Skip to Content
  •  +49 (861) 88 00 32 00
COD powered by extocode GmbH
  • 0
  • Sign in
  • Contact Us
  • Home
  • COD Overview
    Platform
    OverviewFeaturesIntegrationsPricing
    Operations & Network
    MonitoringNetworkNetwork Access Control (NAC)Captive PortalFirewall
    Security & Resilience
    Governance, Risk & ComplianceVulnerabilities (VAS)BackupHypervisorOTPAutomation
    Solutions & More
    NIS2 & CompliancecodPassLive demoReferencesDownloadsFAQ
  • Pricing
  • News
  • FAQ
  • About us
    • About us
    • Careers
    • References
  • Contact
COD powered by extocode GmbH
  • 0
    • Home
    • COD Overview
    • Pricing
    • News
    • FAQ
    • About us
      • About us
      • Careers
      • References
    • Contact
  •  +49 (861) 88 00 32 00
  • Sign in
  • Contact Us

Frequently Asked Questions

General & PlatformCOD – General QuestionsFeature OverviewIntegrationsNIS2 & CompliancePricingLive DemoNetwork & AccessMonitoringNetwork Access Control (NAC)Captive PortalTACACS+ (Device Administration)Switch AutomationSecurity & IdentityVulnerabilities (VAS)OTP AuthenticationcodPassStronghold – Password Vault (coming soon)Operations & ResilienceBackup & Disaster RecoveryHypervisor Management (virtual switches)

General & Platform


COD – General Questions

What is the COD (Central Operations Dashboard)?

The COD is a vendor-independent platform that brings your IT infrastructure together in one place — as a single source of truth. Rather than replacing siloed solutions, the COD connects your existing systems and centralizes their control, documentation, and reporting.

Who is the COD for?

For IT departments and service providers that operate heterogeneous infrastructures spread across multiple sites and want to bring operations, documentation, and compliance together in one place.

Does the COD replace my existing systems and tools?

The COD combines its own solutions with integrations. Capabilities such as NAC, backup, OTP, GRC, or virtual switch management are delivered as standalone, vendor-independent solutions. Existing third-party systems — such as directory services, monitoring, your CMDB/asset management, Baramundi, or firewalls — remain in place and are connected. You keep the mechanisms you know and gain central transparency and automation.

Which modules does the COD offer?

All modules are active by default and already installed out of the box — the only exception is our optional VAS module (Vulnerability Assessment).

We include the following as standalone, vendor-independent solutions: Network Access Control (NAC), backup/disaster recovery, OTP authentication, GRC (including NIS2 support), hypervisor management (for virtual switches), as well as network documentation and visualization (L2/L3 topology) including firewall and report management.

Through integrations, we also connect existing third-party systems: directory services, monitoring, your CMDB/asset management, and Baramundi.

Is the COD run in the cloud or on-premises?

The COD is delivered as containers and can run on-premises or in your own environment (including Docker and Kubernetes/Helm). Your data therefore stays within your infrastructure.

Where does my data reside? Is operation GDPR-compliant?

Because the COD runs in your own environment, your data stays under your control. Access is governed by roles and is logged. Data is held in dedicated databases, and site-specific data is stored separately per tenant/site.

How does user and permission management work?

Through role-based access control (RBAC). Permissions are assigned in fine-grained detail per module, role, and site. For sign-in, existing directory services can be connected via LDAP/Active Directory, and local accounts are supported as well.

Does the COD support multiple tenants and sites?

Yes. The COD is multi-tenant and multi-site capable. Data and permissions are separated per site, and users can switch between the sites they are authorized for.

How does the COD help with NIS2 and GRC?

The GRC module digitizes the risk matrix, asset-based risk management, and policy and threat catalogs. Combined with the central asset and dependency context, the COD supports the evidence and documentation obligations under NIS2.

Which systems and vendors can be connected?

The COD is multi-vendor capable. In network management, it supports Cisco, HPE, Allied Telesis, Ruijie, and MikroTik, among others. Firewalls can be managed via OPNsense, pfSense, and AIMdefense. For NAC, PacketFence can be connected as an alternative. In addition, we connect directory services (LDAP/Active Directory), monitoring, your CMDB/asset management, and Baramundi. The goal is to operate with your existing, heterogeneous infrastructure.

How secure is the COD?

Security is built in from the ground up: role-based access, optional two-factor authentication (OTP), encrypted storage of sensitive data, and end-to-end audit logs. Tenants are already separated at the database level. On-premises operation keeps data and access within your environment.

What does the COD cost and how is it licensed?

All modules are included in the base price — there is no separate licensing for individual modules. Only our VAS module (Vulnerability Assessment) is optional and comes at an additional cost. For a custom quote, contact us at info@extoco.de or +49 (861) 88 00 32 00.

Feature Overview

Is this list complete?

It covers the core features currently shipping, condensed module by module into one description per feature. We continuously maintain the complete, technically detailed picture — just ask about a specific project.

Are all features included in every license?

COD is modular: you license the modules you need. Which features belong to which module is shown above in the respective group, and the terms are listed on the Pricing page.

Does COD run fully on-premises?

Yes. COD runs in your environment, and you retain full data sovereignty — a good fit for KRITIS and NIS2 requirements.

Integrations

Does COD replace my existing tools such as Zabbix or Baramundi?

No. COD talks to your existing systems through Connect integrations and consolidates their data instead of replacing them.

How does the Baramundi integration work technically?

Through the REST-based bConnect interface: communication via JSON, secured over HTTPS with authentication and SSL. Inventory data is imported automatically and synchronized into your CMDB.

Is codPass already integrated into COD?

codPass can be run standalone today. Native integration into COD is in preparation. Browser plugins are not part of the product.

NIS2 & Compliance

Does COD make my organization NIS2-compliant?

COD delivers the technical building blocks that NIS2 requires — asset transparency, asset-based risk management, and gapless auditability. The specific legal assessment of your obligations remains with you or your legal counsel. COD is not a substitute for legal advice.

Do we have to put data in the cloud?

No. COD can run fully on-premises and is KRITIS-ready. Compliance data resides in a dedicated PostgreSQL database under your full control.

Why "on live data"?

The GRC module works on the same assets that COD-Network detects and maintains automatically. Your risk assessment refers to the actual asset including its live status — not to an outdated list.

Pricing

Are the prices shown binding?

These are non-binding list-price guide values (net, EUR/month unless stated otherwise). Your final price depends on the number of seats, hosting model, asset size, and service level — we will prepare a custom quote for you.

What is the minimum cost of COD?

Entry starts at a minimum of 2 seats at €47.50 each plus a tenant fee starting at €8 (self-hosted). VAS and service packages are added as needed.

Do I get a discount for a longer term?

Yes — with a 36-month contract term, seats come with a 10% term discount. For very large environments (from 25,000 assets), we calculate individually.

Live Demo

Does the demo take place in our own environment?

If you like, yes. We demonstrate COD hands-on using scenarios from your environment — or with a prepared sample environment, whichever works best for you.

Is the demo non-binding?

Yes. The live demo is free and without any obligation — no sales pressure.

Which modules can we take a look at?

Any that interest you: from Network & Assets to NAC, firewall & VPN, GRC, and monitoring, all the way to vulnerability management and backup. You set the focus.

Network & Access


Monitoring

How quickly does COD detect an outage?

That depends on the check interval, which you configure per tenant via a cron job. This lets you set the check frequency to suit each customer and site.

Will I be flooded with alert emails during an outage?

No. Per-firewall throttling prevents repeated alerts about the same issue, and you schedule planned maintenance centrally in the calendar, so monitoring does not trigger without reason.

Do I need an additional monitoring system?

Monitoring is built directly into COD as a module and uses the same data as your network inventory. Existing systems such as Zabbix can be connected through Connect integrations.

Network Access Control (NAC)

Technical Profile
  • Type: COD-native, vendor-independent NAC solution based on RADIUS
  • Authentication: 802.1X (EAP with certificates), MAC authentication
  • Access control: dynamic VLAN assignment (Tunnel-Private-Group-Id, Cisco-AVPair, Egress-VLANID), client groups with priorities, quarantine VLAN
  • PKI: integrated certificate management for 802.1X (CA/leaf certificates, CRL, PKCS#12 export)
  • Windows CA: alternatively, connect existing Windows CA environments in read-only mode (reads out existing certificates)
  • NAS management: switches/access points with shared secret
  • Logging: authentication and accounting logs (success/failure, sessions), connection statistics
  • Import: CSV bulk import (MACs, VLANs, groups) with validation and conflict detection
  • Device discovery: ping/monitoring polling and RADIUS events
  • Alternatively connectable: PacketFence
What is COD-NAC?

