Health alerts for Secure Firewall 200 Series device

To optimize performance and ensure effective resource utilization, the health alerts in the Secure Firewall 200 Series device are limited only to the essential health modules. This table lists the health modules in the Secure Firewall 200 Series device, which generate health alerts. You can view all the metrics in the health monitoring dashboard, which is similar to that of other Threat Defense device models.

Health Alerts for Secure Firewall 200 Series Device

Health Module

Health Alert

Certificate Monitoring

Alerts when service authentication certificates are nearing expiration or have expired.

Cluster/HA Failure Status

Provide alerts when a device joins, leaves, or is elected as the primary unit.

Database

Provide alerts on database integrity issues related to schema or configuration data.

Disk Usage

Monitors disk usage in the device's hard drive and alerts when usage exceeds the configured thresholds.

Disk Status

Provide alerts on hard disk or RAID controller issues.

Firewall Threat Defense Platform Faults

Monitors platform faults and generates health alerts for them.

FXOS Health

Alerts when the FXOS HTTPS service is not running in the device.

Identity Process

Monitors the health and operation of identity-related services.

Identity Limits Monitor

Monitors the device for identity-related mapping limits and generates alerts when these limits are exceeded. The module generates alerts when these two specific types of limits exceed their normal value:

  • Number of mappings (user sessions, SXP, dynamic object) limit: Cumulative total of device identity-related mappings that include user sessions, SGT Exchange Protocol (SXP) mappings, and dynamic object mappings.

  • User/Group mappings limit: Total number of user-to-group mappings downloaded to the device.

For more information, refer to Identity-limits-monitor.

Inline Link Mismatch Alarms

Provide alerts if inline pair interfaces negotiate different speeds.

Interface Statistics

Determines if the device currently collects traffic and alerts based on the traffic status of physical interfaces and aggregate interfaces.

Out of band Configuration Changes

Alerts when there is a conflict between the existing Cloud-Delivered Firewall Management Center configuration and the out-of-band configuration changes that are made.

Process Status

Provide alerts when processes in the device are terminated outside of the process manager.

Snort Identity Memory Usage

Enables you to set a warning threshold for Snort identity processing, and alerts when memory usage exceeds the level that is configured for the module.

Snort Reconfiguring Detection

Alerts if a device reconfiguration has failed.

Threat Data Updates on Devices

Monitors updates of threat intelligence data and alerts if this information has not been updated in the devices within the time period you have specified.

Identity limits monitor

Secure Firewall 200 series devices enforce two independent download limits. The device supports a cumulative total of 10,000 user sessions, SXP/SGT mappings, endpoint profiles, and dynamic objects. Separately, it supports up to 10,000 user-group mappings. These limits operate independently; reaching the capacity for one category does not block downloads for the other. The device only stops downloading objects for the specific category that has reached its 10,000-object limit.

Consider some of these remediation measures:

  • Create identity mapping filters to limit the the networks to which an identity rule applies. Refer to "Create an identity mapping filter".

  • Set an ISE network filter to restrict the data that Cisco ISE reports to the Secure Firewall Management Center. For information, refer to "Activate the pxGrid Cloud identity source".

  • Configure realm inclusion and exclusion: When you configure realm to control user groups used in access control policies, you can explicitly select which user groups to download (Included Groups and Users field) and which to ignore (Excluded Groups and Users field). This selection lets you choose which user groups are downloaded. As a result, it limits the size of the user database on the device and optimizes resource utilization.

    For more information, refer to "Realm directory and synchronize fields".

Caution

Generating troubleshooting files in a Firewall Threat Defense device is a CPU-intensive task. Because of limited CPU resources in the Secure Firewall 200 Series device, you may observe higher CPU usage and associated health alerts during this process. To prevent any potential traffic disruption, it's recommended to generate troubleshooting files only when the device is not actively handling network traffic.

Note
  • The Secure Firewall 200 Series device raises alerts only for database integrity issues-related configuration data (sometimes called EO).

  • The Secure Firewall 200 Series device does not maintain a local URL database, and supports cloud-only URL lookups. Local URL database-related alerts are not available for this device type.