Cisco Secure Access Help

PDF

Cisco Secure Access Help

Onboard Experience Insights

Want to summarize with AI?

Log in

Provides instructions for completing the Onboard Experience Insights workflow in Cisco Secure Access. An active Cisco ThousandEyes account with the Organization Admin role.


Use the Experience Insights onboarding wizard to connect Secure Access to your Cisco ThousandEyes account for end user experience monitoring of endpoint, application, and network performance.

Before you begin

  • An active Cisco ThousandEyes account with the Organization Admin role. For more information, see Role-Based Access Control and Built-in Roles and Permissions in ThousandEyes documentation.

    • The administrator who received email notification of Secure Access activation will also receive email notification of ThousandEyes activation. Follow ThousandEyes provisioning instructions within 72 hours of receiving the activation email. If the activation email is expired, visit the ThousandEyes login page and click Forgot password?

  • The ThousandEyes login account group is correct for integration with Experience Insights.

  • Cisco Secure Client must be installed on your endpoints. The ThousandEyes endpoint agent is included in the installation.

  • If you intend to use RAVPN as the target for the synthetic network default test, it must be configured.

Procedure

  1. Navigate to Experience Insights > Insights Management > Management, then click Begin onboarding.

  2. Click the Integrate button to launch ThousandEyes.


    Start the integration with your ThousandEyes account by clicking Integrate.
  3. Log into ThousandEyes using an account with the Organization Admin role.


    The Onboard Experience Insights 02 interface.
  4. Confirm that you authorize the following Secure Access permissions in ThousandEyes:

    1. Read organization - Allows the reading of the organization credentials, account groups, users, user events, roles, permissions, usage and quotas.
    2. Manage endpoint agents - Allows the end user to manage their endpoint agents.
    3. Manage endpoint tests - Allows the end user to manage their endpoint tests.
    4. Manage tags - Allows the end user to manage their tags and labels.
    5. Read tests - Allows the end user to read their tests and the respective results.
  5. After confirming, wait for the Experience Insights onboarding wizard to reload and display the Integration successful message, then click Next.

  6. Choose your ThousandEyes account groups integration: Default account group integration or Multiple account groups integration. After the integration you can change the integration method by navigating in Secure Access to Account Management > Account group integration.

    1. Default account group integration: By selecting this integration, two default tests are only created in the default account group. If you need to edit these tests after the completion of onboarding, navigate to Account Management. For more information, see Edit Default Test Target.
    2. Multiple account groups integration: By selecting Multiple account groups, you will see all the ThousandEyes account groups and tests associated with the ThousandEyes user who did the initial integration with Secure Access

    In Account group configuration select Default account group or Multiple account groups integration.
  7. For the synthetic network test, select the security connection method most commonly used by your endpoints. Test target options include Zero Trust Access, RAVPN, and SWG Roaming Module.

    Synthetic tests identify performance issues in user journeys to their destinations. After onboarding, you can modify the test target to include custom public or private applications.


  8. Select your organization's primary collaboration application (Webex, Zoom, Microsoft Teams, or None) to view a real-time summary of its performance during user interactions, including overall health score. You can update your selection later.


    Select your organization's primary collaboration application.
  9. Manually register the ThousandEyes Endpoint Agent for endpoints that are not using VPN, ZTA, or the Roaming Module for their security connection.


    Select how endpoints register with ThousandEyes to monitor their performance.

    This process involves copying and pasting a command script onto the specific endpoints. The registration script includes a ThousandEyes connection string that is unique to your organization. Your organization's connection string is the parameter following the --register argument.

    "C:\Program Files (x86)\Cisco\Cisco Secure Client\ThousandEyes Endpoint Agent\csc_te_agent" --register <connection string>
    sudo /Applications/Cisco/Cisco\ Secure \Client\ -\ ThousandEyes\ Endpoint\ Agent.app/Contents/MacOS/csc_te_agent --register <connection string>
    1. Navigate to Experience Insights > Configure Account to find your organization's registration scripts.
      You can access these scripts at any time after onboarding is completed.
    2. Copy the appropriate command script for your endpoint's operating system.
    3. On the target endpoints, paste and execute the copied script.

What to do next

Once you complete the Experience Insights onboarding wizard and the registration of one or more endpoints, data reported by the ThousandEyes endpoint agent will appear in your Experience Insights dashboard.

Navigate to Experience Insights > Endpoints to confirm that your endpoint is reporting data.

For more information, see the following resources: