Device Management
Overview
Section titled “Overview”The Devices page is your control center for everything you have deployed. It is where you check whether a device is healthy and online, grab credentials, adjust request details, and jump into ARROW Manager to do hands-on work like deploying VMs. If a device goes quiet mid-engagement, this is the first place you look.
Device Lifecycle
Section titled “Device Lifecycle”A device moves from a request you submitted, through provisioning and shipping, to on-site and operational, and finally back to the warehouse when your engagement ends. The status on each device tells you exactly where it sits in that journey.
Device lifecycle from request to return
| Status | What it means | What you can do |
|---|---|---|
pending | Request awaiting approval | View details, edit the request |
provisioning | Device being prepared | Monitor progress |
shipping | Device ready for pickup | View tracking info |
in-transit | Device with the carrier | Track the shipment |
on-site | Delivered and operational | Full device management |
returned | Back at the warehouse | View archived details |
Viewing Your Devices
Section titled “Viewing Your Devices”Once a device is provisioned it shows up on the Devices page as a card, with a total count under the page title. Use the toggle in the page header to switch between the card view and a compact list view, which is handy when you are managing a lot of devices at once. In list view a settings icon appears beside the toggle with a Show Columns menu, so you can hide the columns you do not need. List view also puts a checkbox on every row: tick a few and a toolbar appears above the table with Add Tags, which labels all of them in one go. The refresh icon at the end of the row pulls live status.
- 1 Filter by status, type, or client to find a device fast when you have a lot of them.
- 2 A physical device card showing client, hostname, NetBird IP, and a shortcut into ARROW Manager on the device.
- 3 A virtual machine card showing how long it has been offline, the hostname, and, once the image is built, Download and Copy URL to grab it.
When the list gets long, the collapsible filter rail between the sidebar and the cards narrows it down without leaving the page. You can search by device name, client, or serial number, and filter by Status (All Devices, Online, Offline, Maintenance, Returned, Decommissioned, Completed (Historical), Overdue Returns, and Offline & Overdue), by Type (All Types, ARROW Device, or Virtual Machine), and by Opportunities, Consultants, or Tags. A Show completed toggle at the bottom pulls finished engagements back into view, and Clear all filters appears under it once you have narrowed anything. The Status and Type filters show a count next to each option so you can see the shape of your fleet at a glance.
Two banners sit above the cards when something has run past its date. The first counts the virtual machines past their end date. Mark them complete to remove VPN access and clean up downloaded files, or extend the date if you are still using them, because a VM left online is a security risk. The second counts physical devices that are still reachable on the VPN after their return date, which means either the engagement ran long and the end date needs updating, or the device was forgotten and needs to come back. Review on either banner narrows the page to just those devices, and Show all devices brings the rest back.
Reading a Device Card
Section titled “Reading a Device Card”Physical Device Cards
Section titled “Physical Device Cards”A physical device card leads with the client logo, the hostname, and a row of status icons, then gives you the facts you check most often:
| Field | What it tells you |
|---|---|
| Client | The client organization for this engagement |
| Location | Physical or IP-based location (shows “Locating…” while it resolves) |
| Hostname | The device hostname |
| NetBird IP | The VPN IP you use to reach the device remotely |
| Engagement | The engagement state derived from your request dates, such as Pending, Active, or Completed |
Below the facts, an ARROW Manager button (labeled with the on-device Manager version) launches the local dashboard. The opportunity number and assigned consultants sit underneath as tags, and Show Details expands the card in place to reveal the rest without leaving the page.
Show Details expands a device card in place for the fuller picture
The status icons in the top-right corner are the fastest way to spot trouble without opening anything:
| Icon | Status | What it means |
|---|---|---|
| Heartbeat | Health Monitor | Device metrics health, updated every minute on Ethernet and every five minutes on cellular |
| Ethernet Port | Primary Adapter | Connected via Ethernet, the primary connection |
| Signal Bars | Failover Adapter | Running on cellular failover |
| Shield Check | VPN Status | The VPN connection is stable |
| Cube | VM Status | A virtual machine is deployed and healthy |
A device that has failed over to cellular reports every five minutes rather than every minute, to keep off your data allowance, and ARROW gives it a correspondingly wider window before it counts as offline. A device on failover therefore stays online between reports rather than flicking offline and back while nothing is wrong.
When a device has fallen back to Nullpath, that same row also carries a Nullpath badge naming the path the device is using, or reading Recovery access when it has not reported a current one, and prefixed with Last reported when the reading is not current. The badge shows up the same way on the row in list view and at the top of the device details panel. See Access Path and Nullpath Usage for what it means and what it costs you.
