SubnetSlinger - Peacemaker revolver

Welcome to SubnetSlinger

Network Cowboys

The modern network engineer's toolkit, now on Linux. New here? This page walks you through it, step by step. (Prefer plain text? The complete reference is in README.txt.)

Get runningInstall - about a minute

SubnetSlinger doesn't need a system-wide install - you run it right out of the folder you downloaded. Here's the whole thing:

1
Extract the download and open a terminal there
Right-click the .tar.gz and choose Extract (or use the command below). Then open the new folder and, in most file managers, right-click an empty spot and choose Open Terminal Here - or just open your terminal app and cd into the extracted folder.
tar -xzf subnetslinger-1.2.0.0-linux-x64.tar.gz cd subnetslinger-linux-x64copy
2
Launch it
A window opens with the toolkit. If Linux asks about local network access, allow it (needed for Ping, Discovery, etc.). The free tools work right away - no account, no internet, nothing to configure.
chmod +x SubnetSlinger.App ./SubnetSlinger.Appcopy
The chmod just marks it runnable (some extract tools drop that bit). It bundles its own runtime, so there's no .NET or framework to install first. To keep it around, move the folder anywhere you like (e.g. ~/Applications) - it runs from wherever it lives.
3
Add it to your apps menu (optional)
Run this from the folder's final location (if you move the folder later, run it again). Step 4 below also installs the menu icon system-wide, so if you're enabling Capture you can skip this.
mkdir -p ~/.local/share/applications ~/.local/share/icons/hicolor/512x512/apps cp io.subnetslinger.SubnetSlinger.png ~/.local/share/icons/hicolor/512x512/apps/ sed "s|^Exec=.*|Exec=$PWD/SubnetSlinger.App|" io.subnetslinger.SubnetSlinger.desktop > ~/.local/share/applications/io.subnetslinger.SubnetSlinger.desktopcopy
4
Enable live packet Capture (optional, one time)
Only if you'll use the Capture tool. This grants the tiny helper - never the app itself - capture permission (the Wireshark model).
chmod +x install-linux.sh sudo ./install-linux.shcopy
Everything else just works. Ping, traceroute, the local test servers, discovery, and the rest need no setup and no grant. Serial console? Add your user to the dialout group (then log out/in) to open /dev/ttyUSB*.

What you getWhat's in the box

Nearly 50 network tools in one app. A quick tour by what you'd reach for:

Diagnose & measure

Ping, Traceroute, Path ping/map, Port scanner, DNS, Speed test, WHOIS, SSL/TLS & HTTP inspectors

Discover & map

LAN Discovery, ARP table, MAC/OUI lookup, L2 neighbors (LLDP), Topology, SNMP, Wi-Fi scan

Connect & configure

SSH terminal, Serial console, SFTP, Multi-host, Config Builder, Provisioning, Drift detection, Inventory

Serve & capture

Local test servers (Syslog, TFTP, DHCP, DNS, RADIUS, TACACS+, SNMP trap) and live Packet Capture

Secure & assist

Vault for credentials, the Deputy AI + Posse multi-agent, and an MCP client for your own tools

Free forever - 9 tools

Ping, Traceroute, Path ping, Port scanner, DNS, Subnet calculator, ARP, MAC/OUI, Discovery. The rest unlock with the trial or Pro.

PrivacyWhat stays on your machine, what leaves it

Short answer: everything stays, unless you turn something on.

Stays local, always

  • Every tool result
  • Vault credentials (encrypted at rest)
  • Metrics history, incidents, inventory
  • Deputy AI chats when using local Ollama
  • Anything you Save / Export to disk

Leaves only when you turn it on

  • Cloud AI providers (opt-in, needs your key)
  • Account sign-in - an email code to unlock Pro
  • License purchase - Stripe in your browser
  • Internet tools you invoke (speed test, WHOIS, public IP)
YOUR MACHINE ONLY WHEN YOU OPT IN Stays local, always No telemetry. Free tier needs no account. Every tool result Vault credentials (encrypted) Metrics, incidents, inventory Local AI chats (Ollama) Anything you save to disk Cloud AI needs your own API key OPT-IN Account sign-in a code sent to your email OPT-IN Buy Pro Stripe, in your browser OPT-IN Each door opens only when you turn it on. Off by default.
Known secret shapes (device passwords, SNMP/TACACS+/RADIUS keys, API tokens) are masked before anything is sent to a model - cloud or local. A strong safety net, not an absolute guarantee.

SpecsWill it run well on my machine?

The app is light. The only thing that wants a bigger machine is running the AI locally (Ollama) - and that depends on where the model runs, not just whether you use AI.

