Troubleshooting
Trace a failed connection from endpoint to application.
Trace the path#
- Device: confirm supported platform, completed authentication, active lifecycle, current connection, and fresh posture.
- Gateway: confirm Online status, supported version, and reachability to the application.
- Service: confirm destination, protocol, port, and serving gateways. Edit and save to remove revoked gateway references.
- Access: confirm deliberate subject and gateway scopes, at least one service, priority, and revision. Remove unsupported time or source-IP conditions.
- Posture: confirm an enforcing mode and blocking action are not rejecting the endpoint.
- Firewall: check ordered gateway rules and application status. Single-rule simulation is advisory only.
- Evidence: run Policy Simulation, then filter Security → Audit around the failure time.
For Secure Web, confirm traffic uses a PulseHA egress path, filtering is enabled, and encrypted DNS is handled. Linux receives no explicit proxy configuration.
For Orbit, confirm it is enabled, the region is allowed, and egress policy selects it.
If evidence reaches the Audit result cap, narrow the category and time range before exporting the current page.