Licensed on-premises software for network engineers
Design it. Size it. Prove it.
The engineering workspace for networks that have to work.
KNOW BEFORE YOU DEPLOY
Stop designing networks in one tool, calculating in another, reading vendor specifications in five browser tabs and writing the report somewhere else. NetSpecForge brings network design, sizing, validation and documentation into one engineering workspace.
- Installs on Windows, Ubuntu and Debian
- Data stays on your infrastructure
- Only online component: licence activation server
- Free download; licence required to activate
01 — Design
A structured topology, not a drawing
Every network is modelled as structured data. Connections terminate on real interfaces, so the design cannot quietly drift from the network that gets built.
- Real interfaces
- Every link names both endpoints as device.port → device.port. Dangling and unterminated links are rejected, not drawn over.
- Structured model
- Devices, interfaces, links, VLANs and subnets are typed objects with relationships — not free-form shapes on a canvas.
- Hardware library
- Verified manufacturer specifications with source provenance. Every spec cites the source document and revision it came from; nothing is typed from memory.
- Provenance
- Each value carries its source: datasheet, vendor portal, or engineer measurement — so reviewers can check the chain.
Link record — example
- Link ID
- L-0042
- Endpoint A
- core-sw-01.Eth1/0/1
- Endpoint B
- dist-sw-01.Eth1/0/48
- Speed
- 10 Gbps (verified: datasheet rev. C)
- Media
- SFP+ DAC, 5 m — within 7 m spec
- Status
- PASS
02 — Size
Deterministic calculations, every time
Bandwidth, path, oversubscription, LACP, PoE and firewall sizing are computed from your inputs by fixed rules. The same inputs always produce the same numbers — and every output cites the inputs it used.
| Calculation | Inputs | Output | Traceability |
|---|---|---|---|
| Bandwidth | Interface speeds, offered load per segment | Required capacity (Gbps) | Each output lists the exact inputs used |
| Oversubscription | Aggregate downlink vs uplink capacity | Ratio (n:1) vs policy ceiling | Policy document referenced; verdict issued |
| LACP | Member count, member speed, hash policy | Effective capacity; worst-case member loss | Single-member-failure case computed explicitly |
| PoE | Per-port class budget, port count, PSU reserve | Watts required vs budget; headroom % | IEEE class table cited per device |
| Firewall sizing | Session count, throughput, ruleset size | Required CPS and throughput; headroom | Vendor benchmark labelled as benchmark |
| Path capacity | End-to-end link capacities along a route | Bottleneck link + utilisation % | Worst link identified by ID, not by guess |
Unknown inputs stay UNKNOWN. If a value is missing, the calculation reports what it cannot compute — it never substitutes a guess. See engineering integrity.
03 — Validate
Twenty named rules. Four honest verdicts.
Every design is checked against validation rules NET-001 through NET-020. Each rule returns one of four verdicts, and the verdict is always stated in words — colour is never the only indicator.
Verdicts
- PASS Requirement met with margin.
- WARNING Met, but within policy tolerance of the limit.
- FAIL Requirement violated; must be fixed before deployment.
- INSUFFICIENT DATA Required input missing; nothing is assumed.
Validation rules
| Rule | Checks for | Example verdict |
|---|---|---|
| NET-001 | Link speed consistency across LAG members | PASS |
| NET-002 | Oversubscription within policy ceiling | WARNING — 2.9:1 vs 3:1 ceiling |
| NET-003 | PoE budget headroom per switch | PASS |
| NET-004 | Firewall session and throughput sizing | PASS |
| NET-005 | End-to-end path capacity (bottleneck) | WARNING — worst link at 62% |
| NET-006 | MTU consistency along the path | WARNING — one hop at 1500 vs 9000 |
| NET-007 | Redundant path availability (no SPOF) | PASS |
| NET-008 | LACP fall-back configuration | PASS |
| NET-009 | VLAN ID uniqueness per segment | PASS |
| NET-010 | Subnet overlap between segments | PASS |
| NET-011 | Routing adjacency feasibility | PASS |
| NET-012 | Transceiver and reach compatibility | PASS |
| NET-013 | Cable length within specification | INSUFFICIENT DATA — lengths not recorded |
| NET-014 | STP loop prevention on access ports | FAIL — 6 access ports without loop guard |
| NET-015 | ACL shadowed-rule detection | PASS |
| NET-016 | Control-plane CPU headroom | INSUFFICIENT DATA — no CPU baseline |
| NET-017 | HA failover capacity (N+1) | FAIL — failover exceeds remaining capacity |
| NET-018 | Management access path exists | PASS |
| NET-019 | QoS policy matches offered traffic classes | PASS |
| NET-020 | Documentation completeness — assumptions recorded | INSUFFICIENT DATA — 2 assumptions unrecorded |
End-to-end path analysis
Follow a flow across the topology and the worst link on the path is computed and highlighted — by ID and by number, not by eye.
