Thousand Eyes Integration with Secure Connect
Overview
ThousandEyes is a comprehensive platform that provides deep visibility into customers' applications and WAN infrastructure. By leveraging active monitoring through various protocols, ThousandEyes effectively tracks application and WAN performance. The integration with Cisco Meraki MX appliances allows for the rapid and efficient activation of ThousandEyes agents, delivering unmatched speed, scale, and operational efficiency.
This solution is specifically designed to offer Meraki customers an effortless way to monitor the performance of web applications and WAN links within their network. It enables the quick identification of issues, whether they stem from the network (LAN or WAN) or the application server.
With the ThousandEyes integration, customers gain enhanced visibility and alerting capabilities. This allows for the creation of customized network and application tests for critical applications, whether they are inside or outside their infrastructure. For more detailed information, please refer to the Meraki MX ThousandEyes Configuration Guide.
ThousandEyes Agent behind Web Proxy
A web proxy acts as an intermediary server that handles requests between a client and the internet, providing anonymity, content filtering, and access to restricted sites. In Secure Connect, the Secure Web Gateway (SWG) performs SSL/HTTPS decryption and inspection, offering essential visibility and security for encrypted web traffic. For decryption, the web proxy must recognize the certificate used to encrypt the traffic.
ThousandEyes agents use their own certificates to communicate with the ThousandEyes cloud, which are not recognized by the Secure Web Gateway (SWG). This can result in some unexpected behaviour with ThousandEyes control traffic. To mitigate this issue, it is recommended to bypass ThousandEyes control traffic from HTTPS inspection.
Web Policy Selective Decryption List
Selective decryption in Web Policy refers to the ability to decrypt only specific HTTPS traffic based on predefined criteria. these are the spepst to enable it.
Navigate to Secure Connect > Web Policy and open Umbrella Dashboard Policies > Policy components > Selective Decryption Lists.
- Select Add
- Create a Name and select ADD under Domains
- Add following domains and click Save
- data.eb.thousandeyes.com
- data.eb.eu1.thousandeyes.com
- c1.eb.thousandeyes.com
- c1.eb.eu1.thousandeyes.com
- registry.meraki-applications.com
Web Policy HTTPS Inspection
Navigate to Secure Connect > Web Policy. This will open Umbrella Dashboard Policies > Management > Web Policy.
- Select Web Policy to configure
- Select Edit under HTTPS Inspection Rulset settings
- Select Enable HTTPS Inspection and select selective decryption list previously created.