
Note
|
The auto-on task feature is available from Cisco Catalyst SD-WAN Manager Release 20.12.1.
|
An auto-on task monitors your network for events that you choose and automatically runs a trace if two consecutive events
of the same type are detected.
QoS congestion event is generated after continuous congestion for 5 seconds, and only one event is generated in one minute.
The auto-on task requires two occurrences in a row to trigger the monitoring.
SLA violation event is generated when one packet does not meet SLA requirements, and only one event is generated in one minute.
The auto-on task requires two occurrences in a row to trigger the monitoring.
You can choose applications as SLA violation trigger conditions.
The number of consecutive events can be configured.
Security Alert event triggers a trace automatically when a security alert is detected by the Unified Threat Defense (UTD),
such as IPS alerts or file reputation alerts, and also if firewall drops are seen unexpectly.
An auto-on task monitors the network for a period that you specify. Each trace that a task runs lasts for 5 minutes. To avoid
congestion from multiple traces running simultaneously, for each site that is monitored, there is a ½ hour interval after
a trace starts before the next one begins.
Options for traces that an auto-on task generates are preconfigured and cannot be changed.
An auto-on task is useful if you have identified or suspect a potential or intermittent issue in your network. For example,
if you have identified intermittent SLA violations, instead of manually monitoring the network and manually starting a trace
when you see an SLA violation, you can create a task that automatically starts traces when SLA violations are detected.
-
From the Cisco SD-WAN Manager menu, choose .
-
Click New Auto-on Task.
-
In the Task Name field, enter a name for the task.
-
From the Select Event drop-down list, choose the following event(s) that, when detected, start a trace:
-
QoS Congestion: Congestion on the non default QoS queue of an interface.
-
SLA Violation: Traffic outside of the parameters that are defined by a service level agreement (SLA), for example, traffic latency exceeding
predefined criteria.

Note
|
In Cisco Catalyst SD-WAN Manager Release 20.18.1, for QOS congestion and SLA violation events, by default, two consecutive events of each type are required to trigger a NWPI
trace, and the number of consecutive events is configurable.
|

Note
|
The Security Alert, WAN Loss and IPSec Anti Replay Drop event types are available from Cisco Catalyst SD-WAN Manager Release 20.18.1
|
-
Security Alert: Automatically initiate a trace when security alerts are detected by UTD, such as IPS alerts or file reputation alerts.
-
WAN Loss: You can configure WAN Loss as an auto-on trace trigger. By setting a loss percentage criterion, Cisco SD-WAN Manager triggers an NWPI trace when the loss percentage is higher than the configured value.
-
IPSec Anti Replay Drop: You can set a criterion on the drop percentage, to help Cisco SD-WAN Manager trigger an auto-on NWPI trace when the drop is percentage higher than the configured value.
When abnormal IPsec Anti-replay drops are detected, the device will send a netconf notification to Cisco SD-WAN Manager, and NWPI triggers an auto-on trace based on the received notification.

Note
|
In Cisco Catalyst SD-WAN Manager Release 20.18.1, for Security Alert, WAN loss, and IPSec anti-replay drop events, a single event of each type is sufficient to trigger a
trace.
|
-
(Optional) From the Select Site drop-down list, choose the name of one or more Cisco Catalyst SD-WAN network sites in which to perform the trace.

Note
|
From Cisco Catalyst SD-WAN Manager Release 20.18.1, you must select one or more Cisco Catalyst SD-WAN network sites.
Up to 50 sites can be supported.
|
If you do not choose a network site, the task monitors all the sites.
-
In the Select Duration field, enter the number of hours the task lasts for.
The task monitors your network for the selected events during this duration.
Enter a number from 1 through 168.

