Health Monitoring
This guide goes over the supported monitoring capabilities in MCF including Cloud Account Onboarding, Site Attachment (Hub/ Spoke), VPC Attachment.
Overview
This section defines the current customer-visible statuses of Site and VPC Regional Attachments, Sites, VPCs, cloud accounts, and Cloud Integrations. It is authoritative for what each status represents, its supported values, and the condition under which each current value applies.
Cloud integration status
Cloud Integration Status represents principal authentication and the aggregate Cloud Account Status of the integration's recorded scope. It is limited to access and permissions exercised while Cloud Integration discovers cloud resources.

| Cloud Integration status | Condition |
|---|---|
| Connected | Every cloud account in the integration's recorded scope is Connected. |
|
Degraded |
MCF can authenticate using the principal and either at least one scoped cloud account is Degraded or Access Lost, or an Azure or GCP principal has no accessible cloud accounts. |
|
Access Lost |
MCF cannot authenticate using the integration's principal. |
Cloud account integration
Cloud Account Status represents MCF's access to one cloud account and the permissions exercised while Cloud Integration discovers cloud resources. It does not confirm permissions used only by dependent workflows such as VPC Attachment.

| Cloud Account status | Condition |
| Connected | MCF can access the cloud account, and Cloud Integration > Synchronization has not detected a missing permission. |
| Degraded | MCF can access the cloud account, but Cloud Integration > Synchronization has detected one or more missing permissions. |
| Access Lost | MCF can no longer access the cloud account. |
AWS account

Azure account

GCP account

VPC
VPC status
VPC Status is a customer-visible classification of VPC onboarding, offboarding, and connectivity health. It follows the common precedence defined above.
Current VPC Attachment behavior creates one Regional Attachment for each VPC. While that Regional Attachment is Provisioned and offboarding has not been committed, VPC Status combines its current Connectivity Status and BGP Status. A feature that introduces multiple Regional Attachments for one VPC must define the resulting VPC Status rollup here.

| VPC status | Condition |
|---|---|
Not onboarded |
The VPC is known to MCF through Cloud Integration, has no Regional Attachments, and no active or unresolved onboarding or offboarding operation applies. |
Onboarding in progress |
VPC onboarding has been committed, its Regional Attachment is Provisioning, and no unresolved onboarding failure exists. |
Unknown |
The Regional Attachment is Provisioned,as offboarding has not been committed, and Connectivity Status or BGP Status is Unknown. |
Healthy |
The Regional Attachment is Provisioned, offboarding has not been committed, and Connectivity Status and BGP Status are both Healthy. |
Degraded |
The Regional Attachment is Provisioned, offboarding has not been committed, neither status is Unknown, and the statuses are neither both Healthy nor both Offline. |
Pending removal |
VPC offboarding has been committed, its Regional Attachment is Deprovisioning, and no unresolved offboarding failure exists. |
Offline |
An unresolved VPC onboarding or offboarding failure exists, or the Regional Attachment is Provisioned, offboarding has not been committed, and Connectivity Status and BGP Status are both Offline. |
Connectivity status
Connectivity Status is a customer-visible classification of aggregate IPsec tunnel availability for one VPC Regional Attachment whose state is Provisioned. Its current value summarizes the tunnels carried by the Regional Attachment.

