Application inventories and network data typically live apart in enterprise IT. Application details sit in application performance management (APM) platforms and configuration management databases (CMDB). Network paths, cloud resources, and security controls sit in separate network tools, cloud consoles and microsegmentation systems. That fragmentation limits what operations teams, and increasingly AI agents, can reliably determine about the infrastructure supporting a given application.
It’s a gap that IP Fabric is now aiming to solve. IP Fabric builds a read-only digital twin of enterprise network infrastructure, discovering devices, paths and configuration to give network teams a current model of how traffic actually moves. The company released version 8.1 of the platform this week. The update adds application infrastructure mapping, which connects application workloads to the network and cloud paths they depend on, along with a redesigned cloud-native data model. The release follows IP Fabric 7.9, which expanded discovery and path analysis for Azure and Google Cloud Platform environments.
“For the first time, we will now have the service-aware digital twin, meaning that you can ask how this application path looks like today,” Pavel Bykov, CEO of IP Fabric, told Network World.
Application teams and network teams have largely worked from separate maps. “For a really long time, like for decades, the world of applications, systems, databases, code, workloads, and the world of networking, the cables, the connections, the cloud, were separate,” Bykov said.
First-class objects. IP Fabric 8.1 treats applications, workloads, and flows as first-class objects in the platform. For each application, the system calculates the end-to-end path for every workload it depends on and assembles those paths into a dependency map.
Bidirectional queries. The mapping works in both directions. Teams can query what infrastructure a given application depends on, or which applications depend on a specific device before it is upgraded or taken offline.
Automated reporting. The platform can also generate daily dependency reports and pre- and post-change impact summaries, which can feed external automation tools and AI agents.
Troubleshooting example. Bykov pointed to a common scenario. A link appears overloaded and traffic is dropping, but comparing the current path against the prior day’s model shows the application actually shifted to a different path entirely.
IP Fabric has always been able to discover network infrastructure natively, but application data is a separate problem, and the platform does not discover it directly. That data is ingested from outside sources, starting with a partnership with Illumio. Bykov explained that further integrations are planned with other vendors, and application data can also be imported through CSV or API.
IP Fabric previously captured cloud data and normalized it into a model built around on-premises concepts such as next hops and devices. Bykov said that approach did not hold up, since cloud paths include traffic manipulators, and transformers with no direct on-premises equivalent.
New model, new entities. VPCs, VNets, subnets, virtual network interfaces, route tables, peerings, and security policies are now first-class entities in the platform rather than elements normalized into an on-premises shape.
Still a translation layer. A layer still exists underneath, normalizing objects such as transit gateways and load balancers, but into a cloud-native model rather than an on-premises one.
What it enables. Path analysis strengthens within a single cloud, across peered networks and between cloud and on-premises infrastructure. IP Fabric evaluates AWS Security Groups, network ACLs and Azure Network Security Groups to determine whether a given path is permitted or blocked, and identifies which policy is responsible.
“We are working with how the cloud is actually communicating instead of trying to basically massage that model onto the on-prem worldview,” Bykov said.
IP Fabric enables AI agents to query the platform via its hosted MCP server, which predates the 8.1 update. What changes with this release is the depth of what sits behind that interface, since agents can now query the same verified application and cloud context described above through the same server.
Bykov said the stakes for that access are rising because AI agents are increasingly logging into network devices and making changes directly, which raises the need to validate what those changes actually did. “We all know that AI is only as good as the integrations to other systems, and there is now this one interface to the network,” Bykov said.
Asked about direction beyond 8.1, Bykov pointed to continued work on scaling the platform to larger and more complex networks, along with broader vendor and cloud coverage. “General direction is definitely right now more system improvements to cover larger, more complex networks,” Bykov said.