Skip to main content

 

Cisco Meraki Documentation

Troubleshooting Cisco Secure Connect Account Setup

This article provides common troubleshooting steps to take when encountering an issue with setting up your Cisco Secure Connect account along with other common questions in relation to the Account and Meraki Organization mapping.

Overview

Setting up Cisco Secure Connect involves configuring your account and mapping it to a Meraki Organization. This troubleshooting article walks you through common issues you may encounter during this process and how to resolve them.  

Troubleshooting automatic API Key sync issue

New customers may encounter an error when attempting automated API key exchange for a new Umbrella org. Automated API key exchange is not supported for existing Umbrella orgs. The error appears as follows 

Screenshot 2023-06-21 at 9.06.11 PM.png

Troubleshooting steps 

  1. When the error appears, click the link highlighted in the error message. 

  1. Manually exchange the API keys by following the instructions on the page. Read more here.   

Troubleshooting multiple errors

Observed error: Network tunnels, Remote access, Users, Applications, Clientless (Browser-based) ZTNA access 

  • Errors on Overview page: "An error occurred while loading tunnels", " Error loading Remote access data"Screenshot 2023-08-22 at 12.48.59 PM.png
  • Error on Users page, no users present: "An error occurred while loading users"Screenshot 2023-08-22 at 12.49.13 PM.png
  • Error(s) on Browser Access page, potentially many per rule: "An error was encountered while loading browser access policy rule data" Screenshot 2023-08-22 at 12.49.35 PM.png
  • Errors on Applications page: "An error was encountered while loading applications.", "An error was encountered while loading application groups."Screenshot 2023-08-22 at 12.49.26 PM.png

Troubleshooting steps: Replace Management Key

For the errors above, replace the Umbrella Management key to address this issue. 

  1. Navigate to Secure Connect > License & API Keys

  2. On the Umbrella Management credentials card, select "Replace API credentials"
    Refresh Management Key copy.png
  3. Follow the link and instructions to retrieve a new key.
    Screenshot 2023-06-21 at 9.19.04 AM.png
  4. Select Link and Continue, then return to the Overview page to verify the fix. 

Observed error: Policies, Policy Overview 

  • Error on Overview page: "Failed to load all policy data" 
    Screenshot 2023-08-22 at 1.15.40 PM.png
  • Error on Policy Overview page: "Failed to load all policy data"
    Screenshot 2023-08-22 at 1.15.47 PM.png

Troubleshooting steps: Replace Network Devices Key

For the errors above, replace the Umbrella Network Devices key to address this issue. 

  1. Navigate to Secure Connect > License & API Keys
  2. On the Umbrella Network Devices credentials card, click on "Replace API credentials"Refresh Network Key copy.png
  3. Follow the link and instructions to retrieve a new key.
    Screenshot 2023-08-22 at 1.05.02 PM.png
  4. Click Link and Continue, return to the Overview page to verify the fix. 

Observed error: Remote access, Users, Browser access 

  • Errors on Overview page: " Error loading Remote access data" (Network tunnels have no errors)
    Screenshot 2023-08-22 at 1.13.14 PM.png
  • Error on Users page, no users present: "An error occurred while loading users" (Users are visible)Screenshot 2023-08-22 at 1.13.22 PM.png
  • Error(s) on Browser Access page, potentially many per rule: "Hit counts failed to load"Screenshot 2023-08-22 at 1.14.59 PM.png

Troubleshooting steps: Replace Reporting Key

For the errors above, replace the Umbrella Reporting key to address this issue. 

  1. Navigate to Secure Connect > License & API Keys
  2. On the Umbrella Reporting credentials card, click on "Replace API credentials"Refresh Reporting Key copy.png
  3. Follow the link and instructions to retrieve a new key.
    Screenshot 2023-08-22 at 1.00.19 PM.png
  4. Click Link and Continue, return to the Overview page to verify the fix. 

Check the data storage location

When an HTTP client request does not originate from the correct location of the Umbrella data warehouse, the Umbrella server returns a 302 Found response. This can manifest across multiple pages within Secure Connect.

To spot this issue:  

  1. Verify the location of data in the Meraki dashboard (at the bottom of any page):
     

  2. Verify the location of Data Storage in Umbrella (Admin > Log Management) 

  3. If the Meraki dashboard data location and the Umbrella data storage location are not aligned, follow these steps to correct the issue: https://docs.umbrella.com/deployment-umbrella/docs/log-to-a-data-warehouse 
    Correct region pairings:

    Region/Location Meraki Hosting Location Umbrella Storage Region
    North America United States North America - California, US
    South America United States North America - California, US
    Europe Europe - Germany Europe - Frankfurt, DE
    Asia Asia - Singapore, Australia Europe - Frankfurt, DE    

Secure Connect is not currently supported in the dashboards hosted in Canada, India, or China

Errors persist? Contact support.
If the two steps above have not resolved the issue, contact our support team. They'll have additional tools to troubleshoot. 