Virtual Machine Cards
Section titled “Virtual Machine Cards”VMs get their own cards. Alongside the client, location, hostname, and NetBird IP, a VM card adds a VM Image row with Download and Copy URL buttons for the image, a Built date showing when the image was created, the Engagement state, and an ARROW Control button (labeled with its version) that opens the on-device control interface.
ARROW also emails you when a build finishes. Download your VM in that message opens a download page in ARROW Console rather than pointing straight at the image. You sign in, ARROW confirms the VM belongs to your organization, and the transfer starts, with the file name, the virtual machine it was built for, its size, when the link expires, and a SHA-256 checksum listed on the page. Copy the checksum and compare it against the file you received, since that is the only way to tell a truncated multi-gigabyte transfer from a good one. The emailed link grants nothing on its own, so forwarding it hands nobody your appliance, and you can reopen it whenever you need the image again. Each download link it creates lasts 7 days; come back to the page for a fresh one rather than reusing an old link.
Browsing Available Images
Section titled “Browsing Available Images”Before you request or deploy anything, it helps to know what your images actually contain. The Images section lists the operating system images your organization can deploy and the security tooling baked into each one, showing the base OS, version, visibility (public or private), and a tool count.
The Images page listing an available image with its OS, version, visibility, and installed tool count
Use the filter rail to narrow images by status, operating system, and visibility. Open an image to see the full list of installed tools in its App Library, so you can confirm a build has what your engagement needs before you commit to it.
Device Actions
Section titled “Device Actions”The […] menu on any device card is where the per-device actions live:
Opening the actions menu on a device card
| Action | What it does |
|---|---|
| View Details | Opens full device details with metrics, network info, and history |
| Access ARROW Manager | Launches the ARROW Manager dashboard for this device (on a VM running ARROW Control, the item reads Access ARROW Control) |
| Edit Tags | Adds or removes organizational tags |
| Edit Request Details | Updates dates, consultants, or notes |
| Copy ARROW Password | Copies the ARROW Manager login password |
| Copy Root Password | Copies the device root credential |
| Request VPN Setup Token | Generates a one-time token for VPN enrollment |
On a virtual machine card, the menu also offers Mark as Completed, which confirms the VM is no longer in use and cleans up its access, and an option to extend the end date when the VM has run past its scheduled return.
The two password actions copy the credential straight to your clipboard with no confirmation dialog, so treat them carefully. Use the value right away and avoid leaving it in plaintext.
Edit Tags opens a small dialog for labeling a device. Type a tag name, pick a color (or set a custom hex value), and click Add. Tags are your own organizational labels, so use them however helps your team, for example marking a device by project, site, or owner. Save when you are done.
The Edit Device Tags dialog, where you add colored tags to organize a device
VPN setup tokens come up when you deploy VMs. To get one, open the […] menu, choose Request VPN Setup Token, and copy the value to use during VM deployment in ARROW Manager. Tokens are single-use and expire after 7 days.
The VPN Setup Token Generated dialog, with the copyable token and the NetBird command to enroll the device
The dialog also spells out the enrollment steps. Install NetBird on the device, run netbird up --setup-key <token>, and the device connects to your VPN automatically. Copy the token with the button next to it, since it is shown only once.
Device Details View
Section titled “Device Details View”View Details opens the full panel, organized into tabs. The Overview tab leads with live CPU, memory, disk, and temperature readings, then the virtual machines running on the device, its location on a map, and the client and contact details. On a physical device with a cellular modem it also carries an LTE Data Usage card showing how much cellular data this engagement has used, with a bar against its allowance and a badge once that allowance is passed.
The device details panel, open on the Overview tab, with metrics, location, and contact
The Metrics and Network tabs go deeper into resource history and connectivity, covering interface status for Ethernet, cellular, and WiFi, VPN connection details, IP addresses and routing, and VM network configuration. The Software tab lists the software versions on the device, comparing installed against latest with an Update Available badge when a newer version exists, and on physical devices adds a Security Updates card for operating system patch status. The Details tab holds the original request information, hardware specifications, serial number and model, and credential access.
The Details tab, with the original request, hardware specifications, and credentials
Access Path and Nullpath Usage
Section titled “Access Path and Nullpath Usage”When the network at a site blocks the VPN outright, a device can fall back to Nullpath, which carries its traffic over a content delivery network, or over a direct path when one is reachable, so you keep remote access. The Network tab reports which path the device is on, between the interface list and the VPN connection details.
