Deployment Models

Deployment Models

Deployment

Deployment Models

Cloudmon supports several deployment models to suit different network environments. This article describes each model, how to choose between them.

Overview

Every Cloudmon deployment uses the following four components:

ComponentRole
Cloudmon ServerRuns the core Cloudmon application.
DatabaseStores monitoring data.
ProbesDiscover and collect data from devices on the network.
Web ConsoleBrowser interface used to view and manage Cloudmon.

The role of each component stays the same in every deployment model. Only their placement relative to your network changes.

Choosing a Deployment Model

The table below lists the available deployment models and where each one applies. Refer to the corresponding section under Deployment Models for details.

ModelTypical EnvironmentProbe Placement
SMB / Basic Internal NetworkSmall office / single LANSame network as Cloudmon Server
Centralized Probe DeploymentBranches connected by MPLS / SD-WAN / leased lineCentralized
DistributedIndependent branch networksOne or more probes per branch
DMZInternet-facing / security-segmented environmentsBased on security zones
MSPMultiple customer environmentsCustomer-site probes + centralized MSP
HA (High Availability)Business-critical environments requiring failoverActive DC + standby DR, with site probes unchanged
ℹ️Note: These models aren't mutually exclusive — for example, a Distributed deployment can also include a DMZ segment at one or more sites. If you're unsure which model fits, contact Cloudmon support for guidance.

Deployment Models

SMB / Basic Internal Network

This is the simplest Cloudmon deployment model, suited to small businesses or a single internal network with no branch or WAN complexity — everything runs on one flat local network.

The Cloudmon Server, database, and probes all run within this same local network. The Web Console connects directly to the Cloudmon Server, and a Linux Probe and a Windows Probe are deployed on the same network to discover and monitor local devices, including firewalls, routers, IP cameras, switches, VMware hosts, and agent-installed laptops and servers.


Centralized Probe Deployment

In this deployment model, branches are connected through an MPLS network, SD-WAN, or leased lines within a single logical network, as would be the case in a smaller organization with multiple sites.

The Cloudmon Server and database are installed either on-premises or in the cloud, with probes deployed in a centralized location such as the cloud, main data center, or a central office. These probes monitor and collect data from SNMP-enabled devices, WMI-based devices, and other network components located across the different branches.


Distributed — Different Networks

In this deployment model, each branch operates on its own independent network or in a different geographical region, as would be the case in a typical large organization with multiple sites.

The Cloudmon Server and database are installed either on-premises or in the cloud. Probes are deployed in each branch to collect performance and health data from local devices, then send the collected data back to the central Cloudmon Server for unified monitoring and analysis.


Demilitarized Zone (DMZ)

A DMZ is a network segment that separates an organization's internal network from external networks, such as the internet, acting as a buffer zone where external-facing services and systems are isolated from the internal network.

The Cloudmon Server and database remain on the internal network, while probes are placed according to security zone requirements — typically behind the internal firewall, with only the necessary ports opened across the DMZ boundary to reach monitored devices.


⚠️Note: Exact probe and firewall rule placement for DMZ deployments depends on your organization's security policy.

Managed Service Providers (MSPs)

Managed Service Providers offer IT monitoring and management services to multiple clients, often spanning various geographical locations and network environments.

The Cloudmon Server and database are hosted at the MSP's premises, while probes are deployed at each customer site to discover and monitor local devices. Each customer-site probe reports back to the centralized Cloudmon Server, giving the MSP a single platform to monitor all client infrastructures.


HA (High Availability)

This deployment model is suited to business-critical environments that cannot tolerate extended monitoring downtime. High availability is achieved using Primary and Secondary Controller URLs, with multiple Cloudmon Controllers deployed behind an external load balancer that manages traffic distribution and failover between them.

The primary Cloudmon Server runs at the main data center (DC), with a secondary Cloudmon Server kept in sync at a separate disaster recovery (DR) site; each site runs its own MongoDB database, with the DR database kept current through continuous replication from the DC. Agents and probes are configured with both the Primary and Secondary Controller URLs and perform client-side failover, switching to the secondary Controller if the primary becomes unreachable — so remote probes at Site-A and Site-B, and the NOC headend, continue reporting in without manual reconfiguration if the DC becomes unavailable.



Network Connectivity and Firewall Requirements

For the list of ports and connectivity requirements per component, refer to the Communication Matrix and Firewall Rules article.
ℹ️Note: For DMZ , HA and MSP deployments, work with your network/security team to confirm which of these paths need to cross a firewall or security zone boundary.

For assistance choosing a deployment model or planning probe placement for a DMZ , HA and MSP environment, contact Cloudmon support. Refer to How to Contact Support.