D
Damira AI

Troubleshooting

11 network domains, advisor mode, and how the assistant diagnoses issues across vendors.

The troubleshooting engine covers 11 network domains across multiple vendors. Describe the problem in plain English, and the assistant walks you through diagnosis using vendor-specific documentation and proven methodology.

Advisor Mode

By default, Damira AI runs in advisor mode. This means:

  • The assistant recommends commands for you to run on your devices
  • You paste the output back into your AI session
  • The assistant analyzes the output and continues diagnosis
  • No SSH connections. No credentials stored. Your data stays on your network.

This is the most secure operating mode. The assistant never touches your devices directly.

Supported Domains

DomainWhat It Covers
BGPPeering issues, route advertisement, path selection, community filtering
OSPFAdjacency problems, area configuration, LSA analysis, DR/BDR election
NATTranslation failures, pool exhaustion, PAT conflicts, policy-based NAT
MTUPath MTU discovery, fragmentation issues, black hole detection
SwitchingVLAN, STP, trunk negotiation, MAC table, port-channel issues
ConnectivityReachability, traceroute analysis, ARP resolution, interface state
Voice/UCSIP registration, one-way audio, call drops, codec negotiation, MRA
WirelessClient association, roaming, channel utilization, AP connectivity
Palo AltoPAN-OS security policies, NAT rules, GlobalProtect, threat logs
FortiGateFortiOS policies, SD-WAN, VPN tunnels, session analysis
JunosSRX/MX/QFX troubleshooting, routing policies, commit issues

How It Works

  1. You describe the problem — "OSPF adjacency won't come up between core-rtr-01 and dist-rtr-02"
  2. Domain identification — The assistant identifies this as an OSPF troubleshooting request
  3. Evidence you already have — Paste any alerts, metrics, or log excerpts from your monitoring along with the symptoms
  4. Documentation lookup — Relevant vendor documentation is pulled automatically
  5. Structured diagnosis — Ranked root causes, with the specific commands to run for anything your evidence doesn't cover
  6. Iterative analysis — You paste command output, the assistant narrows down the root cause

The assistant follows a structured diagnostic methodology: Gather → Isolate → Diagnose → Recommend → Prevent.

my eBGP session to 203.0.113.1 on wan-r1 (ISR4451, IOS-XE 17.9) keeps dropping
every 3 minutes. Here's show ip bgp summary and the log:
...

What comes back is a ranked diagnosis, not "check the config":

**Problem:** eBGP session to 203.0.113.1 resets every ~180 s (hold-timer expiry).
 
**Differential diagnosis (most probable first)**
1. Hold timer expiring: keepalives lost on the path (log shows
   %BGP-3-NOTIFICATION sent 4/0 hold time expired)
2. MTU mismatch dropping full-size UPDATEs after the session establishes
3. Control-plane policing dropping BGP on a busy CPU
 
**Run next**
    show ip bgp neighbors 203.0.113.1 | include hold|keepalive|Last reset
    ping 203.0.113.1 size 1500 df-bit
    show policy-map control-plane | section bgp

Start with What Your Monitoring Shows

Paste the firing alert, a metric excerpt, or the relevant log lines from Prometheus, Grafana, Loki, or your syslog server into your AI session along with the symptoms. The assistant uses that evidence first and only asks for CLI output when it needs data your monitoring doesn't capture. See Monitoring.

Tips for Better Results

  • Be specific about the problem — "BGP neighbor flapping every 30 seconds" is better than "BGP is broken"
  • Include device context — Mention the vendor and platform if possible (e.g., "Cisco IOS-XE 17.x", "Palo Alto PA-5200")
  • Paste full command output — The assistant parses structured output from show commands, so include everything
  • Use multi-turn conversation — The assistant remembers context within a session. Follow up with additional details as you gather them.

Config Security Audit

Paste a device configuration into your AI session, or point at a file in configs/, with a request like:

Audit this config for security issues:

hostname core-rtr-01
...

The assistant checks for common security gaps: default credentials, unencrypted protocols, missing ACLs, open management interfaces, and more.

The audit runs on your machine, so your config never leaves it. Findings come back by severity (excerpt):

Config Analysis Results (13 issues found):

[HIGH] Line 2: Use 'enable secret' instead of 'enable password'
      → enable password cisco123
[HIGH] Line 3: Type 7 passwords are trivially reversible
      → username admin password 7 0822455D0A16
[HIGH] Line 7: Telnet enabled on 'line vty 0 4' — restrict transport input to ssh
[MEDIUM] Line 4: Review SNMP community string security — prefer SNMPv3
[MEDIUM] Line 6: 'line vty 0 4' has no access-class — management access is unrestricted
[MEDIUM] No NTP server configured
[LOW] No login banner configured

Your AI then gives you the remediation commands for each finding.

Config Generation

Describe what you need and the assistant generates configuration:

  • Subnet calculations and IP addressing
  • Interface configurations
  • Routing protocol setup
  • Access control lists
Generate an IOS-XE config for a branch router: OSPF area 10 on Gi0/0/1,
eBGP to the ISP at 198.51.100.1 AS 64500, SSH-only management with an ACL.

Supported for Cisco, Juniper, Arista, Palo Alto, and Fortinet.

On this page