Software Secure Workload
Activity Configure

Enforcement Status

To view enforcement status, click Defend > Enforcement Status in the navigation bar at the left side of the window.

This page is available for site admin/customer support users and scope owners to get an overview of the current status of all the enforcement agents, including the cloud connectors that are enforcing a policy.

If any of the charts shows red or orange, see the applicable topic:

Table 1. Enforcement Status Charts

Chart

Result

Take Action

Agent Enforcement Enabled

Not Enabled

Make sure enforcement is enabled in the agent configuration. See Create an Agent Configuration Profile.

Agent Policy Config

Stale Policies

This situation is generally temporary and typically doesn’t require any action. It occurs because a Secure Workload deployment based on labels updates inventory and policies dynamically.

However, if this situation persists for any individual workloads, contact Cisco TAC.

Agent Concrete Policies

Skipped

This indicates that policies weren’t pushed to some agents.


 
  • To view status for individual scopes or for the entire tenant, use the Filter by Scope option at the top-left side of the page.

  • If the charts indicate a problem, identify which workloads have the problem by clicking the relevant part of a chart.

    The table displays the affected workloads.

    Alternatively, to see filtering options, click the (i) button in the Filter box below the charts.

  • To view a wealth of additional details, click the IP address link in the filtered list of workloads to display the Workload Profile page.

The following table describes the fields shown in the enforcement status table.

Field

Description

Host Name

Host name of the workload.

Address

IP addresses of all the interfaces on the workload.

Enforcement Enabled

Indicates whether enforcement is enabled or not on the agent.

Concrete Policies in Sync

This indicates whether the desired version of concrete policies are currently enforced on the agent.

Concrete Policies

If this value shows Skipped for any host, this means the limit on policies is reached for the agent on that host. (See Limits Related to Policies.)

Policy Count

The number of concrete policies on the agent.

Status

The status of the latest policy config enforcement. If the status is CONFIG_SUCCESS, it indicates that current version is enforced without any issue.