| Connectivity status | Condition |
|---|---|
Unknown |
No IPsec tunnel is known to be Up, and MCF lacks sufficient current data to determine that every tunnel is Down. |
Healthy |
At least one IPsec tunnel carried by the Regional Attachment is Up. |
Degraded |
No current tunnel condition produces this value. VPC Connectivity Monitoring defines its use for historical intervals. |
Offline |
MCF has current status for every IPsec tunnel carried by the Regional Attachment, and every tunnel is Down. |
BGP status
BGP Status is a customer-visible classification of aggregate BGP route exchange for one VPC Regional Attachment whose state is Provisioned. Its current value summarizes the BGP sessions carried by the Regional Attachment.
| BGP status | Condition |
|---|---|
Unknown |
No BGP session is known to be Established, and MCF lacks sufficient current data to determine that no session is Established. |
Healthy |
At least one BGP session carried by the Regional Attachment is Established. |
Degraded |
No current BGP session condition produces this value. VPC Connectivity Monitoring defines its use for historical intervals. |
Offline |
MCF has current status for every BGP session carried by the Regional Attachment, and no session is Established. |
Site
Site status
Site Status is a customer-visible classification of Site onboarding, offboarding, and connectivity health. It follows the common precedence defined above.
Connectivity-derived Site Status begins after every Regional Attachment in the Site's initial scope is Provisioned, whether MCF created them through Site onboarding or Automatic Hub Management. It aggregates the current Connectivity Status and BGP Status of those Regional Attachments.
For an already onboarded hub Site, a Regional Attachment added by Automatic Hub Management is excluded from Site Status while its state is Provisioning and included after its state becomes Provisioned. Automatic provisioning does not produce Site Status Onboarding in progress because no Site onboarding action occurred.
| Site status | Condition |
|---|---|
Not onboarded |
The Site has no Regional Attachments, and no active or unresolved onboarding or offboarding operation applies. |
Onboarding in progress |
Site onboarding has been committed, at least one Regional Attachment in its committed scope is Provisioning, and no unresolved onboarding failure exists. |
Unknown |
Connectivity-derived Site Status applies, and every included Regional Attachment has both Connectivity Status and BGP Status Unknown. |
Healthy |
Connectivity-derived Site Status applies, and at least one included Regional Attachment has both Connectivity Status and BGP Status Healthy. |
Degraded |
Connectivity-derived Site Status applies, and the conditions for Unknown, Healthy, and Offline do not apply. |
Pending removal |
Site offboarding has been committed, at least one Regional Attachment is Deprovisioning, and no unresolved offboarding failure exists. |
Offline |
An unresolved Site onboarding or offboarding failure exists, or connectivity-derived Site Status applies and every included Regional Attachment has both Connectivity Status and BGP Status Offline. |
Connectivity status

Connectivity Status is a customer-visible classification of aggregate AutoVPN tunnel availability for one Site Regional Attachment whose state is Provisioned. Its current value summarizes the AutoVPN tunnels carried by the Regional Attachment.
| Connectivity status | Condition |
|---|---|
Unknown |
No AutoVPN tunnel is known to be Up, and MCF lacks sufficient current data to determine that every tunnel is Down. |
Healthy |
At least one AutoVPN tunnel carried by the Regional Attachment is Up. |
Degraded |
No current tunnel condition produces this value. Site Connectivity Monitoring defines its use for historical intervals. |
Offline |
MCF has current status for every AutoVPN tunnel carried by the Regional Attachment, and every tunnel is Down. |
BGP status
BGP Status is a customer-visible classification of aggregate BGP route exchange for one Site Regional Attachment whose state is Provisioned. Its current value summarizes the BGP sessions carried by the Regional Attachment.
| BGP status | Condition |
|---|---|
Unknown |
No BGP session is known to be Established, and MCF lacks sufficient current data to determine that no session is Established. |
Healthy |
At least one BGP session carried by the Regional Attachment is Established. |
Degraded |
No current BGP session condition produces this value. Site Connectivity Monitoring defines its use for historical intervals. |
Offline |
MCF has current status for every BGP session carried by the Regional Attachment, and no session is Established. |

How MCF determines Site and VPC Status
MCF reports provisioning and connectivity separately:
- Regional Attachment State indicates whether one Regional Attachment is being created, has been created, or is being removed. Product Terminology defines its values.
- While a Regional Attachment is
Provisioned, MCF evaluates whether its tunnels and BGP sessions are working. Site and VPC Regional Attachments use Connectivity Status and BGP Status. - Site Status and VPC Status combine this information into the overall status shown for the Site or VPC.
When more than one condition applies, MCF determines the overall status in this order:
- An unresolved onboarding or offboarding failure produces
Offline. - Onboarding in progress produces
Onboarding in progress. - Offboarding in progress produces
Pending removal. - Otherwise, the Regional Attachments' connectivity statuses determine the Site or VPC Status.
A Site or VPC with no Regional Attachments and no active or unresolved onboarding or offboarding operation is Not onboarded.
A failed provisioning or deprovisioning attempt does not create another Regional Attachment State. It affects the Site or VPC Status until a later attempt succeeds or an authorized recovery resolves the failure.


