AUTONOMOUS TROUBLESHOOTING
Most of an outage is spent finding the cause.
The fix is usually small. The hours go somewhere else — into a bridge call where six teams each demonstrate it isn’t their layer, and the firewall team is guilty until proven innocent. FireWeave shortens the part that actually takes the time.
How a session runs
Resolve the real path
Before anything else, FireWeave works out which devices the traffic actually crosses — firewalls, routers, switches, fabric and cloud. If policy alone already explains the failure, it stops here and tells you, without touching a single device.
Gather evidence in parallel
Read-only checks run across every managed hop at once: policy match, NAT, routes, ARP, interface state, system health. This phase needs no approvals because nothing it does can change anything.
Investigate, bottom-up
The agent then works the OSI stack from the bottom. Interfaces and errors before policy — because a timeout is usually a duplex mismatch or a dead next hop, not a firewall rule. Each proposed command arrives with the reasoning behind it.
You approve, it executes
Nothing runs until a human says so. You see the exact command, the device, the layer it targets and why the agent wants it. Approve, deny, or approve everything pending across all hops.
Conclude — and validate the fix
The agent names the root cause with a calibrated confidence score and concrete remediation. After you make the change, it can re-run the decisive checks and show you a before-and-after diff proving the problem is actually gone.
The safety model, in full
“Autonomous” is a word that should make a network security team nervous. So here is exactly what it means here, and what it does not.
What it can do unattended
- Run read-only diagnostic commands — show, ping, route lookups
- Only from a curated, per-vendor command library
- Within a command budget the server enforces, not the client
- Under a permission you grant separately from ordinary use
What it can never do
- Run a configuration command — write verbs are blocked outright
- Run free-form CLI in autonomous mode — refused categorically
- Exceed its budget — the run halts and is marked as halted
- Escape the audit trail — every command and approval is recorded
It tells you what it didn’t check
An AI that only reports what it found is easy to build and dangerous to trust. FireWeave separates what it proved from what it assumed, and states plainly what it never tested.
Every finding is classified
- Proved — backed by a command and its output
- Assumed — asserted but unsupported
- Not tested — a check the symptom warranted that never ran
- Contradicted — where the evidence disagrees with itself
Confidence you can audit
- A published formula, not a model's self-assessment
- Hard caps the model cannot argue past
- Penalties for invalid commands and unresolved contradictions
- Every score ships with its full breakdown
Where it can investigate
- Palo Alto and Panorama, via the management API
- Cisco IOS, IOS-XE, IOS-XR, NX-OS and ASA
- Juniper Junos and Arista EOS
- Check Point gateways, under a separate permission
- Cisco ACI contract evaluation
- F5 BIG-IP virtual server diagnostics
- AWS, against collected topology rather than live API calls
What you get at the end
- Root cause, remediation and calibrated confidence
- Every command, its output and who approved it
- A hop-by-hop path summary
- Exportable to PDF or Markdown for the incident record
- Attachable straight back to the originating ticket
Bring us a problem you haven’t solved yet
Twenty minutes, your environment, a real flow that should work and doesn’t. No slideware.
Book a 20-minute demo