Re-sending the welcome email or changing the recipient address

To change or re-send the email account associated with Secure Connect, contact support.

When contacting support, include the following in the support case:

  • Subject line: Include "Secure Connect
  • Description: Include the following details from the order:
    • First Name, Last Name
    • Admin Email - Use the admin email that matches Umbrella org 
      • Use the email from the order, or
      • Use another email belonging to an admin in the Umbrella account, if others exist
    • Umbrella Org Id

Troubleshooting wrong Umbrella organization dashboard issue

If you linked a wrong Umbrella organization that is not enabled for Secure Connect to the dashboard, use the steps in this section to unlink the incorrect org and link the correct one. Relinking the correct org ensures the integration between the dashboard and Umbrella is properly established.

For account-related queries, activation issues, or additional troubleshooting, contact Secure Connect support directly. How to Contact Support

Symptoms of this issue:

  • Cannot go back in the API key exchange flow.
  • Cannot see the Secure Connect tab in the left navigation.

Prerequisites

  • If the Meraki org is new, create at least one network. This allows you to access the Cloud On-Ramps configuration, which is required to employ the workaround.
  • If you previously deployed any Umbrella SD-WAN Connector under the Organization > Cloud On-Ramps page > Deployments tab, delete all current Umbrella SD-WAN Deployments.

All sites enrolled in Secure Connect must be detached via the Secure Connect Sites page before unlinking the current Umbrella organization. Verify that the dashboard has deleted all Secure Connect Hub networks after branch sites were detached. Allow the Secure Connect and Umbrella systems sufficient time to complete the un-enrollment process and deletion of Secure Connect Hubs before making any changes to the linked Umbrella organization.    

Troubleshooting steps

To override the org mapping, replace any one API key:

  1.  Navigate to Organization > Cloud On-Ramps page.
  2. Under the Configuration tab of the Umbrella SD-WAN Connector > select the vertical ellipsis button (3 dots) > select Disconnect Umbrella to disconnect the current Umbrella org integration.

    cloud_on-ramps_disconnect_umb.png

  3. Obtain the correct API Keys from your correct Secure Connect enabled Umbrella organization. For more information, refer to our Secure Connect Onboarding KB – Setting Up Your Cisco Secure Connect Account.
  4. Follow the steps from the Secure Connect Welcome Email to activate Secure Connect for the dashboard. For more information, refer to the Secure Connect Onboarding KB – Setting Up Your Cisco Secure Connect Account.

Changing the Umbrella org mapping to a new Meraki Org

You can change the Umbrella org mapping and re-enter or regenerate API keys.

To change the mapping, contact Secure Connect support to clear the API keys from the Secure Connect dashboard. Once cleared, you can use or regenerate Umbrella API keys to map another org. Once complete, follow the appropriate onboarding guide here: Setting Up Your Cisco Secure Connect Account

Troubleshooting EA licensing grace period warning 

An organization with Secure Connect and Enterprise Agreement (EA) licensing has a warning in the Organization > Configure > Subscription and License Info page that Secure Connect Region networks do not have a subscription and will be disabled at the end of the licensing "Grace Period."

This warning will not affect the connectivity or management of Secure Connect or connected networks. You can consider this a cosmetic issue. 

12_33_54.jpg

Troubleshooting steps

To resolve the grace period warning:

  1. Navigate to Organization > Configure > Subscription and License Info.
  2. Bind the Secure Connect networks to your existing EA subscription.

Binding the Secure Connect networks removes the networks from their subscription-less state and does not consume any license seats.

Remove Secure Connect from a Meraki org

Meraki orgs with Secure Connect enabled cannot currently be deleted. They can be downgraded. The Umbrella org with Secure Connect license can be connected to a new org (see below). To wind-down a Secure Connect org for example one used in a trial, contact support.

 

Deleting a Meraki org with Secure Connect enabled

To delete a Meraki org that has had Secure Connect enabled, first follow the steps above to remove Secure Connect from a Meraki org. Then follow the steps to delete a Meraki org here:  https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Deleting_an_Organization  

 

Cannot complete setup after Umbrella and Meraki MR Auto integration

This issue occurs when the same admin user or email is used for MR-Advanced and Secure Connect accounts on MR Networks. When provisioning Secure Connect, an admin user who already has the MR-Advanced capability configured in any organization they control cannot see the Umbrella dashboard.

As noted in the documentation for Automatically Integrating Cisco Umbrella with Meraki Networks, this process is irreversible by a user. A single admin cannot manage multiple organizations that include a mix of MR-Advanced orgs automatically integrated with Umbrella and Secure Connect. 

If this applies to you, contact support for further assistance.

  • Was this article helpful?