DESTINATIONS: YOU CHOOSE THEM
Point each unit at whatever your business actually depends on.
Each destination gets its own name, host, and check type, ICMP ping, TCP port, HTTP/HTTPS for websites and APIs, or a DNS check that a resolver is still answering and a name still resolves. Every one gets its own latency, jitter, packet-loss and 0–100 quality score, plus its own uptime record. Change them anytime from the touchscreen or centrally, no reboot, no site visit.
ALSO WATCHED
The failures that have nothing to do with bandwidth.
Some of what stops a small site has nothing to do with the connection being slow. These are quiet, they are usually dated, and nobody is watching them.
On any HTTPS destination you monitor, before the browser warning does it for you.
Checked against the registry itself, not a reminder email somebody archived.
Your WAN address turning up on a DNS blacklist, which is usually discovered by a customer.
A system clock far enough out to start refusing signed transactions.
Something answering in place of the real service, which looks like uptime until you read the answer.
These run on every unit, enrolled or not.
SPEED, WHEN YOU ASK FOR IT
Is the line actually delivering what you pay for?
A throughput test runs on demand, not on a timer. Scheduled tests burn data on a metered link, they congest the very history you are trying to measure, and they hand a provider an easy answer: that your monitoring caused it. It is off until you ask for it, or until the fleet schedules it.
It measures download and upload, and one number most speed tests leave out: what happens to latency while the line is saturated. That is the difference between “the speed test looked fine” and “the video calls break up every afternoon”, and it is usually the number that settles the argument.
Every test is bounded by hard byte caps, so it cannot run away with a data allowance. A test that moves no bytes is reported as a failure, never as a reassuring zero.
DUAL-PATH MODE
You have backup internet lines? Know which one you're running on.
Backup connections hide a costly problem: silent failover. Traffic shifts to the backup, service continues, and no one notices the primary is down until the backup fails too, or the cellular overage bill arrives.
HopWarden assigns primary and backup gateway roles, shows which line is active, logs timestamped failover and restore events, and reports time spent on backup: a single failover notice instead of a wall of alarms.