Monitor zero trust sessions

This task enables administrators to effectively monitor Zero Trust Application Policy sessions through multiple methods including connection events, dashboard visualization, CLI commands, and diagnostic troubleshooting tools.

After a Zero Trust Application Policy is deployed, additional monitoring capabilities become available to track session activity, user behavior, and system performance. To monitor the zero trust sessions, do these steps.

Procedure


Step 1

Add Zero Trust fields to the connection events table view.

  1. Choose Events & Logs > + Show more > Connection > Events.

  2. Click the Table View of Connection Events tab.

  3. In the table view of events, multiple fields are hidden by default. To change the fields that are displayed, click the x icon in any column name to display a field selector.

  4. Select these fields:

    • Authentication Source

    • Zero Trust Application

    • Zero Trust Application Group

    • Zero Trust Application Policy

    • Zero Trust Application Host

    • Zero Trust Origin User

    • Zero Trust Proxy

    • Zero Trust Rule

    • Zero Trust Status

    • Zero Trust Tunnel ID

  5. Click Apply.

See Connection and Security-Related Connection Events in the Secure Firewall Management Center Administration Guide for more information on the connection events.

Step 2

Access the Zero Trust dashboard to monitor real-time session data.

The Zero Trust dashboard provides a summary of the top zero trust applications and zero trust users that are managed by the management center.

Choose Insights & Reports > Dashboard, and click the Zero Trust tab to access the dashboard.

The dashboard has the following widgets:

  • Top Zero Trust Applications

  • Top Zero Trust Users

Step 3

Use CLI commands to monitor and troubleshoot Zero Trust configurations.

Log in to the device CLI and use the following commands:

CLI Command

Description

show running-config zero-trust

View the running configuration for a zero trust configuration.

show running-config zero-trust-hybrid

View the running configuration for a universal zero trust configuration.

show zero-trust

Display the run-time zero trust statistics and session information.

show cluster zero-trust

Display the summary of zero trust statistics across nodes in a cluster.

clear zero-trust

Clear zero trust sessions and statistics.

show counters protocol zero_trust

View the counters that are hit for zero trust flow.

Step 4

Run diagnostic tools to troubleshoot Zero Trust configuration issues.

The diagnostics tool facilitates the troubleshooting process by detecting possible issues with zero trust configurations. The diagnostics can be classified into two types:

  • Application-specific diagnostics are used to detect issues such as:

    • DNS-related issues

    • Misconfigurations such as socket not open, and issues with classification and NAT rules.

    • Issues with deployment of zero trust policy or SSL rules

    • Issues with source NAT issues and exhaustion of PAT pool

  • General diagnostics are used to detect issues such as:

    • Strong cipher license not enabled

    • Invalid application certificate

    • SAML-related issues

    • Home agent and cluster bulk sync issues

  1. Click Diagnostics (The image illustrates the process of monitoring zero trust sessions, highlighting key diagnostic steps and options available in the Diagnostics dialog box for troubleshooting application issues.) next to the zero trust application that you want to troubleshoot. The Diagnostics dialog box appears.

  2. Choose the device from the Select Device drop-down list and click Run. A report is generated in the Reports tab after the diagnostic process is complete.

  3. To view, copy, or download the logs, click the Logs tab.


You have successfully configured comprehensive monitoring for Zero Trust sessions. The connection events table now displays Zero Trust-specific fields, the dashboard provides real-time visualization of top applications and users, CLI commands are available for detailed system monitoring, and diagnostic tools can identify and troubleshoot configuration issues.