04 — Diagnose
Evidence first. Hypotheses second. Never mixed.
The diagnostics workspace keeps observed evidence and engineer hypotheses in separate records. Failure-mode simulation shows what the network does when something breaks — before it breaks.
Observed evidence
- 2026-10-05 09:41 — ifEth1/0/24: input errors 0, output drops 12 (SNMP)
- 2026-10-05 09:44 — measured throughput 2.31 Gbps (30 s test)
- 2026-10-05 09:47 — log: interface state change, port-channel member
Hypotheses — unverified
- H1 — oversubscription on access uplink · confidence: medium · not verified
- H2 — NIC offload mismatch on edge host · confidence: low · not verified
A hypothesis never enters the evidence record until independently verified.
Failure-mode simulation — example
- Simulated fault
- Remove link DIST-B ↔ ACCESS-C
- Recomputed path
- DIST-B → CORE-A → DIST-D → ACCESS-C
- New worst link
- CORE-A → DIST-D at 71% utilisation
- Result
- WARNING — no FAIL introduced
05 — Report
Professional, white-labelled PDF documents
Produce a design document your client's reviewers can actually audit. Your logo, your cover, your colours — and the deterministic outputs embedded, not re-typed by hand.
- Cover and branding — your logo and identity on every page.
- Topology diagrams — generated from the structured model, so they cannot disagree with the data.
- Calculation trace — every input → output pair, so any number can be re-derived.
- Validation results — NET-001…NET-020 with PASS / WARNING / FAIL / INSUFFICIENT DATA verdicts.
- Path analysis — bottlenecks identified by link ID and utilisation.
- Failure-mode simulation results — what was tested, what changed, what it means.
- Assumptions register — every UNKNOWN value listed, so nothing hides in prose.
Document metadata — example
- Title
- Campus core redesign — validation record
- Generated by
- NetSpecForge (on-premises instance)
- Model revision
- r.118
- Rules applied
- NET-001 … NET-020
- Verdicts
- 12 PASS · 3 WARNING · 2 FAIL · 3 INSUFFICIENT DATA
- Branding
- Client white-label — no NetSpecForge watermark
Engineering integrity
The tool must never be the source of a lie
Three rules the engine enforces on itself, on every calculation and every report.
UNKNOWN is an answer
NetSpecForge never invents specifications. If a value is not in the model or its source, the result is UNKNOWN — stated plainly — instead of a plausible guess.
Benchmarks are labelled
Manufacturer benchmarks are quoted with their source and are never presented as guaranteed real-world performance. The distinction is printed on the page.
AI explains; it never calculates
Every number is produced by deterministic rules. AI assistance only explains those results in plain language — it does not compute, estimate or adjust them.
Get NetSpecForge
Download Free
Free download; a NetSpecForge licence is required to activate. Installs and runs on your own Windows, Ubuntu or Debian infrastructure.
Windows
- Platforms
- Windows 10 / 11 (x64), Windows Server 2019 and later
- Package
- Installer (.exe)
Ubuntu
- Platforms
- Ubuntu 22.04 LTS / 24.04 LTS (x64)
- Package
- Debian package (.deb)
Debian
- Platforms
- Debian 12 / 13 (x64)
- Package
- Debian package (.deb)
No build has been published yet. The first public build is in preparation, so there is no download today and no version number to quote. When it is ready, the download will appear on this page first. Activation requires a NetSpecForge licence and our licence activation server — the only component that ever goes online. After activation, all of your data stays on your infrastructure.