NIVMIA Vendor Plugins

DEC NIVMIA — Vendor Platform Plugins

NIVMIA is vendor-neutral because the hard work happens inside the plugins. Each plugin speaks one network vendor's native API or CLI, normalizes it into NIVMIA's platform-agnostic model, and translates policy back down to the vendor's own syntax. Add a plugin → that entire fleet becomes a first-class citizen in the orchestrator. Today: 16 platforms shipped, 2 more in beta.

Enterprise & carrier platforms

The vendors you already run in production. Each plugin covers configuration, inventory, telemetry, and change-orchestration.

Shipping

Cisco IOS / IOS-XE

Catalyst, ISR, ASR, cBR

Full NETCONF / RESTCONF where available, CLI-over-SSH fallback. Config parsing, interface inventory, VLAN / VRF topology discovery, and compliant change-windows via orchestrated commit rollback.

Shipping

Cisco NX-OS

Nexus data-center switching

VXLAN / EVPN fabric discovery, VPC peer awareness, port-channel orchestration, and fabric-wide drift detection. Integrates with DCNM / NDFC where present but does not require it.

Shipping

Arista EOS

eAPI + CLI orchestration

Native eAPI integration. MLAG awareness, VXLAN / EVPN fabric coverage, CloudVision-optional (works with or without). Streaming telemetry consumed where available.

Shipping

Juniper JunOS

MX, EX, QFX, SRX

NETCONF-first. Commit-confirmed / rollback-on-fail orchestration, hierarchical-config awareness, routing-instance and security-zone modeling for SRX.

Shipping

Aruba AOS-S / AOS-CX

HPE Aruba switching

Both legacy AOS-S and modern AOS-CX. REST-API for CX, CLI-over-SSH for older AOS-S. Unified VLAN / ACL / PoE management across mixed-generation Aruba estates.

Shipping

FortiGate (FortiOS)

Fortinet firewall / SD-WAN

FortiOS REST-API. Policy-table management, address / service objects, IPsec / SSL-VPN tunnel orchestration, SD-WAN rule modeling. Coexists with FortiManager where present.

Shipping

Palo Alto PAN-OS

NGFW / Panorama

XML-API and REST-API. Security / NAT / decryption policies, address & service objects, device-group and template-stack awareness for Panorama. Commit-validate before deploy.

Shipping

Cisco Viptela SD-WAN

vManage-orchestrated fabrics

Reads and writes through vManage REST-API. Template / device-config modeling, policy-list lifecycle, site / device inventory. Pairs with the OpenUTM SD-WAN plugin for hybrid fabrics.

Open-source & SMB platforms

The vendors that show up everywhere — labs, branch offices, MSP-managed SMB, homelab, and the OT segments nobody likes to talk about.

Shipping

OPNsense

Open-source firewall / router

Native API integration. Interface / VLAN / firewall-rule orchestration, NAT, IPsec / WireGuard / OpenVPN tunnels, HAProxy package awareness.

Shipping

pfSense / pfSense Plus

Open-source + Netgate commercial

Config-XML parsing plus the pfSense REST-API package. Alias / rule / schedule orchestration, gateway & routing-group modeling, multi-WAN support.

Shipping

firewalld

Linux host-level firewall

DBus-backed zone / service / rule orchestration for Linux hosts running firewalld. Useful for host-level ACLs that complement a perimeter firewall — and the audit plugin for OpenUTM feeds off the same data.

Shipping

Ubiquiti UniFi

UniFi OS gateways, switches, APs

UniFi Controller / UniFi OS API. Network / WLAN profile orchestration, switch-port modeling, site-to-site VPN, and topology discovery across multi-site UniFi estates.

Shipping

Netgear Smart / Managed

GS / MS / M4xxx lines

Web-API + CLI fallback. VLAN, PoE, LAG, and ACL orchestration for the managed / smart-managed Netgear product lines that show up heavily in SMB and branch environments.

Shipping

TP-Link Omada / Jetstream

Omada controller + standalone

Omada Controller API for managed fleets, per-device CLI fallback for standalone Jetstream switches. VLAN / SSID / ACL orchestration with Omada site awareness.

Shipping

D-Link Managed

DGS / DXS managed series

CLI-over-SSH orchestration with screen-scrape normalization. Covers VLAN, LAG, ACL, and port-security on the managed D-Link lines that persist in manufacturing and education.

Shipping

TRENDnet Managed

Web-managed industrial / SMB

HTTP-API + CLI. VLAN, PoE, QoS orchestration on TRENDnet's managed lines — common in small-industrial and education deployments.

Shipping

MokerLink Managed

Budget managed 2.5G / 10G

Normalized orchestration for MokerLink's managed 2.5G and 10G lines. Common in prosumer / small-office uplinks where 10G arrived before the budget for Cisco or Arista.

In beta / roadmap

Beta

Extreme Networks EXOS

Switching & wireless

REST-API integration in beta. VLAN, LAG, policy-based routing, and wireless-controller orchestration.

Beta

Mikrotik RouterOS

RouterOS v7 API

Beta plugin for RouterOS 7's REST API. Common in ISP / WISP deployments and small enterprises.

Beta

Nokia SR OS (Service Router)

Carrier-grade routing

NETCONF-first plugin under active development for carrier and large-enterprise deployments.

How the plugin architecture works

Every vendor plugin implements the same NIVMIA interface — inventory, config-read, config-write, telemetry, change-orchestration — so a fleet-wide policy is authored once and translated to each vendor's native syntax at deploy time. New plugins are signed, versioned, and hot-loadable into a running core without a full reinstall.

Your network runs more than one vendor. Your orchestrator should too.

NIVMIA plugins are how you keep the vendor-neutral promise without giving up the features your team already depends on.

Back to All Products Talk to Us