Note
|
From Cisco Catalyst SD-WAN Manager Release 20.18.1, you can enter a number from 1 through 720 hours or 1 through 30 days.
|
-
(Optional) Expand the Advanced Configuration area and configure the following parameters:
Table 4. QoS Congestion
Field
|
Description
|
Application
|
From Cisco Catalyst SD-WAN Manager Release 20.18.1, the enhanced auto-on configuration allows selection of up to 32 applications.
Only QoS Congestion events associated with these specified applications will trigger an auto-on trace.
|
Number of consecutive events
|
This setting determines how many consecutive QoS Congestion events from the same Cisco IOS XE Catalyst SD-WAN device are required to trigger an auto-on trace. By default, this is set to 2. This means that if two QoS Congestion events occur
in succession, a trace will automatically be initiated to monitor and diagnose the congestion issue.
|
Congestion burst interval (second)
|
For continuous QoS congestion, the device generates one QoS congestion event per reporting interval. The configurable reporting
interval ranges from 1 to 60 seconds.
|
Trace only the selected or impacted applications
|
Click this check box to ensure only the flows with applications matching those reported in the QoS Congestion event are traced.
By default, it is not selected. All the applications will be traced in the trace triggered by the auto-on task.
|
Table 5. SLA Violation
Field
|
Description
|
Application
|
From Cisco Catalyst SD-WAN Manager Release 20.18.1, the enhanced auto-on configuration allows selection of up to 32 applications.
Only SLA Violation events associated with these specified applications will trigger an auto-on trace.
|
Number of consecutive events
|
This setting determines how many consecutive SLA Violation events from the same Cisco IOS XE Catalyst SD-WAN device are needed to trigger an auto-on trace. The default is 2. This means that a trace will be initiated automatically if two
SLA Violation events occur consecutively.
|
Trace only the selected or impacted applications
|
Click this check box to ensure only the flows with applications matching those reported in the SLA Violation event are traced.
By default, it is not selected. All the applications will be traced in the trace triggered by the auto-on task.
|
Table 6. Security Alert
Field
|
Description
|
UTD IPS Alert
|
Check this check box to automatically create a trace when Cisco IOS XE Catalyst SD-WAN device identifies and blocks suspicious activity using Intrusion Prevention System (IPS). You can specify a particular Security
Identifier (SID) to create a trace only when that specific signature is identified.
|
UTD File Reputation Alert
|
Check this check box to create a trace when a malicious file is identified and blocked by the Advanced Malware Protection
(AMP). You can specify a particular SHA hash value to create a trace only when that specific file is identified.
|
UTD File Reputation Retrospective Alert
|
Check this check box to trigger a trace based on a retrospective analysis of files that have passed through the network. |
Firewall Drop
|
Application flows dropped by a firewall policy are usually as per configuration/design. However, you suspect unexpected drops
due to a misconfigured firewall policy, select this checkbox to enable firewall policy drop rate monitoring in auto-on task.
|
Trace only the traffic with the same source IP as the alert event
|
Click this check box to ensure that when an auto-on trace is created, it only traces the flows with the source IP reported
in the security alert.
|
Trace only the traffic with the same destination IP as the alert event
|
Click this check box to ensure that when an auto-on trace is created, it only traces the flows with the destination IP reported
in the security alert.
|
Table 7. WAN Loss
Field
|
Description
|
WAN Loss Rate Threshild (%)
|
Set a loss percentage criterion to help Cisco SD-WAN Manager trigger an auto-on NWPI trace when the loss percentage is higher than the configured value.
|
Table 8. IPSec Anti Replay Drop
Field
|
Description
|
Drop Rate Threshold (%)
|
Set a criterion on the drop percentage, to help Cisco SD-WAN Manager trigger an auto-on NWPI trace when the drop is percentage higher than the configured value.
|
-
Click Start.
The task appears in the table of auto-on tasks. This table provides the following information and options for each task and
each trace that the task starts:
-
Task name: Task trace name. This field also includes the Insight Summary link, which lets you see more information about the traces that the task started. See Insight Summary.
-
Task ID: System-generated identifier of the task or trace.
-
Event(s): The event or events that you configured to start a trace, or the events that triggered a trace.
-
Site(s): The name of each site that the task monitors, or the name of the site in which a trace ran.
-
State: Active means that the task is live or a trace is running. Finished means that the task or trace has completed.
-
Start Time: Date and time at which you started the task or that a trace started.
-
Duration: Number of hours that a task or trace is live or ran.
-
Stop Time: Date and time at which the task or trace ended.
-
Actions:
Start a trace using a time schedule-based auto-on task
From Cisco Catalyst SD-WAN Manager Release 20.18.1, you can schedule traces to start at specific times.
-
From the Cisco SD-WAN Manager menu, choose .
-
Click .
-
In the Task Name field, enter a name for the task.
-
In the Duration field, select the number of days (maximum 30).
-
In the Recurrence Setting pane, enter the Trace Start Time (s) and Duration(s).

Note
|
A maximum of 8 Trace Start Times is supported, the combined duration of all traces is 1,440 minutes (24 hours). A minimum
gap of 10 minutes is required between traces.
|
Monitor events using a a time schedule-based auto-on task
From Cisco Catalyst SD-WAN Manager Release 20.18.1, you schedule the monitoring of events within specific timeframes.
-
From the Cisco SD-WAN Manager menu, choose .
-
Click .
-
In the optional Recurrence Setting pane, specify the days to monitor only at critical moments. If unspecified, the auto-on task will monitor events throughout
the entire timeline by default.