Path Analysis
Path Analysis evaluates how traffic would move across your modeled network, based on the configuration and state collected from your devices.
Each result shows every device and interface a packet would traverse, the forwarding and policy decisions applied at each hop, and the configuration or state that drove each decision.
In This Section
| Page | What it covers |
|---|---|
| First Steps | Hands-on walkthrough of one complete query, with examples to try. |
| Overview | Concepts: modeled network, anchors, IP localization, path groups, scope. |
| Running Path Analysis | Building queries, anchors and constraints, filters, modes, common intents. |
| Understanding Results | Reading path groups, hops, outcomes, drop reasons, return paths, diffs. |
| Troubleshooting & FAQ | Symptom-keyed recipes for common path-search problems. |
| Reference | Tokens, outcomes, drop reasons, network functions, anchor resolution. |
| Layer-7 User-Group Filtering | Identity-based filters for queries against user-aware policies. |
| Layer-7 URL Filtering | URL filters for queries against URL-aware policies. |
Suggested Reading Order
- New to Path Analysis: read First Steps, then Overview, then Running Path Analysis as you build more involved queries.
- Already comfortable: jump to Running Path Analysis and Understanding Results.
- Looking up a token, outcome, or drop reason: go straight to Reference.
Related Applications
- Verify — automated intent checks built on Path Analysis (existence and isolation).
- Security → Blast Radius — destinations reachable from a given source.
- Security → Posture — effective reachability between zones.
- Topology — visualize and navigate the modeled network.