Cisco Secure Access Help

PDF

Cisco Secure Access Help

About Endpoint Agent Tests

Want to summarize with AI?

Log in

Describes About Endpoint Agent Tests in Cisco Secure Access. Secure Access endpoint tests powered by Cisco ThousandEyes simulate the user path to sites and applications using real traffic to gain insights into performance issues.


Secure Access endpoint tests powered by Cisco ThousandEyes simulate the user path to sites and applications using real traffic to gain insights into performance issues. When you onboard Experience Insights and install the ThousandEyes endpoint agent on end user devices, the agent goes where the user goes. This enables synthetic testing that closely matches end user experience.


Manage endpoint tests in Secure Access

To manage and configure your endpoint licenses, synthetic endpoint tests, and default network and collaboration app tests, log into Secure Access and navigate to Experience Insights > Endpoint tests.


Endpoint license usage

The first table displays your ThousandEyes license usage. You can click on the All Account Groups drop-down list to select specific account groups to view their license usage.

Changing the All Account Groups drop-down list does not update the Endpoint tests table.


The Endpoint License Usage interface.

The number of tests you can run is based on your organization's ThousandEyes license type. The embedded license is assigned by default when you onboard Experience Insights.

License type Synthetic tests per endpoint Test data retention
ThousandEyes Endpoint Embedded (default) 2 4 days
ThousandEyes Endpoint Essentials 4 14 days
ThousandEyes Endpoint Advantage 10 30 days

You can run a combination of multiple scheduled and dynamic tests at a time. If you exceed the number of allowed tests, ThousandEyes uses a mechanism to determine which tests should run on a given agent. For information, see Assigning tests to an Endpoint Agent.

For more information about ThousandEyes licensing, see ThousandEyes Endpoint Agent Licensing.


Endpoint tests

The second table lists your running and disabled tests. In the table you can:

  • Search by test name.

  • Filter by test type: All test types, Network, or HTTP.

  • View all ThousandEyes created tests and tests created in Experience Insights, or only view Experience Insights tests.


The Endpoint Test Account Group interface.

Click a test name to view Endpoint test results. For more information, see View HTTP Server Test Results and View Network Test Results.

Click Add new to configure a new synthetic test. For more information, see Create HTTP Server Tests and Create Network Tests.

Account Group: Shows all the account groups that the Endpoint tests are configured in. (This option appears only when you have multiple ThousandEyes account groups selected in Account Management.)

Select one or more table rows to delete, disable, or enable tests.


Select one or more table rows to delete, disable, or enable tests.

Default Endpoint tests


Manage endpoint agents and tests in ThousandEyes

Additional options are available in the ThousandEyes dashboard.

  • You can configure alerts for specific tests. For more information, see Alerts.

  • You can adjust test priority for each endpoint agent. For more information, see Test Priority.

  • You can reallocate a license to another endpoint. For more information, see Assigning licenses to Agents.

  • For more information about managing synthetic endpoint tests in ThousandEyes, see Managing Synthetic Tests.


Limitations

A single synthetic test is limited to a maximum of 150,000 endpoint agents.


Estimate Peak Traffic to Custom Targets for Default Endpoint Tests

Endpoint tests sent to custom targets (whether public or private) require bandwidth. A high number of endpoint agents sending synthetic traffic to a custom target can generate network throughput high enough to negatively impact custom target performance.

Before selecting a custom target for a default endpoint test, we recommend using the traffic calculator to estimate peak throughput. Use that estimate to ensure your network and server have the capacity to handle peak throughput. You can also use mitigation strategies described below to attempt to reduce peak throughput.


Calculate Estimated Peak Throughput of Test Traffic

Estimated peak throughput of test traffic is an estimate of the upper limit of bandwidth required in the event that the default test runs for all endpoint agents at at the same time. At the default test interval of 1 minute, actual test throughput will be at or near estimated peak throughput. At higher test intervals, actual test throughput may not be as high as estimated peak throughput, but this is not guaranteed.

Estimated peak throughput = A x N

  • A = Agent throughput for a single test (in KB/s). Peak throughput is 1 KB/s per endpoint agent.
  • N = Number of endpoint agents, assuming one synthetic test per agent to the same custom target. By default, all endpoint agents are included in the default test.