How you run the AIYour machine needs
No AIMinimum
Cloud AI (your key)Minimum + internet
A model on your own serverMinimum + reach it
Local Ollama (this box)32 GB RAM + a GPU
 MinimumRecommended
CPU64-bit dual-corequad-core or better
RAM8 GB16 GB (32 GB for local AI)
Disk~500 MB freeSSD, 2 GB+ (plus 5-10 GB per local model)
GPUnone (integrated OK)local AI: 8 GB+ VRAM
Display1280x800 or largersame

Cloud AI, or any model you host on another box, keep this machine at the minimum. Only running the model on this box raises the spec. Full details are in README.txt.

Install helpersAdd-ons - only for the feature you use

SubnetSlinger doesn't bundle these. It builds the command and runs the one you have installed - and tells you at runtime if one isn't there. Click a row for the exact install command. Commands show apt; on Fedora use dnf, on Arch pacman.

Live packet Capture libpcap

Need it if: you'll use the Capture tool to record and inspect live network traffic.

The Capture tool wraps libpcap (usually already installed). If it's missing:

sudo apt install libpcap0.8copy

Then grant capture once with sudo ./install-linux.sh (step 4 above).

Command-line tools you drive (nmap, dig, mtr, tcpdump) CLI wrappers

Need it if: you'll drive nmap scans, dig lookups, mtr, or tcpdump from the CLI Wrappers tool.

Install only the ones you'll use:

sudo apt install nmap curl bind9-dnsutils mtr tcpdumpcopy
SFTP / SCP receive (Local Servers) openssh-server

Need it if: you want devices (or people) to send files TO your workstation over SSH.

Lets devices push files to your workstation over SSH (TCP 22):

sudo apt install openssh-server sudo systemctl enable --now sshcopy
Local AI - private and free (Ollama) local-only

Need it if: you want AI with no cloud key and no cost - the private, local option.

How it works: Ollama is a small, free program that runs AI models locally - your own private AI on your machine, no key and no cost.

1. Install Ollama once (ollama.com).   2. Download a model or two into it (commands below).   3. In SubnetSlinger, set AI = Ollama and pick which of your models to use. The app simply talks to Ollama on your machine - nothing leaves it.

Step 1 - install Ollama. The official one-line installer from ollama.com (or grab the package there):

# installs Ollama and starts it locally on port 11434 curl -fsSL https://ollama.com/install.sh | shcopy

Step 2 - pull a model. It must be tool-capable - the Deputy drives tools, so the model needs function calling (not all do). Bigger models answer better but need more RAM/GPU (see specs). Reliable picks, start with the first:

ollama pull llama3.1 ollama pull qwen2.5 ollama pull mistralcopy

See what you've pulled (or browse the catalog at ollama.com/library):

ollama listcopy
In the app
Deputy > Settings > AI = Ollama > hit refresh to list the models you've pulled, then pick one
Needs
32 GB+ RAM and a GPU for a good experience (see specs above)
Share it
Point the Deputy at one Ollama server on your LAN and every workstation stays at minimum spec
Connect the AI to your own tool servers (MCP) Node / uv

Need it if: you'll connect the Deputy AI to your own external tool servers (MCP).

Install the toolchain your MCP servers need:

sudo apt install nodejs npm curl -LsSf https://astral.sh/uv/install.sh | shcopy

MCP servers run as local child processes over stdio - no inbound ports.

Lab throughput testing (iperf3) iperf3

Need it if: you'll measure throughput/bandwidth between two machines (Lab Testing).

Needed on both ends of a Lab Testing throughput run:

sudo apt install iperf3copy

Third-party servicesAI providers & sign-in - all opt-in

Nothing here runs until you turn it on. Each row shows what it does, what it sees, and what it needs.

Do I have to download a model? For cloud AI (Claude, OpenAI-compatible, Gemini) - no. The models run on the provider's servers; you add a key, pick a model, and the app's model list stays current on its own. For local Ollama - yes: you pull each model yourself (ollama pull, 4-10 GB for a typical one), and it must support tool/function calling.

How cloud AI works: the model runs on the provider's servers (Anthropic, OpenAI, or Google) - not your machine. You paste your own API key once; then when you ask the Deputy a question, it sends your prompt plus the relevant tool output - scrubbed of secrets by the local redactor first - to that provider and shows you the answer. Nothing to download, and the model list stays current on its own. You pay the provider directly for what you use (usually pennies); we take no cut, and never see your key or your data.

