The networking page shows whether your Link Agents are connected, how much traffic flows through each tunnel, and whether any agent's host is running short of capacity. This article describes what each part of the page shows. Open it at Settings > Networking. Agents on company tunnels appear on the Networking page of the company dashboard, which has the same layout.
The page refreshes every 10 seconds, so you can watch traffic move through a tunnel while a test runs. Choose 1h, 24h, or 7d to set the time range for the charts.
Summary
The counts at the top of the page:
| Count | What it shows |
|---|---|
| Active agents | Link Agents that are connected now |
| Active tunnels | Tunnels with at least one connected agent |
| Warnings | Link Agents reporting a capacity warning or a critical health state |
| Updates available | Link Agents with a newer release available to install |
Charts
| Chart | What it shows |
|---|---|
| Throughput (Mbps) | Traffic across all of your agents, Outbound to mabl and Inbound from mabl |
| Active sessions by tunnel | How many sessions each tunnel carries. A session is one tunneled TCP connection, a test reaching a target in your network through the agent, so there is roughly one per concurrent request a running test makes. |
| Connections by outcome | How the connections your tests opened through the tunnels ended. See Connection outcomes. |
| Avg RTT | The average round-trip time between your Link Agents and the mabl cloud, across all tunnels |
Connection outcomes
| Outcome | Meaning |
|---|---|
| Successful | The agent connected to the target. |
| DNS lookup failed | The agent's host could not resolve the target's name. |
| Connection refused | The target actively refused the connection, usually because nothing listens on that port. |
| Connection timed out | The target didn't answer in time, often because a firewall drops the traffic. |
| Target unreachable | The agent's host has no route to the target. |
| Connection failed | The connection failed for another network reason. |
| Blocked by connection filter | The agent's connection filter doesn't allow the target. |
| Agent out of connection resources | The agent's host ran out of resources for new connections, such as open files or local ports. See the agent's details. |
| Authentication rejected | The connection was not authorized to use the tunnel. |
| Malformed request | The agent received a request it couldn't read. |
A rise in anything other than Successful points at the problem to look into. DNS, refused, timed-out, and unreachable outcomes come from the network the agent runs in, not from mabl.
Tunnels
The Tunnels table has a row per tunnel, grouping every agent that serves it:
- Agents: how many agents are connected to the tunnel
- Throughput: the tunnel's traffic
- Health: whether any agent on the tunnel is in a warning or critical state, or whether no agent is connected
- Environments: the environments that route through the tunnel. On the company dashboard, this column is Workspaces instead.
Click a tunnel to open its details, which list Agents on this tunnel and chart Connection quality over time.
Link Agents
The Link Agents table has a row per Link Agent:
| Column | What it shows |
|---|---|
| Agent ID | The agent's ID. Click it to open the agent's details. |
| Tunnel | The tunnel the agent serves |
| Agent host | The name and address of the machine the agent runs on |
| Distribution | Java for the Link Agent installers, archives, and Docker image, or CLI for an agent run with the mabl CLI |
| Version | The agent's version, marked Update available with the newer version when there is one |
| Health | Healthy, Warning, Critical, Offline, or Unknown, from the agent's host resources |
| Sessions | The sessions the agent carries now |
| Latency | The round-trip time between the agent and mabl |
| Throughput | The agent's traffic |
| Endpoint | How the agent connects to mabl: QUIC, WSS, or Legacy. Hover over an endpoint to see whether it is in use. |
| Status | The agent's state. See Agent statuses. |
| Last connection | When the agent most recently established its connection to mabl |
| Actions | The Manage menu, to enter or exit maintenance or shut the agent down |
A warning icon in the Endpoint column means the agent can't reach one or both of the Link 3.0 endpoints. See Troubleshooting issues with mabl Link.
Agent statuses
| Status | Meaning |
|---|---|
| Initializing agent | The agent is starting. |
| Updating | The agent is installing an update. |
| Initializing tunnel | The agent is setting up its tunnel. |
| Announcing | The agent is registering its tunnel with mabl. |
| Securing tunnel | The agent is connecting to mabl. |
| Connected or Ready | The tunnel is ready and carrying test traffic. |
| Draining | The agent is in maintenance mode, and its current connections are finishing. |
| Drained | The agent is in maintenance mode and has no active sessions. It is safe to shut down. |
| Shut down | The agent was shut down. |
A Connected agent whose last heartbeat is overdue shows a warning, because it may be having trouble reaching mabl.
Agent details
Click an agent's ID to open its details:
- Live capacity & host health: the host's CPU, memory, and open-file use against their limits, and Tunnel capacity, which estimates how many tunnels the host's memory supports. A resource that is low on headroom is flagged before it limits the agent. See Sizing and scaling Link Agents.
- Host tuning & sizing: host settings worth changing, with the change to make, such as too little memory for the agent's tunnels, a narrow ephemeral port range, small socket-buffer limits, or a Link 3.0 endpoint the host can't reach.
- Host pressure: load average, swap, disk space, and open sessions.
- Active carriers: the agent's carrier connections. A carrier is the connection a Link Agent makes to mabl, over QUIC or WSS, to establish the secure tunnel.
- Recent errors: the latest errors the agent reported.
- Configuration: the settings the agent runs with, including its Point of contact, connection filter, proxy settings, release channel, auto-updates, and the tunnels it serves.
- Connection quality over time: charts of round-trip time, packet loss, retransmits, throughput, sessions, connection outcomes, and how close the tunnel is to saturation.
Recent activity
Recent activity, at the bottom of the page, is a timeline of what your agents have done, such as registering, connecting, disconnecting and reconnecting, entering and finishing maintenance, updating, and shutting down. It also shows access to your tunnels: who accessed a tunnel, connections that were denied, and sessions that mabl support started.
The same events appear in the activity feed under the link agent and link tunnel access entity types. Events for company tunnels appear in the company dashboard's activity feed.