Overview
Gateway health, quick actions and the current IRIS site state.
Quick actions
Operational controls only.
Current site state
- Gateway
- Stopped
- Coordinator
- -
- Local view
- -
- RELAY site
- -
- State file
- -
- SITE-SYNC
- Unknown
Operator summary
Plain-language interpretation of the current settings.
Recent events
Visual multi-site topology
Shows the local site, visible local nodes, the elected Site Master, remote sites, RELAY route health and the current SITE-SYNC state.
SITE-SYNC state
RELAY route health
Visible site summary
Data rate
Measured JGroups transport traffic for the local cluster and RELAY3 bridges, sampled independently from route-health checks (2 s default). Reconnect samples establish a fresh baseline and are not counted as traffic. Current, peak and time-weighted average are over the selected window. Not radio bearer capacity.
RELAY3 bridge counters
Cumulative JGroups transport counters per configured bridge since the runtime started.
Node identity
These values identify this Edge Gateway to other IRIS nodes.
WAN echelon
Host the echelon that remote IRIS devices join over the internet: this gateway runs the GossipRouter, coordinates the cluster and issues every device its credential.
On: this node's local network becomes a TUNNEL cluster through an embedded GossipRouter with TLS, device-certificate authentication and ASYM_ENCRYPT, coordinated by this gateway. Every certificate is generated at start. Off: the local network returns to UDP and the router is disabled; nothing else changes.
Derived from the router port and bind address, this node's bind address and its callsign. Open Advanced only to override a value; an override is kept until one of those changes.
Devices
Each device gets its own certificate, admitted in the truststore under its callsign. Add one, send the operator the .iriswan file by whatever channel you trust and read them the passphrase; it is shown once and not stored. Remove revokes: the device's connections are closed and its certificate stops being accepted immediately.
Advanced: router bind, timeouts, this gateway's own link and bring-your-own certificates
Router
This gateway's link
How this gateway itself joins the echelon as a TUNNEL member of its own router. Filled by the switch and re-derived on every change of the router port, a bind address or the callsign; an edit here stands until then. The fields below are the local stack's and return to the local network card when the switch is off.
Local tactical network (LAN)
Choose how this node joins its local IRIS cluster.
Transport TLS, ASYM_ENCRYPT & coordinator preference
Multicast, failure detection & flow control
Certificate security (SSL_KEY_EXCHANGE)
Compression (COMPRESS)
Local compression is off by default (500-byte threshold). When RELAY3 is enabled it is isolated below RELAY3, so cross-site traffic uses only the bridge compression policy. Local peers must use compatible COMPRESS settings.
Multi-site RELAY3 / SITE-SYNC
Create one or more independent relay bridges. Each bridge can use a different local network interface and bridge network.
Matches the current IRIS application baseline. Normal nodes can participate in RELAY3 while Site Master eligibility remains separately controlled.
Site-Master bridges
Each bridge owns an independent JGroups bridge stack. New bridges start with the same default values used by the IRIS application.
match-address:10.10.20.*,site_local,loopback, so the bridge stays associated with that subnet when the host address changes.
RELAY3 forwarding rules
Define hierarchical/asymmetric routes for destination sites that are not local and not directly connected. Each enabled rule maps a destination-site expression to a directly reachable gateway site.
to is a Java regular expression matched against the destination site name and gateway is the directly connected remote site that should receive the message next. Example: to=NET3, gateway=NET2. A catch-all route can use to=.*.
Guided JGroups profile
Select a deployment style for a more user-friendly way to configure the underlying JGroups profile.
Approved profile file
Plain-language profile summary
Engineering view: raw profile JSON
AI / External Tactical API
This is the controlled interface for an AI adapter or other external edge workload.
Allows one authorised adapter to subscribe to IRIS operational data and publish approved results.
AI Provider Adapter
Expose AI to the IRIS network without placing the model in the JGroups, RELAY3 or SITE-SYNC routing path.
The deployed IRIS ai.request/ai.response contract stays the same regardless of the selected AI environment.
OpenAI endpoint and credential settings
AI deployment environments
ai.request; the gateway hides provider-specific authentication and returns ai.response.Deployed IRIS AI Service
Allow authorised IRIS Desktop or Android clients to ask this gateway AI through the normal PluginEnvelope path.
ai.request messagesResponses are returned directly to the actual requesting IRIS user as ai.response; provider credentials never leave the gateway.
pluginId: com.neoplexus.iris.airequest: ai.request / com.neoplexus.iris.ai.request.v1tool: ai.tool_request ↔ ai.tool_response / v1response: ai.response / com.neoplexus.iris.ai.response.v1No AI request has been sent.
Gateway plugins
Add headless capability at this edge node without changing the IRIS Desktop or core Gateway. Plugins can ingest external feeds and publish authorised information into the IRIS network.
Web management
Controls how this browser interface is exposed. Changes take effect after restarting the Java application itself.
Gateway log files
The process log the service captures: JGroups (TUNNEL, GossipRouter, TLS handshakes), the embedded router and enrolment, and the gateway's own output. Tails the file from the end; the filter is a case-insensitive regular expression applied per line.
Live events
Gateway, JGroups, RELAY3, SITE-SYNC and management events.