Consult with internal teams (IT, network, or firewall administrators) to compare the results to your network and server capacity to ensure that your systems can withstand the load.

Note
Estimated Peak Throughput Calculation Example

A = 1 KB/s

N = 1000 agents

Peak throughput: A x N = 1,000 KB/s (1 MB/s)


Mitigation Strategies

Follow these strategies to mitigate default test throughput that exceeds your available bandwidth.

  • Change the default test target (RAVPN, Zero Trust Access, or SWG remote module) or custom target that is more capable of managing the load.
  • Increasing the test interval may mitigate impact on your network. At the default test interval of 1 minute, actual throughput will be at or near estimated peak throughput. Increasing the interval will likely redistribute the tests over the longer interval.
    Note
    It is not possible to predict actual throughput at test intervals greater than 1 minute. In the worst case scenario, if all endpoint agent tests run at the same time (for example, at minute 30 of a 30-minute test interval), they would still generate actual throughput at or near estimated peak throughput.
  • Increase the capacity of your backhauling infrastructure.
    • If using IPsec tunnels, provision traffic backhauling over your edge infrastructure that is capable of handling increased traffic load.
    • If using resource connectors, add additional connectors to resource connector groups to increase the ability to handle the traffic load.

Recovery Options

If your system crashes or becomes unavailable due to high traffic sent to a custom target, do the following:

  • For public targets: The SaaS provider may block traffic that is sent from Cisco IP addresses. The traffic may mimic the characteristics of a distributed denial-of-service (DDoS) attack, potentially disrupting legitimate user access by overloading system resources. Contact Cisco support.
  • For private targets: Seek assistance from your IT or network administration team.

Create HTTP Server Tests

HTTP server tests measure the response time and generate the response code of a web server. They are compatible with VPN and ZTA destinations.

Prerequisites

  • Endpoints must have requisite permissions to access the test's target application. For more information, see Manage Access Policies.
  • Endpoints must meet testing capacity requirements. For more information, see Endpoint Agent Licensing.

Zero Trust Access prerequisites:

  • Endpoints must meet Zero Trust Access posture-profile requirements. For more information, see Manage Zero Trust Access Posture Profiles.
  • End users must be enrolled in Zero Trust Access and must be signed into their OS.
  • Strongly recommended: When testing private resources, turn off the user-authentication interval to prevent end users from receiving unexpected notifications. You must turn off the user authentication globally and for the specific HTTP server test. For more information, see: Rule Defaults: Default Settings for Access Rules and Network Requirements for Zero Trust Access.
  • Your ZTA version must be 5.17 or higher, as earlier versions lack the necessary telemetry support. Updating ensures full visibility into the secure access path for better monitoring and troubleshooting.

Procedure

Strongly recommended: Before running large-scale tests, run a test with a small subset of agents to ensure that your network can support the test traffic between Secure Access and your on-premise environment.

Procedure

  1. In Secure Access, navigate to Experience Insights > Insights Management > Endpoint tests.

  2. Above the Endpoint tests table, click Add new > HTTP.


    The Experience Insights HTTP Tests 01 interface.
  3. Define the agents and target destination under Add HTTP test.


    The Experience Insights HTTP Tests 02 interface.
    • Name —Enter a name that identifies the agent-to-server test (such as target domain name or IP address).

    • From —Specify by location, account groups, specific agents, or device type. You can also select between different account groups.

      • If you select all agents from a given location, the test will be associated with the agents that are currently present for that location.

      • If a new agent becomes available for the location when the test is run, the agent won't be included in the test. To add the new location, create a new test or clone the existing test.

      • Regardless of which group of agents you choose, the test itself will always be stored in your default account group for easy, centralized access.

      • Device type: Windows and macOS are supported.

      • A single synthetic test is limited to a maximum of 150,000 endpoint agents.

    • To

      • Private resource: Choose an IP address from the drop-down. VPN and ZTA are supported.

      • Custom target: Specify a Web URL.

    • Protocol:

      • Auto-detect—The default and recommended option. Auto-detect tries several probes to identify the best test method for the device's current network conditions.

      • ICMP

      • ICMP + TCP Connect—Enables a TCP connection with a 10-second timeout and closes the connection if it is unable to connect. Unsuccessful connections count towards the TCP-connection failures metric.

      • Prefer TCP (ICMP fallback)

      • TCP

    • Test interval—Select the frequency of the test run.

