Expansive
Network Admiral
Network Management Center
Forgot your password?
Expansive
Reset password
We'll email you a reset link
If an active account exists, a reset link will be sent. The link expires in 1 hour.
Expansive
Choose a new password
Network Admiral
Expansive
Two-step verification
Enter your 6-digit code
Send a new code Use a backup code
Expansive
Set up two-step verification
Required for Network Admin accounts

Pick how you'd like to receive your sign-in codes. You can change this later from your profile.

Scan this with your authenticator app, or enter the key by hand:

Two-step verification is on.

Save your backup codes. Each one signs you in once if you lose your phone or your email. This is the only time they are shown.


        
Expansive EXPANSIVE Network Admiral

  • Change Password
  • Logout
Dashboard Properties Companies WiFi Users Login Attempts Usage
Tech
ISP Circuits Network Public IP Assignments Access Points Audit Log Yardi Kube Sync
Admin Accounts

Dashboard

Activity & Usage
System Health

Properties

Property Companies WiFi Users Actions

Customer Name Office VLAN Bandwidth Subnet Public IP Users Actions
Connected Clients (live)
UserCompanyIPMACAP AP UplinkConnected Status

Office Port Map

Companies

Property Customer Name Office VLAN Bandwidth Subnet Public IP Users Actions

WiFi Users

Username Full Name Property Company VLAN Password Status Actions

Admin Accounts

Email Name Role Properties 2FA Status Last Login Actions

ISP Circuits

Network

Public IP Assignments

Access Points

AP NameMACLocation VendorIPActions

Audit Log

When Network Admin Action Area Target Property Details

Yardi Kube Sync

Per-property Yardi records
Property Yardi companies Yardi WiFi users Status Auto-email Sync

Welcome emails to new Wi-Fi users
Queued Property User Why Status Detail
Tenants that can't be synced to the site they occupy —
Tenant Office here Why it can't sync Where their record is Last seen

Usage

Company Property Plan Now ↓ Peak ↓ % plan Users Active Volume Last seen
Throughput is device-observed per company (VLAN) from the core over SNMP; volume and presence come from WiFi accounting. "% plan" is today's peak download vs the plan rate. Infrastructure VLANs 1–20 are excluded. Rows are ranked by utilization.
Company usage
Loading…
CPU load history
Loading…
Rejected authentications · last 24h
Loading…

Login Attempts

Security

Two-Step Verification …

Loading…

Two-step verification is required for your role and can't be turned off. A Network Admin can reset it for you if you lose your device.
Trusted browsers

How would you like to receive your sign-in codes?

Scan with your authenticator app, or type this key:

Save these backup codes. Each signs you in once if you lose your device. This is the only time they're shown, and generating them invalidates any earlier set.

              

Change Password

Add Access Point
Activity Report —
Property
Friendly label shown across the portal. Leave blank to use the system name below.
Activity reports use this zone. Blank falls back to Central.
System name — used to match imports (Network Commander & ISP). Avoid changing once set.
Used to build network-device hostnames. UPPERCASE letters, numbers and dashes only. Optional.
10. .x.x
Property octet only. Builds 10.<loc>.0.0/16 — core 10.<loc>.2.1, switches 10.<loc>.2.2–149. Leave blank to derive from companies.
Company
—
Caps how many users a company admin can add in the customer portal. Blank = unlimited.
Assign Public IP
Available addresses from this property's Active-Primary ISP block. Pick “Other…” to enter one manually.
WiFi User
Changing the property moves this user and reloads the companies below.
Required. The company's VLAN is what RADIUS gives this user — without one they land on the management network (VLAN 2).
Move User

Moving from to another property, or to a different company at the same property. The user's VLAN follows whichever company you pick.

Reset Password

Username:

Make Company Admin

Make a Company Admin?

They'll be able to sign into the customer portal and add, remove, enable, disable, view, and email passwords for users in their company.

Delete WiFi User

Permanently delete ?

This removes them from RADIUS authentication immediately and cannot be undone.

Yardi Kube Sync —
Admin Account
Sends the account email address their role, sign-in link and password.
Network Admins have access to all properties automatically.
ISP Circuit
Edit Device

IP:

Change to reassign this device — e.g. convert a Switch to an Edge (or back). The IP stays the same; vendor options update to match.
Defaults to the floor/switch convention; override here if needed.
Auto-built from the Location Prefix + Name (e.g. ATX1-FL2-SW1) and saved with this device. Set the prefix on the property to change it.
Used by automation scripts. Options depend on device type.
OPNsense interface for future automation (e.g. wan, lan, opt1). Defaults to wan.
WAN IP is picked from this property's ISP block — already-assigned IPs (e.g. the Expansive/house IP) are shown and stay selectable. Mask & gateway pre-fill from the circuit; edit if this firewall differs. Stored for the automation box.
Write-only. Handed to Ansible Vault on the automation box — never stored here or shown again.
The core's SNMP listen-address — usually 10.<loc>.7.1, not the mgmt IP.
Feeds the per-VLAN throughput on the Usage page. The collector polls every 5 min.
FS core — bandwidth is tracked via sFlow, not SNMP. The core exports sFlow to the automation box (network-sflow-collector.service, UDP 6343); there is no per-device toggle here. See PerimeterFSCore_sFlow_Setup.md.
Add Device

Auto-filled from floor/switch — edit if needed.
Hostname: — (auto-built from the property prefix + name)
Used by automation scripts. Options depend on device type.
OPNsense interface for future automation (e.g. wan, lan, opt1). Defaults to wan.
WAN IP is picked from this property's ISP block — already-assigned IPs (e.g. the Expansive/house IP) are shown and stay selectable. Mask & gateway pre-fill from the circuit; edit if this firewall differs. Stored for the automation box.
Mgmt VLAN is auto-derived from the IP; edit it later if needed.
OPNsense API Secret

Device: . The key and secret are handed to the automation box for Ansible Vault and are never stored in this portal or shown again.

SSH connecting…
SNMP
Topology
Help & Guide
Guide only — nothing here leaves your browser.