A COD-native, vendor-independent solution for Network Access Control based on RADIUS. It controls and logs network access centrally in the COD.

Do I have to replace my switch hardware?

Usually not. COD-NAC is multi-vendor capable and works with existing 802.1X- or MAC-capable infrastructure.

Which authentication methods are supported?

802.1X (EAP, with certificates) as well as MAC authentication.

How are devices assigned to a VLAN?

Dynamically via RADIUS attributes. Client groups with priorities let you bundle rules, and non-compliant devices can be placed in a quarantine VLAN.

Can I import devices in large numbers?

Yes. The CSV bulk import handles MAC addresses, VLAN assignments, and groups, including validation and conflict detection.

Where do I get certificates for 802.1X?

From the integrated PKI: creation of CA and leaf certificates, CRL management, and PKCS#12 export for distribution to clients.

Can I keep using an existing Windows CA?

Yes. As an alternative to the integrated PKI, an existing Windows CA environment can be connected. COD reads out the existing certificates in read-only mode and manages them centrally.

Can I keep using PacketFence?

Yes. PacketFence can be connected as an alternative, and existing policies are preserved.

How do I see who was connected and when?

Through authentication and accounting logs (real time and history) as well as per-client connection statistics.

Captive Portal

Does IT have to create every guest access?

No. Thanks to role-based delegation, reception or non-technical staff can handle guest management themselves, without admin rights and without an IT ticket.

What happens to expired access?

It is automatically disabled and removed. Forgotten legacy accounts and permanently valid passwords are a thing of the past.

How secure are the credentials?

They are generated server-side according to current standards, with WPA2/3 and complexity requirements, optionally as one-time passwords. No one copies a password off a whiteboard anymore.

TACACS+ (Device Administration)

Technical Profile
  • Type: TACACS+ AAA server for administering network devices (authentication + authorization)
  • Protocol: TACACS+ (port 49), RFC 8907; for switches, routers, firewalls, access servers
  • Authorization: PERMIT/DENY rules, pattern-based command authorization, privilege levels 1–15
  • RBAC: roles link user group ↔ device group ↔ authorization rule (different permissions per device)
  • Crypto: Argon2id (passwords), AES-256-GCM (sensitive fields)
  • Management: REST API, separate from the server daemon
  • Operation: PostgreSQL, Python
Which devices are supported?

Any TACACS+ client per RFC 8907 — such as switches, routers, and firewalls. The solution is not vendor-specific.

Can a user have different permissions on different devices?

Yes. Through roles (user group × device group × rule), permissions can be assigned granularly per device group.

Can I restrict individual commands?

Yes. Command authorization works on a pattern basis.

How are passwords stored?

As an Argon2id hash — not reversible.

What is the management API for?

For managing users, clients, groups, and rules — separate from the actual server daemon.

Which privilege levels are there?

Levels 1 to 15, configurable per user.

How do I disable a rule or a user?

Via an enabled flag. Disabled entries are skipped during evaluation.

Switch Automation

Technical Profile
  • Type: Automated switch configuration via Ansible
  • Vendors: Allied Telesis (AWPlus), Cisco IOS, Ruijie (CLI fallback) — extensible
  • Profiles: PORT (interface), AUTH (802.1X/AAA), VLAN (create/delete), PORT_ACTION (cable test, port restart)
  • Security: credentials encrypted in the vault; automatic config backup before every change, selective restore
  • Transport: SSH (libssh/paramiko), legacy algorithms for older devices
  • Execution: asynchronous with task/result logging, tied into the COD audit
Which switch vendors are supported?

Allied Telesis, Cisco IOS, and Ruijie (via CLI fallback). Additional vendors can be added.

Do I have to enter credentials for every change?

