Use Cloud Tracer to diagnose multi-cloud network connectivity and security policy issues with real-time, hop-by-hop path visibility.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS AI Runtime Security
|
|
Cloud Tracer gives you real-time visibility
into how traffic moves within a single cloud, across regions, or spanning multiple
clouds. Trace the exact hop-by-hop path between any two endpoints with detailed
visualizations directly in Strata Cloud Manager. Instantly spot where
connectivity breaks—whether it is a misconfigured route, a firewall drop, or a
security policy violation.
With this release, Cloud Tracer supports:
- Azure and cross-cloud AWS-to-Azure tracing
- Full inline Palo Alto Networks firewall policy evaluation at the firewall hop
- Broader security policy coverage including security groups, network access
control lists (NACLs), and network security groups (NSGs) evaluated at every
applicable hop along the path
Cloud Tracer always shows the full end-to-end path as long as a route exists. Even if
a security policy denies traffic at a hop, the trace continues to show every hop
that would have been traversed.
The trace may
fail when a route is missing; a full, end-to-end trace occurs as long as the
route exists.
The hop where traffic was denied is clearly marked with a drop indicator and the
specific reason—whether it is a firewall policy name, a NACL rule number, or an NSG
rule—so you know not just that traffic was blocked, but exactly where and why.