The card leads with the current state: Nullpath selected as the fallback, Nullpath on standby while the device uses its normal path, or the path unreported when the device has not sent one. When Nullpath is selected it names the path the device prefers for new connections, either REALITY direct or a delivery network with the protocol in use, and tells you that existing connections may be on another healthy path. If the device has not reported a preferred path, the card says so. If the device has not checked in for a couple of minutes, the card marks the reading as last reported and tells you the current route is unknown, so read it as history rather than as proof the VPN is up.
Below that it accounts for what Nullpath has moved: the recorded total for the current month with its upload and download split, the recorded lifetime total, a breakdown across the CloudFront, Cloudflare, and Azure delivery networks and the direct REALITY path, and the time of the last bandwidth sample. Those figures are payload estimates that include reverse access and standby traffic, and transport overhead sits on top of them. Measurement only starts once a device reports, so a device that has not reported yet says so instead of showing a zero, and usage from before then cannot be reconstructed. Once a month’s total reaches the usage threshold the card names the figure it hit, which is a prompt to go looking for large transfers rather than a cut-off. Recovery access keeps working either way.
ARROW also keeps a central record of what each device saw each time it worked out how to get online. It is held in ARROW Console rather than read off the device, so it is still there when the device is unreachable, which is usually when you want it. That record is not shown in your console, and it covers the last 30 days, so if a device keeps losing its path, contact support while the evidence is still there.
VPN Access Control
Section titled “VPN Access Control”By default anyone on your organization’s VPN can reach any device on it. The VPN access control section on the Overview tab narrows that to the people assigned to the device’s request, which is what you want when a device sits inside a client network and only the consultants on that engagement should be able to touch it. The assignments are the same ones behind Network Access Control.
Who can reach this device shows the current state as a badge, and the dropdown under it sets the rule:
| Option | What it does |
|---|---|
| Follow organization default | Uses whatever your organization is set to, and keeps following it if that changes |
| Assigned users only | Removes this device from the organization-wide rule and grants access only to the users assigned to its request |
| Any VPN user | Leaves this device reachable by everyone on your VPN, whatever the organization default is |
The line below the dropdown tells you what the organization default currently is. Once a restriction is in force, the section also lists who has access, with a count and a Contractor badge next to anyone who is one. If that list is empty nobody can reach the device at all, and the section says so, so assign users on the device request to grant access.
A Not in force badge means the device is set to restrict access but nothing is enforcing it yet. The rule that lets every VPN user reach every device is removed for a whole organization rather than one device at a time, so the organization-wide setting has to be on first. Your choice is kept and takes effect the moment it is. Contact support if you want it turned on for your organization.
Changes here are recorded in your organization’s audit trail. If you do not see this section, your account does not have permission to manage VPN access for your organization.
Public Web Access
Section titled “Public Web Access”Normally you reach a device’s own interfaces over the VPN. If public web access is turned on for your organization, the Overview tab also carries a Public web access section that lets you publish one of those interfaces on the open internet instead, which is the way in when you are on a network where the VPN is not an option.
There is an Expose ARROW Manager switch on physical devices, and an Expose ARROW Control switch on virtual machines and on any physical device that has ARROW Control installed. A switch is greyed out when that application is not installed on the device. Organization admins can use these switches, and so can anyone assigned to the device’s request.
Turn one on and the section reports where it has got to: Provisioning, then Issuing certificate, then Active, at which point the public hostname appears with buttons to copy the URL or open it in a new tab. Sign-in still goes through your organization’s SSO before anything on the device answers, so publishing the address does not publish access to it. Turning the switch off stops the public URL working immediately, and both turning it on and turning it off are recorded in your organization’s audit trail.
If you do not see this section, public web access is not enabled for your organization. Contact support if you want it.
Working in ARROW Manager
Section titled “Working in ARROW Manager”ARROW Manager is the local management interface running on every physical ARROW device. It is where you set up encryption, deploy VMs, and configure networking on the device itself.
Signing In
Section titled “Signing In”Click the ARROW Manager button on a device card, or choose Access ARROW Manager from the […] menu. A new browser tab opens, connects to the device, and signs you in as your ARROW Console user, so there is no second password to type. Your ARROW Console permissions decide whether you can open a device at all, and if your organization restricts a device to assigned users, only those users and organization admins are signed in.
