or container shell in the browser. See Consoles. | Running devices |
| Clear message | Remove a start or crash message from the device. | Devices that carry one |
| Focus | Dim everything except this device and the devices linked to it. The top bar reads "Focus: name · Esc to exit". Press Esc or click empty canvas to leave. | All |
| More > Console | Copy SSH Command copies an ssh command for the management address of a running device. Copy Mgmt IP copies the address itself, or the console port when there is no address. | All |
| More > Power | Restart and Reset.... | All |
| More > Configuration | Machine Settings (see Editing a device), Disconnect all links, Reconnect, Expose Containers and Change icon.... | All; Expose Containers only on devices that can host containers (depends on edition) |
| More > Snapshots | Snapshots... saves and restores a device's disk. See Save points. For devices that are not virtual machines the row is disabled and points to Use Config versions. | Depends on edition |
| More > Operations | Startup Config, Clone..., Rename, Export Config and Import Config. | All |
| More > Diagnostics | Image Details, View Metrics, View Logs, Packet Capture and Runtime Details. | Packet Capture needs the capture permission of your role; Runtime Details is for administrators |
| Remove... | Delete the device after a confirmation. This cannot be undone. | All |
Several rows open a dialog:
- Clone... asks for a name (the default is the device name plus "-copy") and offers Also copy this device's current links. ONEP reports how many links were copied and how many were skipped.
- Change icon... offers router, switch, firewall, server, linux, windows, pc, container and cloud.
- Image Details shows the image name, vendor and version, its badges, and a link to the full details in Centrum.
- View Metrics shows live CPU and memory use of the device, refreshed every two seconds, and its status, vCPU, RAM, console port and management IP.
- View Logs shows the device's log lines. Runtime Details shows how the device runs on the appliance, in a form you can copy.
- Rename asks for a new name.
Editing a device#
Choose Machine Settings to open Device Settings: name, icon, device type, CPU, memory, the image, and under Advanced settings the hardware options of the device. The fields are listed in the Canvas reference. A device that is running locks its settings; Stop & edit in the dialog stops it so they can be edited. The image can only be changed while the device is stopped.
Device type here sets the type of this one device and which images the Image menu offers. The class and type of an image itself are set in Centrum, from the image's Edit menu; see Centrum.
Startup configuration#
Startup Config opens an editor for the configuration a device boots with. It is applied when the device boots and again after a reset. The buttons are Copy, Download .cfg, Import .cfg (loads a file into the editor; press Save to apply it), Cancel and Save. If a save would replace a saved configuration with an empty one, ONEP asks you to confirm. Where versions are kept, saving keeps the previous text as a version and the dialog lists them under Version history: save the current text as a version with a note, restore, download, protect from deletion or delete a version.
Export Config downloads the configuration as a .cfg file without opening the editor, and Import Config replaces it from a file. Select several devices to export all their configurations as one zip, or to import one file into all of them. Saving, exporting and version history depend on your edition; see Limits per edition.
A small colored dot at the top left of a device marks an event on it, for example a saved configuration that ONEP kept because the captured one came back empty, or an image that was substituted at import. Select the dot to read the reason, open the startup config where that helps, or Dismiss it.
Reset a device#
Reset... returns a device to its first boot. The dialog lists what is kept (the device, its interfaces, links and MAC addresses, its saved configuration and versions, its position) and what is removed (its disk state; for a container, the container is recreated from its image). For a container you can also tick Also reset persistent data, which is off by default. Type the device name to confirm. The device must be powered off first.
Several devices at once#
Select two or more devices and right-click one of them. The menu offers Start, Stop, Restart, Open consoles, Export configs, Import config to all, Align (horizontal, vertical or grid), Set icon, Lock positions (the row reverses once positions are locked) and Delete…. Delete refuses to run while any selected device is running, and while the environment is locked. Ctrl+C and Ctrl+V copy and paste a selection; pasted devices are new devices of the same type and image, named with "-copy", without links or configuration. Ctrl+D duplicates the selection.
Save points#
- Config versions: named copies of a device's startup configuration. See Startup configuration.
- Checkpoints (top right): a named set of saved configuration versions for every device that keeps a text startup configuration. Give it a name and an optional note, then Save. Restore needs every covered device to be stopped; when some run, a partial link restores only the stopped ones. Devices without a text configuration are skipped and named in a message. Deleting a checkpoint keeps the saved versions.
