Configure OpenConfig Streaming Telemetry
Before you begin
-
Ensure that the threat defense device where you want to deploy the health policy configuration allows installation of the SSL certificate and private key.
-
Ensure that you configure a gNMI client that supports the OpenConfig streaming telemetry implementation, from which you can make the gRPC requests to the gNMI server on the threat defense.
-
To use dial-out mode and configure OpenConfig streaming telemetry, ensure that you configure a gRPC tunnel server and client on the management system. This tunnel configuration enables communication between the gNMI client and the threat defense device.
-
You must be an admin user to perform the following task.
Procedure
Step 1 | Choose . |
Step 2 | Click the Edit health policy icon next to the threat defense health policy that you want to modify. |
Step 3 | Go to Settings tab. |
Step 4 | Move the OpenConfig Streaming Telemetry slider to enable the configuration. This configuration is disabled by default. |
Step 5 | Upload the SSL Certificate. The gNMI server uses this certificate to enable server authentication for the TLS connection and encrypt all communications through the channel. The OpenConfig streaming telemetry configuration supports only certificate with PEM format. |
Step 6 | (Optional) Specify the Passphrase if the private key files are encrypted. |
Step 7 | Choose the deployment mode to use for streaming telemetry over gNMI protocol. For DIAL-IN mode:
For DIAL-OUT mode:
|
Step 8 | Specify the username and password to validate the gNMI collector. The threat
defense server uses this credential to authenticate the gNMI collector when
receiving the |
Step 9 | Click Save. |
What to do next
Deploy the health policy to your threat defense device, for the configuration changes to take effect.