Deep Axion Technical Overview | Cross-VLAN AV Discovery
For technical teams and integrators

Segmented by design. Simple to operate.

Deep Axion reflects service discovery across VLANs without bridging the network. Media streams travel directly, existing firewall policy remains authoritative, and engineers gain live operational visibility.

Deep Axion reflection map
Origin and reflected destinations visible in one operational view.
Discovery onlyReflects the small mDNS and SSDP conversations, not media payloads.
Streams go directAudio and video follow the normal routed unicast path.
Low overheadLab measured below 2% CPU and 0.5 Mbps at 10 active VLANs.
Vendor neutralRuns with any suitable managed switch with IGMP snooping.
Architecture

Discovery is reflected. Streaming is not.

Deep Axion solves the discovery problem, then gets out of the way. It is neither a layer-2 bridge nor a media proxy.

01 · VIA DEEP AXION

Discovery

A client asks which compatible services are available. Deep Axion evaluates policy and reflects the small discovery exchange to the appropriate VLANs.

02 · DIRECT

Connection

The client learns the destination device's real IP address and opens a normal routed unicast connection, subject to existing firewall policy.

03 · DIRECT

Streaming

Video, screen mirroring and audio flow directly between endpoints. Deep Axion is not in the media path.

Security posture: VLAN separation and firewall enforcement remain intact. Deep Axion handles discovery metadata only; it does not decrypt, transcode, inspect or carry media payloads.
Compatibility

One appliance for the services used on site.

Deep Axion combines mDNS and SSDP discovery so mixed Apple, Google, Sonos and UPnP estates can operate across segmented networks.

ServiceDiscovery familiesTypical use
AirPlay audio and videomDNSiPhone, iPad or Mac to Apple TV, HomePod or AVR
Sonos S2mDNSSSDPApp discovery, grouping, volume and zone control
Google ChromecastmDNSSSDPAndroid, Chrome and supported apps to Chromecast or Google TV
Spotify ConnectmDNSSpotify app to compatible speakers, televisions and receivers
Tidal ConnectmDNSTidal app to compatible speakers, televisions and receivers
Roku and UPnPSSDPRoku ECP discovery, DLNA renderers and compatible UPnP devices
AirPrint, HomeKit and MattermDNSDiscovery for printing, smart-home and automation services
Deployment

Fits the network already specified.

A preconfigured macOS or Ubuntu appliance connects to a trunk port and becomes the single mDNS and SSDP authority for the participating VLANs.

Host options

Apple Mac mini M4 appliance or a supported Ubuntu 24.x Linux host.

Network attachment

One 802.1Q trunk port with the required VLANs presented to the appliance.

Switch requirement

Managed switching with IGMP snooping enabled on participating VLANs.

Existing relays

Disable competing mDNS gateways, Bonjour forwarding and legacy multicast helper configuration before commissioning.

Routing and firewall

Allow the service-specific unicast paths required between clients and destinations. Existing firewall policy remains authoritative.

Management

Local browser interface over TLS, with two-role authentication and no ongoing internet dependency after activation.

CiscoUniFiArubaRuckusMikroTikJuniperExtreme
Operational visibility

Find the fault without starting from packet capture.

Deep Axion combines service reflection with active health and multicast diagnostics in the same local interface.

Deep Axion active device health

Active device health

TCP probes run against advertised service ports on a 60-second cadence, with per-device state and recent history.

Deep Axion forwarding rules

Live forwarding policy

Per-protocol forward and block rules, VLAN-to-VLAN policy, device-source rules and live re-evaluation.

Deep Axion reflection map

Reflection map

See each physical device, its origin VLAN and reflected destinations without tracing the cache manually.

Deep Axion multicast traffic map

Multicast traffic map

Observed per-VLAN flows with protocol classification, live rates, IGMP health and rolling history.

Validation and commercial model

Built to stay local and keep running.

The appliance has been exercised in demanding, mixed-vendor AV environments.

180+ daysContinuous soak testing
150+ devicesTested across installations
10 VLANsCurrent tested reference scale
PerpetualHardware-locked signed licence
Licence and support: the perpetual licence does not require a continuing subscription or call-home service. The first twelve months include version updates and priority support; annual renewal is optional thereafter.
Engineering checklist

What to confirm before deployment.

Participating VLANs

Document the source and destination segments and the services that should be visible between them.

Competing discovery features

Remove legacy ip helper-address multicast relays and disable vendor mDNS gateways.

IGMP snooping

Enable it on participating VLANs and confirm an appropriate querier is present where required.

Inter-VLAN policy

Permit the endpoint-to-endpoint TCP and UDP ports required by the services being deployed.

Trunk presentation

Present the required tagged VLANs to the appliance and verify local addressing on each interface.

Acceptance testing

Validate discovery and playback from representative client networks, then review health and reflection views.

Technical review

Review the design with us.

Share the switch platform, VLAN count, intended services and deployment type. We will help your integrator confirm fit before quotation.