No. After the initial rollout, credentials are stored encrypted in the vault and reused.

What happens before a configuration change?

A backup of the current configuration is created automatically. A restore to an earlier state is possible.

Can I roll out VLANs and ports centrally?

Yes, via profiles (PORT, AUTH, VLAN) directly from the COD.

Do older switches with old SSH algorithms work too?

Yes. Legacy algorithms (host key, key exchange, cipher) are supported, and paramiko is used when needed.

Does a port restart mean a device restart?

No. Only the individual interface is reset (shutdown/no shutdown), and the device stays in operation.

Can I change the same switch from multiple sources at once?

There is no lock. Requests are processed sequentially, and parallel manual CLI changes should be avoided in the meantime.

Security & Identity


Vulnerabilities (VAS)

Does VAS replace my existing vulnerability scanner?

VAS brings scans, severity distribution, remediation status, and trends into a shared, multi-tenant context on COD's live asset base — so findings become prioritized and trackable instead of just appearing as a list.

What does "risk-based prioritization" mean in practice?

Findings are broken down by severity and presented so you immediately see where urgent action is needed — you work on the risk, not on the length of the list.

Does the module run on-premises?

Yes. The vulnerability module is part of the modular COD platform, multi-tenant capable and fully operable on-premises — KRITIS-ready, with full data control.

OTP Authentication

Technical Profile
  • Type: COD-native, central OTP management
  • Standard: TOTP (RFC 6238), SHA-1/256/512, 6–8 digits, 30-second interval
  • Provisioning: QR code or manual entry; compatible with common authenticator apps (Google, Microsoft, Authy)
  • Sharing: private (user-bound) or public tokens; group delegation for teams
  • Recovery: six one-time backup codes per user
  • Isolation: site-specific (separated per tenant)
  • Integration: multi-factor sign-in and password reset in the COD
What does the OTP module do?

It manages time-based one-time passwords (TOTP) centrally — for multi-factor authentication, without credentials having to be shared among users.

Does it work with Google Authenticator and the like?

Yes. It generates standard otpauth:// codes and works with any RFC 6238-compatible app.

Can teams share tokens?

Yes. Tokens can be shared across a team via groups, while private tokens remain bound to individual users.

What if a user loses their smartphone?

Six one-time backup codes per user are available for sign-in.

Who sees which tokens?

Private tokens only the respective owner. Public or group tokens are visible to the members of the group as well as administrators.

Are tokens separated per site?

Yes. All tokens and groups are isolated per site.

How is access secured?

Through the COD's role-based access control and site isolation. Storage is in the secured database.

What is OTP used for within the COD?

For multi-factor sign-in and securing the password reset.

codPass

Can I use codPass in production today?

Yes. codPass can be run standalone and operates fully independently as a dedicated password and secrets manager. Native COD integration is in preparation.

Is there a browser plugin for codPass?

No. codPass currently does not offer browser plugins. Managing passwords, secrets, and OTP happens directly in the application.

Why open source for a password manager?

Because openness builds trust: the source code and the security mechanisms are transparent and verifiable. For a secrets manager, that is a security and quality feature, not an afterthought.

Stronghold – Password Vault (coming soon)

Status

Coming soon. Stronghold is in final development.

Technical Profile
  • Type: Zero-knowledge vault for passwords and secrets (end-to-end encrypted)
  • Principle: The server stores only ciphertext. Plaintext, the master password, and private keys never reside on the server.
  • Vaults: one personal vault per user, plus shared team vaults (roles: OWNER/MEMBER)
  • Sharing: individual entries across users, with READ/WRITE permission and expiration date
  • Recovery: one-time recovery code at setup
  • Crypto: Argon2id (key derivation), X25519 sealed box (key wrapping), AES-GCM (entries), HKDF
  • Sign-in: JWT (ES384) via the COD login, verified through JWKS
  • Operation: PostgreSQL; reachable only through the COD proxy; rate limiting; tamper-proof audit log (HMAC chain)
Can extocode or administrators view my passwords?

No. The server holds only encrypted data. Without your master password — which exists only on the client side — that data is worthless even in a full database dump.

What happens if I forget my master password?

At setup you receive a one-time recovery code. It lets you restore access to your key and set a new master password.

