Monitor the passive identity agent

The passive identity agent indicates whether or not it can communicate with the Security Cloud Control and other agents if it's configured as primary-secondary. View the status at Integrations > Identity > Identity Sources.

Deployments

A standalone passive identity agent is represented as follows.

A diagram illustrating the representation of standalone deployments and primary-secondary pairs, along with a table explaining the meaning of the indicators.

A primary-secondary pair is represented as follows.

The diagram illustrates the representation of standalone deployments and primary-secondary pairs, along with a table explaining the meaning of various indicators.

This table explains the meaning of the indicators.

Object

Meaning

The primary-secondary pair is illustrated, showing the relationship between the two components and their respective indicators. The accompanying table provides definitions for each indicator.

Cloud-Delivered Firewall Management Center

The image illustrates a standalone monitoring system setup, highlighting the key components and their interconnections for effective performance tracking.

Standalone Passive Identity Agent

The image illustrates a standalone Active Directory domain controller setup, highlighting its role in managing user authentication and directory services within a network.

Active Directory domain controller

The image illustrates the configuration of a standalone Active Directory domain controller, highlighting its role as the primary agent in the network setup.

Primary agent

The image illustrates the roles of the primary and secondary agents in an Active Directory domain controller setup, highlighting their status indicators and associated colors.

Secondary agent

Status indicators and colors

The passive identity agent indicates status using lines (that indicate whether communication with the Cloud-Delivered Firewall Management Center is active or standby) and colors (that indicate whether or not communication is successful).

This table explains the meanings of lines and colors:

Object

Meaning

Solid line

The agent that is responsible for communicating with the Cloud-Delivered Firewall Management Center.

Dashed line

Primary/secondary configuration only. The agent that is acting as the backup agent. In the event of a communication failure between the active (solid line) agent, this agent communicates with the Cloud-Delivered Firewall Management Center.

Blue

The status indicators show that both the green and blue agents are communicating normally, while the amber indicator requires further attention.

Agent communication is normal.

Amber

The status indicators show that both the green and blue agents are communicating normally, while the amber indicator requires further attention.

Agent has never successfully communicated with the Cloud-Delivered Firewall Management Center. A newly created agent line is amber and remains so until configuration is complete.

Red

The agent line status indicator shows amber for newly created agents, indicating that configuration is incomplete, while a red status signifies communication failure.

Communication is failing. To resolve the issues:

  • Verify the network connections between agents and the Cloud-Delivered Firewall Management Center.

  • Complete the configuration for the system (Microsoft AD server, domain controllers, and the Cloud-Delivered Firewall Management Center).

    For more information, see Create a passive identity agent identity source.