The three cloud providers below work the same way - they differ only in where you get the key and the endpoint the app calls:

Anthropic (Claude) opt-in
Does
Deputy AI provider - answers questions about tool output, can call safe read-only tools
Sees
Your prompts + tool output, after the local redactor strips secrets and tokens
Where
api.anthropic.com
Needs
Your own key from console.anthropic.com (stored locally)
OpenAI-compatible endpoint opt-in
Does
Deputy AI provider - any endpoint that speaks the OpenAI Chat Completions API
Where
Whatever URL you paste - Azure OpenAI, Databricks, self-hosted vLLM/LM Studio, Groq, OpenRouter
Needs
Endpoint URL + API key from your provider
Google Gemini opt-in
Does
Deputy AI provider
Where
generativelanguage.googleapis.com
Needs
Your own key from ai.google.dev
Ollama (local) local-only
Does
Deputy AI provider running entirely on your machine - no key, no cloud round-trip
Where
localhost:11434 (or a server you point it at)
Needs
Ollama installed (see the add-on above)
Account sign-in opt-in
Does
Unlocks your paid license - sends a six-digit code to your email
Sees
Your email address; verifies the code you type back
Runs when
You tap Sign in on the Account screen
License purchase (Stripe) opt-in
Does
Payment for the Pro license
Sees
Your name + card details - Stripe handles the card, we never see it
Where
checkout.stripe.com, in your default browser (not embedded)

First time with AI?How to get a cloud API key

You only need a key if you want cloud AI. The free tier and local Ollama need none. Getting a key is the same idea for every provider:

1
Sign up / log in at the provider's console
See the links below.
2
Add a payment method
Cloud AI is pay-as-you-go, billed by the provider - not by us. Usage is usually pennies.
3
Create a new API key
Look for "API keys" then "Create key". Copy it right away - most consoles show it only once.
4
Paste it in and pick a model
Deputy > Settings > choose the provider > paste the key > pick a model from the list. The list shows the current models and their per-message cost, and refreshes on its own. Your key is stored locally.
ProviderWhere to create a key
Anthropic (Claude)console.anthropic.com > API Keys
Google Geminiai.google.dev > Get API key
OpenAI-compatibleyour provider's console (platform.openai.com, Azure OpenAI, Databricks, Groq, OpenRouter, ...)

What does cloud AI cost?

You're billed per token by the provider - input (everything sent) plus output (the reply) - with no markup from us. Example list rates for the default Claude models (per 1,000,000 tokens; rates change, so the app pulls the current ones from subnetslinger.com/models.json). OpenAI and Gemini have their own rates.

ModelInputOutputGood for
Haiku 4.5 (default)~$1~$5quick lookups, most questions
Sonnet 4.6~$3~$15multi-step investigations
Opus 4.8~$5~$25the hardest problems

A typical short question is a few thousand tokens - fractions of a cent on Haiku (the default). The app shows the running cost live as it works, and local Ollama is always free.

Keep spend in check: the Deputy has per-chat, per-day, and per-run caps built in (on by default) - and the strongest ceiling is a hard spend limit on your key at the provider (Anthropic/OpenAI/Google account settings). Set that once and nothing can spend past it.

Supply-chain integrityVerify this download is genuine

Every Linux release is signed with an offline GPG key - a full compromise of our website still could not forge a build. The files that ship next to the tarball: the detached signature, SHA-256/512 checksums, the public key, and a CycloneDX Software Bill of Materials (SBOM) - all covered by the signature.

# import the public key, then verify the signature + checksums gpg --import subnetslinger-signing-key.asc gpg --verify subnetslinger-1.2.0.0-linux-x64.tar.gz.asc subnetslinger-1.2.0.0-linux-x64.tar.gz gpg --verify SHA256SUMS.asc SHA256SUMS sha256sum -c SHA256SUMScopy

Expect Good signature, the fingerprint below, and OK on the checksums.

Fingerprint  6285 1F0E BBD5 AA9D 6E3C E11A 9433 D73B DB83 622C

Cross-check that fingerprint against subnetslinger.com/download - a tampered page cannot match both.

ReferenceNetwork ports - the built-in test servers

These listen only when you use the Local Servers tool, on the standard service ports so real gear can point at your workstation. On Linux, a refused low-port (below 1024) bind falls back to a high port automatically - no grant needed.

ServiceProto / PortServiceProto / Port
SyslogUDP 514RADIUSUDP 1812-1813
SNMP trapUDP 162TACACS+TCP 49
TFTPUDP 69FTPTCP 21
DNSUDP 53HTTPTCP 80
DHCPUDP 67SFTP/SCPTCP 22

Trial & licensingFree, trial, and Pro

Free tier - 9 tools, forever, no account, no internet required.

Free trial - 30 days of full Pro, no card. One trial per email. Start it in-app: Account > Start trial.

Pro - $499 USD, one-time, via Stripe. Unlocks every desktop OS (Windows, macOS, Linux) for v1.x. No subscription; every dot-release inside v1 is free.

Mobile - free forever on iPhone, iPad, and Android. Companion apps, no gate.

ReferenceWhere your data lives

PathContents
~/.config/SubnetSlingersettings & state
~/Documents/SubnetSlingerserver folders (tftp/http/ftp/dns/radius/tacacs/scp), exports, captures, logs