Troubleshoot health status failures

You can run a health status check to review the overall health of Security Connector. If Security Connector is offline, this process pinpoints where a failure is occurring. If you cannot resolve an issue, contact ‚ÄčAkamai‚Äč Support.

This table describes Security Connector operations that are checked and the mitigation steps that are suggested to resolve a failure:

OperationDescriptionResolution to Failure
AMG ActivationIndicates whether Security Connector was successfully activated.Confirm that:

  • Security Connector is activated. To activate Security Connector, see Activate the security connector.

  • Run a connectivity test in the Security Connector network diagnostics to identify the connectivity issue that is causing this failure. For more information, see Run a connectivity test.
AMG ConnectivityIndicates whether Security Connector can connect to ‚ÄčAkamai‚Äč.Confirm that:

  • Security Connector is activated. To activate Security Connector, see Activate the security connector.

  • Run a connectivity test in the Security Connector network diagnostics to identify the connectivity issue that is causing this failure. For more information, see Run a connectivity test.
CAS Key RotationSecurity Connector backend service.Confirm that:

  • Security Connector is activated. To activate Security Connector, see Activate the security connector.

  • Run a connectivity test in the Security Connector network diagnostics to identify the connectivity issue that is causing this failure. For more information, see Run a connectivity test.
CAS RegistrationSecurity Connector backend service that is responsible for activation.Confirm that:

  • Security Connector is activated. To activate Security Connector, see Activate the security connector.

  • Run a connectivity test in the Security Connector network diagnostics to identify the connectivity issue that is causing this failure. For more information, see Run a connectivity test.
CAS ReportingBackend service that‚Äôs responsible for ‚ÄčSIA‚Äč Reports.Confirm that:

  • Security Connector is activated. To activate Security Connector, see Activate the security connector.

  • Run a connectivity test in the Security Connector network diagnostics to identify the connectivity issue that is causing this failure. For more information, see Run a connectivity test.
CSI Authentication TokenToken that‚Äôs used to deliver logs and data to ‚ÄčSIA‚Äč reports.Confirm that:

  • Security Connector is allowed to access ‚ÄčAkamai‚Äč Cloud services over port 443.

  • Security Connector can reach the CSI service. You can run a ping test with the CSI service hostname. To find this hostname, see View debug information. To perform a ping test, see Run a Ping test.
CSI Log PostingService that‚Äôs used to deliver logs and data to ‚ÄčSIA‚Äč reports.Confirm that:

  • Security Connector is allowed to access ‚ÄčAkamai‚Äč
    Cloud services over port 443.

  • Security Connector can reach the CSI service. You can run a ping test with the CSI service hostname. To find this hostname, see View debug information. To perform a ping test, see Run a Ping test.
CPU LoadOperation that tracks the overall traffic load of Security Connector.
  • Verify the configuration to check if only risky domains are sent to Security Connector for IP attribution.

  • Verify if any test traffic is directed to the Security Connector IP address.
Disk UseOperation that tracks disk space of the Security Connector VM.
  • Verify the configuration to check if only risky domains are sent to Security Connector for IP attribution.

  • Verify if any test traffic is directed to the Security Connector IP address.

  • Review the logging mode of the Security Connector web console.
NTP SyncOperation for Network Time Protocol synchronization.Confirm that your firewall is not blocking UDP port 123.
Web Console CertificateOperation for checking whether the Web Console Certificate is validConfirm that:
  • The root CA is installed on the device that‚Äôs used to access the Security Connector Web Console.
  • Security Connector is activated.
  • The browser supports signed Elliptic Curve Digital Signature Algorithm (ECDSA) certificates.

View Security Connector health status

You can check the overall health of Security Connector. If Security Connector is offline, this area of the console allows you to identify the operation where the failure occurred.

To view Security Connector health status:

  1. In the Security Connector main menu, press 6 or use the arrow keys to select View Health Status and then press Enter. Security Connector performs the health check.
  2. If a failure occurs, see Health status check for more information on how to resolve the issue.