A user-friendly PHP looking glass that lets visitors run network diagnostics (host, mtr, ping, traceroute, and IPv6 variants) on your server through a web UI.
Current version: 1.0.0 (PHP 8.1+, Bootstrap 5, CSRF protection, multi-node)
Author: Aria Jahangiri Far
- Automated install via
configure.sh - IPv4 and IPv6 commands
- Live streamed command output
- Light / dark themes
- Per-IP rate limiting (SQLite)
- CSRF-protected command endpoint (POST)
- Multiple nodes — add remote LookingGlass servers and run tests from them
- PHP 8.1+ with PDO SQLite and cURL (required for remote nodes)
- Linux host with
host,mtr,ping/ping6,traceroute - Apache (with
AllowOverride) or Nginx + PHP-FPM
-
Place files in your web root.
-
Copy config:
cp LookingGlass/Config.example.php LookingGlass/Config.php
Edit values (especially
$adminPasswordand$apiKey), or run:cd LookingGlass bash configure.sh -
Ensure Apache/Nginx denies HTTP access to
/LookingGlass.
Use multiple LookingGlass installs (for example one per PoP). Visitors choose a Node in the test form; this server runs the command locally or proxies it to a remote peer.
- Install LookingGlass on every server that should run tests (same codebase and PHP requirements).
- On every server, edit
LookingGlass/Config.php:- Set
$adminPasswordto a strong password (used only on the server where you manage the node list). - Set
$apiKeyto a long random secret. The same$apiKeymust be configured on all peers.
- Set
- Ensure PHP cURL is enabled on the server that will proxy to remotes (usually your main / hub instance).
- Prefer HTTPS for every LookingGlass URL.
Example secrets in Config.php:
$adminPassword = 'your-strong-admin-password';
$apiKey = 'a-long-random-shared-secret';- Open
https://your-main-lg.example.com/admin.php. - Log in with
$adminPassword. - Under Add node, fill in:
- Name — display name, e.g.
Tehran - Location — optional label, e.g.
IR-THR - Base URL — leave empty so tests run on this server
- Name — display name, e.g.
- Click Add node.
A default Local node is created automatically if none exist; you can rename it or add another local-style entry with an empty URL.
- Confirm LookingGlass is working on the remote host, e.g.
https://lg-fra.example.com. - On that remote host, set the same
$apiKeyas on the hub inLookingGlass/Config.php. - On the hub, open
/admin.phpagain and add a node:- Name — e.g.
Frankfurt - Location — e.g.
DE-FRA - Base URL — LookingGlass site root only, no trailing slash and not pointing at
ajax.php
Correct:https://lg-fra.example.com
Wrong:https://lg-fra.example.com/orhttps://lg-fra.example.com/ajax.php
- Name — e.g.
- Click Add node.
- On the public Looking Glass page, select the new node and run a test (e.g.
pingto1.1.1.1).
If the remote is unreachable, check firewall/DNS, matching $apiKey, and that cURL can reach the remote URL from the hub.
In /admin.php (while logged in):
- Change name, location, or URL, then click Save.
- Click × to delete a node (if you remove all nodes, a default local node is recreated).
- Open the main Looking Glass page.
- Enter a host or IP.
- Choose a Node from the dropdown.
- Choose a command and click Run Test.
Local nodes execute on this server. Remote nodes are called by this server using $apiKey (visitors never see the key).
| Item | Hub | Each remote |
|---|---|---|
| LookingGlass installed | Yes | Yes |
Same $apiKey |
Yes | Yes |
$adminPassword set |
Yes (to manage list) | Optional |
| Node URL empty | Local tests | — |
| Node URL = peer root | — | Listed on hub |
| PHP cURL | Required for remotes | Recommended |
- Change
$adminPasswordand$apiKeyfrom the defaults before going public - Set a non-zero
$rateLimitin production - Keep
/LookingGlass(config, SQLite,nodes.json, scripts) blocked from the web - Run behind HTTPS; monitor for abuse
.htaccess disables indexes, blocks private LookingGlass files, and turns off gzip for *.test downloads. Enable AllowOverride.
Use or adapt LookingGlass/lookingglass-http.nginx.conf.
MIT — see LICENCE.