Can I share passwords with colleagues?

Yes — either through a shared vault or by sharing individual entries (with permission and expiration date). Both are public-key encrypted.

What happens when I revoke a member's access?

The vault key is reissued for the remaining members, and the removed member loses access to future content.

Is a vault's name visible?

No. The vault name is encrypted, and only the icon is stored in plaintext.

Does the recovery code also protect against data loss?

The recovery code restores access to your key (e.g., after a forgotten master password). The COD's regular backup protects against server-side data loss.

How does sign-in work?

Through the COD login (JWT, ES384; verified via JWKS). The vault is reachable exclusively through the COD proxy.

Operations & Resilience


Backup & Disaster Recovery

Technical Profile
  • Type: COD-native, vendor-independent backup solution
  • Target systems: all devices reachable via SSH (switches, firewalls, servers) as well as MariaDB/MySQL databases
  • Methods: SSH command, SFTP file/folder, MariaDB dump
  • Scheduling: cron per host or template
  • Encryption: optional AES-256-CBC per host/template
  • Retention: by count or age (days), automatic cleanup
  • Comparison: diff view of two backup states
  • Storage: local, optional mirroring to an SCP server
  • More: jump host/bastion, pre-backup scripts, email alerts, disk-space monitoring, serial number check
What does COD-Backup back up?

Configurations of all devices reachable via SSH as well as MariaDB/MySQL databases. The solution is vendor-independent and extensible via OS templates.

How often can backups run?

Freely configurable via cron — per host or per template, e.g., hourly, daily, or weekly.

Are the backups encrypted?

Optionally. AES-256-CBC can be enabled per host or template.

How long are backups retained?

Configurable by count or age in days. Once the limit is reached, the oldest states are deleted automatically.

Can I compare two backup states?

Yes. A diff view shows the changes between two versions line by line.

What happens if a backup fails?

You receive an email alert with error details, and the host is flagged with ERROR status.

Can I mirror backups to an external system?

Yes. Optionally, backups are mirrored to an SCP server, including retention rules.

Does COD-Backup also reach devices behind a bastion host?

Yes, through a jump-host tunnel.

How do I restore a backup?

Backups can be downloaded through the interface. Restoring to the device is done manually with the usual tools.

Hypervisor Management (virtual switches)

Technical Profile
  • Type: Management of virtual switches (no VM or host management)
  • Platform: VMware vCenter / ESXi
  • Objects: vSwitches, port groups, VLAN IDs (0–4094), NIC teaming, security policies
  • Functions: read inventory (datacenter → cluster → host → vSwitch → port group), create vSwitch, create/modify/delete port group
  • Dry run: test changes in advance without risk
  • Multi-host: operations across multiple hosts, result per host
  • Interface: REST API, sign-in via vCenter account
What does this module manage?

Virtual switches and port groups on VMware. It deliberately does not control the lifecycle of VMs or hosts.

Which hypervisors are supported?

VMware vCenter and ESXi (via the VMware API pyVmomi). Other platforms such as Hyper-V or KVM are not supported.

Is VLAN tagging supported?

Yes. Each port group is assigned a VLAN ID (0–4094).

Can I test changes in advance?

Yes. All modifying calls support a dry-run mode that simulates changes without making them.

Is NIC teaming supported?

Yes. Active/standby/unused NICs as well as load balancing can be read and configured.

How do I sign in?

With vCenter credentials (host, user, password) in each call.

Can I change multiple hosts at once?

Yes. Operations accept a host list, and the result reports success or failure per host.

What is the inventory for?

It provides the complete vCenter object tree as read access — for example, for dashboard views or documentation.

Folgen Sie uns
​
  • COD Overview
  • Features
  • Pricing
  • Integrations
  • NIS2
  • codPass
  • References
  • Downloads
  • FAQ
  • Contact

Kotzinger Straße 21 • 83278 Traunstein • Deutschland

  • ​+49 (861) 88 00 32 00
  • ​info@extoco.de
Datenschutz Impressum ​
Copyright © extocode GmbH
English (US) Français Deutsch Español Türkçe

We use cookies to provide you a better user experience on this website. Privacy Policy

Decline Accept