| Hostname | Plant | Floor | Line | IP Address | MAC | Switch | Port | State | Registered At | Agent Version | Last Seen |
|---|
Pick a plant tab, then a floor tab, to edit that floor's lines and IP ranges. Each floor's subnet is auto-detected from its plant + floor label (e.g. P2 / 1F → 172.16.10.0/24–172.16.11.0/24) and shown read-only. For floors not in that auto-detect map — or to supplement an auto-detected floor — add Custom IP ranges, which a locked PC's plant/floor is also matched against when it activates. A PC activates by scanning its QR and picking the line it's on. Changes here are pushed to PCs on their next check-in.
Add each managed switch the server can reach over SNMP (UDP 161). The poller walks enabled switches to map each registered PC’s MAC to a physical port (e.g. GigabitEthernet1/0/1) and flags any PC that reappears on a different port for re-registration (a moved PC). Same-port reconnects never re-lock. Community string is per-switch; on Comware, for a non-default access VLAN use a VLAN-indexed community such as public@10.
Uploading does not push the build to hosts by itself — click "Publish" next to a version once you've verified it, and hosts will pick it up on their next check-in.
The first URL in this list is encoded into every QR's activation link, so phones outside the tailnet can open it. Add your Tailscale Funnel HTTPS URL here. If the machine serving Tailscale ever changes, just edit the URL here — it takes effect on the next QR, with no .env edit or server restart. Every listed hostname is also treated as "public" by the gateway: only the phone activate flow and agent-keyed requests (X-Agent-Key) are exposed there; everything else is blocked.