SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
AI Specialist · Traffic & paths · Rolling out

HeHermes

Follows any packet anywhere. Why was this blocked, where is this IP used, is this connection allowed, answered from the live path, not from a config guess. And when the network itself misbehaves, Hermes digs to the root cause, deep into SD-WAN and backbone.

The pathfinder

The live path, not a config guess.

Most networking incidents get analysed by reading configs and hoping they describe reality. Hermes works from reality itself. He follows the packet along the path it actually took, through firewall, tunnel, SD-WAN and backbone, and shows what happened to it at every hop.

That covers the everyday questions, why was this blocked, where is this IP used, is this connection allowed, and the hard ones: when a site is slow or a link degrades, Hermes runs the root-cause analysis deep into SD-WAN and backbone, down to a carrier-side path flap.

Live path

The real forwarding path, hop by hop, not a guess from the config.

Root cause

Deep into SD-WAN and backbone, down to the carrier-side event.

One question

Replaces a day of hopping between consoles and logs.

Trained on 35 years

What Hermes learns.

  • Your live paths: flows, tunnels, routing and policy decisions as they actually happen
  • 35 years of network incidents and how their root causes were actually found
  • How SD-WAN and backbone failures look before, during and after, from telemetry, not theory
Capabilities

Follow any packet anywhere.

  • Answers "why was this blocked?", "where is this IP used?", "is this connection allowed?" from the live path
  • Deep SD-WAN and backbone root-cause analysis, down to the carrier-side event
  • Links every answer straight to the evidence in the portal
  • Turns a day of console-hopping into one question
"Why is this blocked?""Where is this IP used?""Is this connection allowed?""Why was the site slow yesterday?"
How it works

From a 5-tuple to the live path.

Give Hermes a flow, an IP, an object or a plain-language question. He reconstructs the path the traffic actually took from live state, not from the config, and shows the decision at every hop.

1 - Resolve the target

Maps your question to a concrete 5-tuple and time window: source, destination, port, protocol, and the sites or users involved.

2 - Reconstruct the path

Replays flow records, firewall sessions and tunnel telemetry to rebuild the forwarding path hop by hop, with the allow or deny decision at each firewall and gateway.

3 - Correlate the underlay

Aligns SD-WAN path selection, uplink health, BGP and carrier events over the same window, so a flap or a policy change lines up with the symptom.

4 - Localise the cause

Separates your configuration from the network: a shadowed rule, a saturated uplink, or a carrier-side route change. Each verdict links to the raw evidence.

See it in action

One question, a full trace.

You ask"Why can't the Munich office reach the payroll API since 14:00?"
# hermes · path trace · site-DE-MUC -> payroll-api:443 trace 10.42.6.0/24 -> 203.0.113.20:443 window=14:00-now hop 1 swg-muc allow rule "SaaS-allow" 0.4 ms hop 2 fw-edge-muc allow session established 1.1 ms hop 3 sdwan uplink-A degraded loss 22% jitter 140 ms hop 3' sdwan uplink-B healthy path not selected ! cause traffic pinned to uplink-A; carrier flap since 13:58, seven route changes ✓ verdict not your policy. Failover to uplink-B stages the fix; carrier ticket drafted.

Representative trace. Every line links to the underlying flow, session and path-selection records in the portal.

Data sources

Grounded in your live telemetry.

Flows & sessionsNetFlow / IPFIX, firewall and proxy session logs, connection state across every gateway.
Path & underlaySD-WAN path selection, uplink loss, latency and jitter, tunnel health, BGP and carrier events.
Policy contextFirewall, ZTNA and SWG rules, objects and their references, so every allow or deny is explained.
History35 years of network incidents and their resolutions, to recognise a failure mode from its first symptoms.
One door

Reports to Lucy. You talk to her.

You never address Hermes directly. Ask Lucy "why was the Frankfurt site slow yesterday afternoon?" and she consults him behind the curtain, then answers in one voice, with Hermes named as the source. He works alongside the rest of the team:

  • Lex explains the policy behind a blocking decision
  • Argus triages what the gateways caught on the way
  • Prometheus uses the same telemetry to see the failure coming
Bounded autonomy

Autonomous, not autonomous-washing.

Grounded

Every answer cites the live path and real telemetry, not free-form generation.

Bounded autonomy

Hermes diagnoses and explains; any change still runs through propose, approve, act.

Human accountability

Level-3 engineers own every critical call. No L1, no L2.

Sovereign-aware

Scoped to your tenant, region-pinned, with the evidence to prove it.

Maturity & roster

Go deeper.

Maturity: Rolling out. Hermes ships with Lucy: no extra tool, no separate console, no additional contract. The network gets a voice inside the conversation you already have.

See the operators run your SASE.

Watch the agents diagnose, decide and act, with Level-3 engineers owning every critical call.

Book a demo
Already a customerEverything you use today keeps running.