Monitor your VPN clusters by viewing the health status
of applications and links.
| Where Can I Use This? | What Do I Need? |
Monitor the application and link performance in your VPN clusters to troubleshoot issues by
viewing summary information across all VPN clusters and then successively drilling
down to isolate the issues to affected sites, applications, and links. Visibility on
SD-WAN traffic is shown on the SD-WAN firewall
receiving the traffic. For example, for traffic from the hub firewall to the branch
firewall, the SD-WAN monitoring data is reflected on the branch
firewall. The landing dashboard displays:
App Performance
Impacted—One or more applications in the VPN cluster
for which none of the paths have jitter, latency, or packet loss
performance that meet the specified thresholds in the Path Quality
Profile in the list of paths from which the firewall can choose.
OK—Number of VPN clusters, hubs, and branches that
are experiencing no jitter, latency, or packet loss performance
issues.
Link Performance
Error—One or more sites in the VPN cluster have connectivity
issues such as when a tunnel or a virtual interface (VIF) is
down.
Warning—Number of VPN clusters, hubs, and branches that have
links with
bandwidth
(supported in PAN-OS
11.1.5 and later with SD-WAN
plugin 3.2.2 and later
versions),
jitter, latency, or packet loss performance
measurements that exceed the moving seven-day average value of the
metric.
OK—Number of VPN clusters, hubs, and branches that are
experiencing no
bandwidth (supported
in PAN-OS
11.1.5 and later with SD-WAN
plugin 3.2.2 and later
versions),
jitter, latency, or packet loss performance
issues.
Beginning with
PAN-OS
11.1.5, SD-WAN
plugin 3.2.2 and later
versions
support 'bandwidth' which is the primary measure of the link
performance.
(SD-WAN plugin
2.0 and later versions) If a hub or branch firewall have
an SD-WAN policy rule configured with Forward Error Correction, an
Error Correction Initiated message is displayed to
notify you that the hub or branch firewall detected and corrected errors in
transmitted data for an application.
(
SD-WAN
plugin 2.0 and later versions)
SD-WAN
hubs display
Error Correction Initiated only if
traffic originated from the
SD-WAN hub to the
SD-WAN branch and matched an
SD-WAN policy rule with an
error correction profile attached.
From the landing
dashboard, narrow the view to impacted applications or links that have
the Error or Warning status. Then select an affected site to view
site-level details. From the site, view application-level or link-level
details.
If no data is present or the screen indicates that
SD-WAN is undefined, check in
the
Compatibility Matrix that the
Panorama release you are using supports the
SD-WAN
plugin release you are trying to use.