Skip to main content
Scheduled maintenance is planned for Meraki Product Documentation on Saturday, October 26th. Maintenance will begin at 11:59 PM, Pacific Time, and is expected to last three hours. Documentation will be unavailable during this time.
Cisco Meraki Documentation

Thousand Eyes Integration with Secure Connect

Overview

ThousandEyes is a comprehensive platform that provides deep visibility into customers' applications and WAN infrastructure. By leveraging active monitoring through various protocols, ThousandEyes effectively tracks application and WAN performance. The integration with Cisco Meraki MX appliances allows for the rapid and efficient activation of ThousandEyes agents, delivering unmatched speed, scale, and operational efficiency.

This solution is specifically designed to offer Meraki customers an effortless way to monitor the performance of web applications and WAN links within their network. It enables the quick identification of issues, whether they stem from the network (LAN or WAN) or the application server.

With the ThousandEyes integration, customers gain enhanced visibility and alerting capabilities. This allows for the creation of customized network and application tests for critical applications, whether they are inside or outside their infrastructure. For more detailed information, please refer to the Meraki MX ThousandEyes Configuration Guide.

 

ThousandEyes Agent behind Web Proxy

A web proxy acts as an intermediary server that handles requests between a client and the internet, providing anonymity, content filtering, and access to restricted sites. In Secure Connect, the Secure Web Gateway (SWG) performs SSL/HTTPS decryption and inspection, offering essential visibility and security for encrypted web traffic. For decryption, the web proxy must recognize the certificate used to encrypt the traffic.

ThousandEyes agents use their own certificates to communicate with the ThousandEyes cloud, which are not recognized by the Secure Web Gateway (SWG). This can result in some unexpected behaviour with ThousandEyes control traffic. To mitigate this issue, it is recommended to bypass ThousandEyes control traffic from HTTPS inspection.

Web Policy Selective Decryption List

Selective decryption in Web Policy refers to the ability to decrypt only specific HTTPS traffic based on predefined criteria. these are the spepst to enable it.

Navigate to Secure Connect > Web Policy and open Umbrella Dashboard  Policies > Policy components > Selective Decryption Lists.

  • Select Add
  • Create a Name and select ADD under  Domains
  • Add following domains and click Save 
  • data.eb.thousandeyes.com
  • data.eb.eu1.thousandeyes.com
  • c1.eb.thousandeyes.com
  • c1.eb.eu1.thousandeyes.com
  • registry.meraki-applications.com

Screenshot 2024-10-18 at 9.33.29 AM.png

 

Web Policy HTTPS Inspection

Navigate to Secure Connect > Web Policy. This will open Umbrella Dashboard  Policies > Management > Web Policy.

  • Select Web Policy to configure 
  • Select Edit under HTTPS Inspection Rulset settings

Screenshot 2024-10-18 at 9.38.42 AM.png

 

  • Select Enable HTTPS Inspection and select selective decryption list previously created.

 

Screenshot 2024-10-18 at 9.40.48 AM.png

  • Was this article helpful?