Getting started / What ONEP is

What ONEP is

A network and security platform that runs on your own hardware, as one appliance.

On this page
  1. What it ships as
  2. What runs where
  3. Sealed by default
  4. The areas you work in
  5. Words ONEP uses

ONEP is a network and security platform. It builds, wires, isolates, runs and removes whole multi-vendor environments: routers, switches, firewalls, servers, endpoints and security tools, cabled together on virtual networks the platform manages for you. It is built for network engineering, security training and cyber ranges: Active Directory attack ranges, blue-team monitoring, OT/ICS segmentation and general-purpose network topologies.

A router is one kind of device among many. Around the devices is the platform: the canvas you draw on, the ready environments you deploy, the image library, the consoles and packet capture.

The ONEP canvas showing a running campus network: a cloud node, an edge firewall, two core switches, three access switches and five endpoints, grouped in labeled zones.
An environment on the canvas: a routed campus core with a firewalled edge, every device powered on.

What it ships as#

ONEP is one appliance that you run on your own hardware. You import it into a hypervisor, and you are the only tenant on the appliance. The same appliance serves every edition; the license you install decides the edition, and an appliance with no license runs as Community.

The appliance contains the platform. You bring your own images, or fetch them through Discover.

  • Images. A Content Hub card downloads and builds its parts from the vendor's own source, on your appliance, the first time you deploy it. Later deploys reuse what was built.
  • Licenses. Cisco images are yours to bring and need your own Cisco license. ONEP does not supply, sell or verify Cisco licenses.
  • Identity. ONEP does not supply vendor credentials or an AI provider key. The appliance creates its own TLS certificate and its own install ID, so no two appliances share an identity.

What runs where#

The appliance runs two layers:

  1. The platform: the web interface, the API, the database and the background services. This is what you sign in to.
  2. The environment layer: the devices that make up your environments. Router images, virtual machines and containers can all sit in the same environment.

After the appliance restarts, environments stay off until you start them.

Sealed by default#

Every environment starts with no path to the ONEP host, to your network, or to another environment. That holds whichever switch it uses. An environment reaches the outside only through a door you add on purpose:

  • Cloud node: outbound internet through NAT from shared address space (100.64.0.0/10, RFC 6598), or a bridge that joins your real network. Tailscale uses the same range, so avoid overlap.
  • Container expose: open an app from the environment in your browser. Which devices can be exposed depends on your edition.

See Network and ports for how each door behaves.

The areas you work in#

AreaWhat it is for
Environments and the canvasBuild topologies by hand, then power them on and off, open consoles and capture traffic.
Content HubDeploy a ready environment or range from a card and a short wizard.
Centrum and DiscoverThe images on your appliance, and downloads straight from the vendor.
AI GeneratorDescribe a network in English and review the topology it builds.
Migration HubImport environments from EVE-NG, GNS3 and Packet Tracer files.
SettingsStatus, network, AI source, remote access, license, users, diagnostics and your account.

Words ONEP uses#

An environment is a topology and the devices in it, whatever built it. Reset returns a device to its first boot; Restart is a power cycle. The Glossary has the rest.

Something wrong or missing on this page? Write to hello@onep.io.