- Snapshots (device menu): a named copy of a virtual machine's disk. Take or revert one only while the device is stopped. Snapshot environment at the top right takes one for every virtual machine in the environment and skips the other kinds.
Checkpoints and snapshots depend on your edition; see Limits per edition.
Environment status#
The Environment status button at the top right opens a small panel at the top right of the canvas. It stays open or closed per environment in your browser.
- A line with the number of devices running, failed and stopped.
- A line by device type, such as Router, Switch, Virtual machine or Container, with how many are on, off or failed.
- Appliance CPU, memory and disk use. The numbers dim while ONEP waits for a new sample.
- One row per device, running devices first: a power button, a status dot, the name (select it to find the device on the canvas), a Console button and, for virtual machines, a Desktop button. Powering off a running device asks you to confirm on the row. The Console and Desktop buttons stay grey until the device is on.
Labels, zones and layout#
Annotations label parts of a topology, as in the zones above. Open … > Annotate… to add them. They are saved with the environment.
- Add text places a text label. Double-click it to edit and press Enter to finish.
- Shapes offers Rectangle, Circle, Line, Arrow and Dotted line. A rectangle with a label is a zone. Double-click a rectangle or circle to type a label in it. Drag the handles of a selected rectangle or circle to resize it (sizes snap to the grid), or the round handles at the ends of a line or arrow to move the ends.
- With a shape or text selected, the Annotate menu shows Border style (solid or dotted), a color picker with presets and, for text, Font and Size. Border style changes the selected shape. Color, font and size set what the next shape or text you add starts with.
- Right-click a shape or text to recolor it (None, Neutral, Accent, Green, Amber, Red, Blue, Gray, Outline), set its text size (S, M, L, XL), Bring to front, Send to back, step it Forward or Backward under More, or Delete it.
- An imported environment can carry pictures from its source file. They appear as resizable shapes.
- Notes on the toolbar opens free text that is saved with the environment. Layers lists every device and shape and lets you hide or show each one. Search finds a device by name and centers it. … > Task shows the task text and description an imported environment carries.
Layout:
- Align & arrange on the toolbar aligns and distributes the selected devices, snaps devices to the grid, arranges the whole drawing by connectivity, and changes the front-to-back order. Arrange by connectivity moves devices only; it never changes the wiring.
- When ONEP opens an environment whose devices have no positions, such as a newly imported one, it asks Tidy this layout? with Arrange and Dismiss.
- The zoom button shows the zoom as a percentage. Select it for a slider with plus and minus, or double-click it to fit the drawing. Fit view (Ctrl+F) fits everything in view, and does not zoom out below 60 percent so device names stay readable.
- Canvas themes are Navy, Graphite and White, with a grid you can show as Dots, Lines or Plain. Both choices are under … > Appearance and are remembered in your browser.
- Screenshot saves the whole drawing as a PNG file.
- Undo and Redo step through moves, alignment, shapes and text. They do not bring back a deleted device or link.
Containers inside a device#
Some devices host containers. Expose Containers in the device menu turns container visibility on or off for such a device. The change applies when the device next starts, so power cycle it to apply. When a running host has containers to show, selecting it opens a panel listing them with their image, role and address. Select a running container to open a shell in it, or right-click it for Open console, View logs, Start or Stop, Restart and Copy exec cmd. The panel also has an Expose switch, Show on canvas (draws each container as a device linked to the host; Hide on canvas removes them) and Open UI. Expose depends on your edition; see Limits per edition.
Diagram pictures#
An environment can carry a diagram picture, for example one that came with an imported environment. The image button on the toolbar reads Add a diagram picture until there is one; choose a PNG or JPEG file. After that it reads View diagram and opens the picture. Hotspots on the picture open a running device's console, or offer to start a stopped one. Edit hotspots lets you mark a device by clicking a spot on the picture and choosing the device, move or resize a hotspot, and delete it. Add page adds another picture, the arrows step through pictures, and the bin deletes the current one.
Locking an environment#
Lock an environment when it must not change, for example while a class is using it. The lock icon at the top right turns the lock on and off. While it is locked the topology is frozen: you cannot add, delete or move devices, add or delete links, edit configuration or change shapes and text. Starting, stopping and consoles still work. A banner at the top of the canvas says so. The owner of the environment and administrators can release it from the banner or the lock icon.
Packet capture#
Select a link and choose Capture on this link, or open More > Diagnostics > Packet Capture on a device and pick one of its links. See Packet capture.