Two things send you to the device’s own sign-in page instead. One is a device you are not cleared to open, the other is a device whose software predates one-click sign-in. ARROW Console tells you when it falls back, and when the reason is out-of-date software the message names the version the device is running and the version to update to, which is ARROW Manager 1.0.43 or newer on a physical device and ARROW Control 1.0.8 or newer on a virtual machine. That page defaults to Sign in with ARROW SSO. To sign in directly on the device, choose Use local login instead and enter the manager credentials:
- Username: manager
- Password: the ARROW Password from the device card (via the action menu)
The ARROW Manager local login screen, where you enter the manager username and password
Getting a New Device Ready
Section titled “Getting a New Device Ready”Once you are in, four steps take a fresh device to ready-for-testing. Set the LUKS encryption key, deploy a virtual machine from your App Library, configure network settings (a static IP if the site needs one), and optionally attach USB devices such as wireless cards to your VMs.
Setting LUKS Encryption
Section titled “Setting LUKS Encryption”VMs live on an encrypted storage partition, so this comes first. In ARROW Manager, open the Proxmox tab. You will see an “Encrypted Storage Setup Required” message; click Setup Encryption, enter a strong key, and click Create Encrypted Storage. It takes 15 to 30 seconds.
Important Store your LUKS Encryption Key somewhere safe, following your organization’s policy. If the device loses power or reboots, you need this key to restart your virtual machines, and VTEM Labs cannot recover a lost one.
The Virtual Machines page shows an Encryption Setup Required banner before you can deploy
Enter a strong LUKS encryption key, then click Create Encrypted Storage
Deploying a Virtual Machine
Section titled “Deploying a Virtual Machine”With encryption in place, go to the App Library, pick the image you want, and click Deploy. The Configure VM Deployment window asks for:
| Field | Required | What it does |
|---|---|---|
| Root Password | Yes | Password for the VM root account |
| ARROW User Password | Yes | Password for the arrow user account |
| SSH Public Key | No | Enables passwordless SSH access |
| NetBird Device Name | No | VPN device name (defaults to pvm-[host-suffix]) |
| Enable ARROW Control | No | Installs ARROW Control on the VM, with an optional beta-version toggle |
| MAC Address | No | A pre-assigned MAC for NAC or DHCP reservation |
| Static IP Configuration | No | For networks that do not use DHCP |
You no longer enter a VPN setup key here. It is provisioned automatically and tied to your device request.
Click Create VM (roughly 50 seconds). The Virtual Machines page shows deployment progress, and the VM appears under Your Machines once it is running.
Network Configuration
Section titled “Network Configuration”Most of the time, DHCP is the right call. Use it when the client’s network hands out IPs automatically, you have no specific IP requirements, and outbound VPN connections are allowed.
Reach for a static IP when the client requires specific addresses for firewall rules, DHCP is not available, or network security expects pre-registered IPs. Even then, the cleanest option is to have the client assign a static IP via DHCP reservation. If you do need to set one manually, open Network Settings in ARROW Manager, select the Static IP radio button, and enter the IP address, subnet mask, gateway, and DNS servers. Save the changes; no reboot is required.
After a network change, the device tries to establish the VPN connection on its own. If the settings are wrong or network security blocks it, the device fails over to cellular or a WiFi hotspot rather than going dark.
Important Do not edit
/etc/network/interfacesby hand. Make every network change through ARROW Manager so the device stays in a known state.
Reviewing Metrics
Section titled “Reviewing Metrics”The Metrics section turns your activity into analytics you can actually use, like how long devices take to deploy and how long they stay on site. Service Metrics summarize your request volume, delivery timelines, and deployment durations, with a date range selector and a per-client filter at the top.
Service Metrics summarizing total requests, average time to deploy, average time on site, and trends over time
The summary cards report totals such as Total Requests, Avg / Month, the Hardware and VM request counts, Avg Time to Deploy (request to deployment), and Avg Time On Site (average deployment duration). Below them, the Requests Over Time and Deployment Duration Trend charts show how those numbers move month over month, and Request Status Breakdown counts the requests in the period by status.
Troubleshooting
Section titled “Troubleshooting”A device shows offline. This usually comes down to connectivity at the site, a firewall blocking the VPN, or the device being powered off. Check with your on-site contact about network status, confirm the required VPN ports are open (support can tell you which), and make sure the device has power.
You cannot reach ARROW Manager. Almost always this is the VPN or the credentials. Confirm the VPN status icon is green, use Copy ARROW Password to get the exact login, and refresh the page.
A VM will not deploy. The common culprits are LUKS encryption not being set up, an invalid VPN setup token, or not enough disk space. Complete LUKS setup first, generate a fresh VPN setup token, and check available space in the Proxmox tab.
Related Documentation
Section titled “Related Documentation”- Device Requests - Creating and managing device requests
- Device Shipments - Tracking shipments and delivery
- ARROW Manager Overview - Detailed ARROW Manager documentation
- USB Devices - Attaching USB devices to VMs
- VPN Management - VPN configuration and troubleshooting