    • The Network traffic calculator is available to help you ensure your network can support the maximum throughput for private resources considering the number of endpoints that will be registered.

  4. Click Save test.

    Before running large-scale tests, run a test with a small subset of agents to ensure that your network can support the test traffic between Secure Access and your on-premise environment.


Create Network Tests

Network synthetic tests measure the network performance and path between an agent and its target destination. They are compatible with VPN destinations. The destination can be an IP address or a domain name.


Procedure

Before you begin

  • Endpoints must have requisite permissions to access the test's target application. For more information, see Manage Access Policies.

  • Endpoints must meet testing capacity requirements. For more information, see Endpoint Agent Licensing.

Procedure

  1. In Secure Access, navigate to Experience Insights > Insights Management > Endpoint tests.

  2. Above the Endpoint tests table, click Add new > Network.


    The Experience Insights Network Tests 01 interface.
  3. Define the agents and target destination under Add network test.


    The Experience Insights Network Tests 02 interface.
    • Name—Enter a name that identifies the agent-to-server test (such as target domain name or IP address).

    • From—Specify by location, account groups, specific agents, or device type. You can also select between different account groups.

      • If you select all agents from a given location, the test will be associated with the agents that are currently present for that location.

      • If a new agent becomes available for the location when the test is run, the agent won't be included in the test. To add the new location, create a new test or clone the existing test.

      • Regardless of which group of agents you choose, the test itself will always be stored in your default account group for easy, centralized access.

      • Device type: Windows and macOS are supported.

      • A single synthetic test is limited to a maximum of 150,000 endpoint agents.

    • To

      • Private resource: Choose an IP address from the drop-down. Only VPN is supported.

      • Custom target: Specify an IP address or Web URL.

    • Protocol:

      • Auto-detect—The default and recommended option. Auto-detect tries several probes to identify the best test method for the device's current network conditions.

      • ICMP

      • ICMP + TCP Connect—Enables a TCP connection with a 10-second timeout and closes the connection if it is unable to connect. Unsuccessful connections count towards the TCP-connection failures metric.

      • Prefer TCP (ICMP fallback)

      • TCP

    • Port:

      • The field will auto-populate for configured ports. For non-configured resources and resources that have multiple ports, enter the port number(s).

      • If you entered a custom target, accept the default value or leave the field blank.

    • Test interval—Select the frequency of the test run.

    • The Network traffic calculator is available to help you ensure your network can support the maximum throughput for private resources considering the number of endpoints that will be registered.

  4. Click Save test.

    Before running large-scale tests, run a test with a small subset of agents to ensure that your network can support the test traffic between Secure Access and your on-premise environment.


View HTTP server test results

The Endpoint Test Results page displays the response time and response code for HTTP server tests, as well as error types and details for failed tests.


Screenshot of the Endpoint test results page.

Procedure

  1. Go to Experience Insights > Insights Management > Endpoint tests.

  2. On the Endpoint Tests page, click a scheduled HTTP server test (identified in the Test type column).


    Screenshot showing a scheduled HTTP server test in the Test type column.
  3. View the aggregated results for the test.

    • Response code—Indicates the interaction between the client and the server. A successful response code falls within the 200–299 range.
    • Response time—The time it takes for a request sent by the testing agent to receive a response from the target application server.

    Screenshot showing response code and response time results for an HTTP server test.
  4. To view HTTP test results for a specific endpoint, click the down arrow next to the username to display the device path to the target destination.


    Screenshot showing the expanded device path to the target destination for a specific endpoint.

View Network Test Results

The Endpoint Test Results page displays the quality of the test's network connection represented by key metrics including latency, packet loss, and jitter.

Procedure

  1. Navigate to: Experience Insights > Endpoint tests.

  2. On the Endpoint Tests page, click a scheduled network test (denoted in the Test type field).

    The Experience Insights View Network Test 01 interface.
  3. On the Endpoint Test Results page, view the results:

    • Latency—High network latency is 150ms or above.

    • Jitter—High jitter is 40ms or above.

    • Loss—High packet loss is 20 percent or above.

    The Experience Insights View Network Test 02 interface.
  4. Click the down arrow next to a username to view the Endpoint test results, and Segment visualization for the device path to the target destination.

    This is a screenshot of the Endpoint test results.