Monitor and Troubleshoot Steering Policy Health

Traffic steering policy

Security service insertion enhances security for SD-Access fabric networks by steering the traffic through firewalls based on traffic steering policies.

A service insertion site is the fabric site in a network where virtual networks and firewalls are configured to steer the traffic. To use security service insertion, enable a service insertion site in your network.

The traffic steering policies contain

  • security groups (source and destination security groups),

  • firewall, and

  • traffic steering contracts.

Monitor and troubleshoot the health of your steering policies

Ensure steering policies are functioning correctly by monitoring their health and addressing detected issues.

Before you begin

  • Enable a service insertion site. For more information, see the "Security service insertion for SD-Access" section in the Catalyst Center User Guide.

  • Configure traffic steering policies. For more information, see the "Configure Traffic Steering Policies " chapter in the Catalyst Center User Guide.

Use this procedure to view the health of your steering policies and determine if there are potential issues that must be addressed.

Procedure


Step 1

From the main menu, choose Assurance > Health.

The Overall health dashboard appears.

Step 2

Click the Steering Policy tab.

The Steering Policy health dashboard opens.

Step 3

Click the time range drop-down (Time range drop down) to specify the time range of data displayed.

  1. Select the time range: 3 Hours, 24 Hours, or 7 Days.

  2. (Optional) Specify a custom start date, end date, and time.

  3. Click Apply.

Step 4

(Optional) Click Gear icon and use the Data Auto Refresh Setting toggle button to enable or disable the automatic refreshing of data.

The refresh interval is 5 minutes.

Step 5

View the data in these dashlets.

Dashlet

Description

Security Service Insertion Sites

Displays the number of configured service insertion sites.

Policies

Displays the number of configured traffic steering policies.

Contracts

Displays the number of configured traffic steering contracts.

Issues

Displays the number of detected priority 2 (P2) issues.

Step 6

In the Issues table, view and address any listed issues.

  • Issues are color coded and sorted by priority, starting with P1 (highest).

  • Click an issue to open a slide-in pane with additional details about the issue type.

  • From the slide-in pane, click an issue instance and complete the required tasks:

    If you want to...

    Then...

    resolve the issue instance

    from the Status drop-down list, select Resolve.

    ignore the issue instance

    1. From the Status drop-down list, select Ignore.

    2. On the slider, set the number of hours to ignore the issue.

    3. Click Confirm.

For more information on managing issues, refer to View open issues and Resolve or ignore issues.

Step 7

In the Security Service Insertion Sites dashlet, view information about service insertion sites in your network.

Item

Description

Health

Filter sites displayed in the table based on health status:

  • All

  • Good: Both Cisco ISE synchronization and policy configuration are successful.

  • Poor: Cisco ISE synchronization, policy configuration, or both are not successful.

Search Table

Search for specific sites by name.

Table

View these details about service insertion site:

  • Site name: Hierarchical service insertion site location.

  • Overall site health: Consolidated health status for the service insertion site.

    Note

     

    Site health is considered Good only when both the Cisco ISE synchronization and policy configuration statuses are successful. Otherwise, the health is marked as Poor.

  • ISE sync: Status of the synchronization between Catalyst Center and Cisco ISE. A green check mark indicates a successful synchronization.

  • Policy download status: Indicates if security policies are successfully downloaded to the network devices at the service insertion site. A green check mark indicates a successful policy download.

  • Policies configured: Indicates if traffic steering policies are successfully configured on the network devices at the service insertion site. A green check mark indicates policies have been successfully configured to the network devices at the site.