Troubleshooting Agent Workflows
Diagnose connectivity failures, device health anomalies, and performance degradation
using the Troubleshooting Expert Agent in Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
|
|
- Strata Cloud Manager Pro
- This feature is currently in Beta and available on request.
Contact your account team to enable the feature.
- Superuser role for agent administration, onboarding, and
managing permissions
- Network Administrator or Security Administrator role for agent
interaction
|
This feature leverages a large language model or
generative AI, and may contain errors. Double-check for accuracy before applying
changes.
The Troubleshooting Expert Agent diagnoses connectivity failures, device health
anomalies, and performance degradation across your network security infrastructure. When
users report access issues or monitoring systems detect anomalies, this agent correlates
data from multiple sources to identify the root cause and generate actionable
remediation steps.
Unlike manual troubleshooting that requires you to check multiple dashboards and
cross-reference logs, the Troubleshooting Agent automates the diagnostic workflow
end-to-end. It retrieves relevant telemetry, applies correlation logic, and presents
findings in a structured report that includes both the identified root cause and specific
remediation actions you can approve for execution.
Supported Workflows
| Workflow | Trigger | Description |
| Remote Network (IPSec VPN) Connectivity | NLQ, UI Click | Troubleshoot IPSec VPN tunnel failures for remote network
connections, including IKE negotiation and routing issues. |
| Service Connection (IPSec VPN) Connectivity | NLQ, UI Click | Diagnose service connection tunnel issues between Prisma Access and
on-premises infrastructure. |
| Prisma SD-WAN Troubleshooting | NLQ, UI Click, Incident | Root-cause SD-WAN branch connectivity failures, path quality
degradation, and failover issues. |
| GlobalProtect App Connectivity | NLQ, UI Click | Diagnose GlobalProtect app connection failures including
authentication, portal/gateway selection, and tunnel
establishment. |
| ADEM Diagnostics | NLQ, UI Click | Leverage ADEM data to diagnose end-user experience issues and
network path problems. |
Trigger abbreviations: NLQ = natural language query through Strata Copilot; UI Click =
contextual prompt on a Strata Cloud Manager page; Incident = automatic response to a
Strata Cloud Manager incident.
Common Invocation Examples
| Query | What It Does |
| @agent/troubleshooting Why can't user john.doe access Salesforce? | Correlates ADEM data, traffic logs, and policy rules to identify the
root cause of the user's access failure. |
| @agent/troubleshooting Check tunnel status for branch-office-3 | Retrieves IPSec tunnel telemetry, IKE logs, and routing state for
the specified remote network. |
| @agent/troubleshooting My SD-WAN site is experiencing packet loss | Analyzes SD-WAN path metrics, SLA probes, and failover events to
identify the degradation source. |