Diagnose Multi-Cloud Network Connectivity and Security Policy Issues
Focus
Focus
Prisma AIRS

Diagnose Multi-Cloud Network Connectivity and Security Policy Issues

Table of Contents

Diagnose Multi-Cloud Network Connectivity and Security Policy Issues

Learn how to use Cloud Tracer for tracing and debugging network paths.
Where Can I Use This?What Do I Need?
  • Prisma AIRS AI Runtime Security
You can diagnose multi-cloud network connectivity and security policy issues using Cloud Tracer. Cloud Tracer delivers real-time insights into network traffic paths and security policy enforcement within your cloud environments. It enables you to trace packet routes and diagnose connectivity issues.
The Cloud Tracer Service deploys and configures tracer parameters across your environment. You define trace parameters via the Visualization/Reporting Interface, which translates requests into actionable trace jobs. Agents then generate specialized trace packets, collecting hop-by-hop information. This system uses a distributed agent-based model with a centralized control plane, integrating with native cloud capabilities.
Tracer Agents establish secure, outbound connections to the Cloud Tracer Service to report telemetry. The Service communicates with the Data Store/Analytics Engine for persistent storage and analysis. This architecture provides granular, per-segment network visibility, and offers near real-time insights for issue resolution in your network.
This procedure guides you through deploying, configuring, and validating the Cloud Tracer feature within your environment.
  1. Log in to Strata Cloud Manager.
  2. Select InsightsCloud Network SecurityCloud Tracer.
    Click Run Trace to get started.
  3. In the Trace Parameters screen, enter the following information:
    1. In the Source section, specify the Cloud Provider and use the drop-down to select the corresponding Region, select the VPC/VNet and indicate the IP address, then enter the Source Port and optionally select the Protocol (for example, TCP, UDP, or ICMP).
    2. In the Destination section, use the drop-down to select the Region, choose the VPC/VNet and indicate the IP address, then enter the Destination Port.
  4. Enter a descriptive Deployment Name. This name helps identify the Cloud Tracer deployment for auditing and management. The field accepts alphanumeric characters and hyphens.
  5. Click Run.

Validate Cloud Tracer Installation and Operation

Use this procedure to validate Cloud Tracer operation:
  1. Select Cloud TracerStatus. This page provides an overview of deployed Cloud Tracer instances and their operational status.
  2. Verify the Status column for your Cloud Tracer instance shows Running. A Running status confirms successful deployment and active monitoring. Investigate any other status, such as Pending or Error.
  3. Perform a test trace to confirm active data collection:
    1. Select your deployed Cloud Tracer instance.
    2. Select Run Test Trace.
    3. Enter the Test Source IP (e.g., 192.168.1.15).
    4. Enter the Test Destination IP (e.g., 10.0.0.10).
    5. Select Initiate Trace.
  4. Review the initial trace results to confirm data visibility.
  5. Observe the Trace Path visualization, noting hops and devices.
  6. Check the Latency and Packet Loss metrics.
  7. Confirm trace data aligns with your network topology and expected traffic flow.