Enforcement Status
To view enforcement status, click
in the navigation bar at the left side of the window.This page is available for site admin/customer support users and scope owners to get an overview of the current status of all the enforcement agents, including the cloud connectors that are enforcing a policy.
If any of the charts shows red or orange, see the applicable topic:
Chart |
Result |
Take Action |
---|---|---|
Agent Enforcement Enabled |
Not Enabled |
Make sure enforcement is enabled in the agent configuration. See Create an Agent Configuration Profile. |
Agent Policy Config |
Stale Policies |
This situation is generally temporary and typically doesn’t require any action. It occurs because a Secure Workload deployment based on labels updates inventory and policies dynamically. However, if this situation persists for any individual workloads, contact Cisco TAC. |
Agent Concrete Policies |
Skipped |
This indicates that policies weren’t pushed to some agents.
|
|
|
The following table describes the fields shown in the enforcement status table.
Field |
Description |
Host Name |
Host name of the workload. |
Address |
IP addresses of all the interfaces on the workload. |
Enforcement Enabled |
Indicates whether enforcement is enabled or not on the agent. |
Concrete Policies in Sync |
This indicates whether the desired version of concrete policies are currently enforced on the agent. |
Concrete Policies |
If this value shows Skipped for any host, this means the limit on policies is reached for the agent on that host. (See Limits Related to Policies.) |
Policy Count |
The number of concrete policies on the agent. |
Status |
The status of the latest policy config enforcement. If the status is CONFIG_SUCCESS, it indicates that current version is enforced without any issue. |