Five ways to avert issues with BlueCat LiveAssurance

By flagging and notifying you of hidden issues before they cause damage, you can go from reactive to proactive in your Integrity DDI environment.

Futuristic data center aisle with server racks and glowing blue circuit-like network lines reflecting on the floor
Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

The article explains BlueCat LiveAssurance (BCIA), a proactive monitoring and automation solution for BlueCat Integrity enterprise DDI (DNS, DHCP, and IPAM) environments that helps detect hidden issues before they cause outages. It describes real-world problems such as disabled backups, configuration drifts, connectivity breaks between Address Manager and BDDSes, and high-availability (xHA) failures that can lead to instability or downtime, and shows how LiveAssurance continuously checks components, flags specific alerts, and provides remediation guidance. Outcomes include earlier detection of risks (connectivity, backups, xHA, config drift, SSL expirations, kernel limits, PNA buildup), reduced reactive firefighting, and planned expansion of proactive alerts with customer input via the Network VIP Slack channel.

How does LiveAssurance detect connectivity problems between Address Manager and BDDSes and what alerts will I see?

LiveAssurance continuously interrogates the Integrity environment to verify communication paths between Address Manager and BDDSes, surfacing early warning signs when expected connectivity is broken. It issues specific connectivity alerts such as: connectivity broken between the two DHCP failover servers, communication from Address Manager to BDDSes not working, and communication from BDDSes to Address Manager not working. These alerts let admins identify whether failures stem from the DDI components themselves or from external changes (for example firewall policy changes) so they can take corrective action before DNS/DHCP deployments or failover processes are impacted.

What backup-related failures does LiveAssurance monitor for, and why are those checks important?

LiveAssurance monitors the full backup posture for Address Manager and BDDS components to ensure recoverability if a failure occurs, because you are only as safe as your last successful backup. It flags conditions such as backup not configured, backup disabled, backup failed due to another backup process running, backup using an insecure protocol, local backup failed, remote backup failed, and remote backup not configured. These alerts help prevent prolonged unnoticed backup failures so administrators can quickly re-enable, reconfigure, or secure backup routines and avoid situations where restoration is attempted and no valid backup is available.

How does LiveAssurance help with high availability and configuration drift in Integrity environments?

LiveAssurance provides targeted checks and alerts to validate high-availability (xHA) and to detect configuration drift between Address Manager and local BDDS configurations. For xHA it monitors database replication status and latency, xHA backbone configuration, and DHCP failover states, issuing alerts like database replication disabled/stopped, replication latency nearing warning/critical, xHA backbone overlapping or interface not configured, xHA failover detected, and DHCP failover cluster or server down. For config drift it issues a ‘config drift detected’ alert comparing Address Manager and BDDS configs and highlights discrepancies (for example NTP differences) that can cause issues like failed zone transfers, enabling admins to reconcile settings before service degradation occurs.

From disabled backups to configuration drifts, many types of disruptions can slow your network down or even bring it to a grinding halt. For example, drifts away from standard configurations among network devices, perhaps the result of ad hoc changes, can lead to erratic network behavior, instability, or even downtime.

Warning signs of these disruptions to your DNS, DHCP, and IP address management (together known as DDI) environment often lurk undetected. If you can proactively identify and address these hidden issues, configuration errors, and forgotten maintenance tasks before they escalate, you can avoid much bigger headaches down the road.

But how? It’s a tall order for network admins to catch all of this. For BlueCat Integrity enterprise customers, BlueCat LiveAssurance provides proactive monitoring to root out hidden issues in your DDI environment, along with recommended steps to address them.

In this post, we’ll explain what BlueCat LiveAssurance (BCIA) is, and then delve into five ways that the platform can help you go from reactive to proactive in your Integrity environment. Finally, we’ll briefly highlight what’s to come in future releases and how you can contribute to the conversation.

What is BlueCat LiveAssurance?

The result of BlueCat’s acquisition of Indeni, BlueCat LiveAssurance (BCIA) is a proactive monitoring and automation solution. Think of it as a virtual DDI expert, on duty 24/7.

LiveAssurance provides deep visibility into BlueCat Integrity enterprise environments, including its key BlueCat Address Manager and BlueCat DNS/DHCP Server (BDDS) components, to flag early warning signs of issues. With our domain expertise codified into BlueCat LiveAssurance, the platform knows what to look for, interrogating your systems to ensure they are healthy. This includes knowledge of capabilities and features of the BlueCat implementation of DDI and its entire management layer.

A diagram of how BlueCat LiveAssurance provides deep visibility into BlueCat Integrity enterprise environments, including its key BlueCat Address Manager and BlueCat DNS/DHCP Server (BDDS) components

Should it find something, the platform proactively alerts customers that there might be a service failure—or any level of degradation of service—coming. And it provides a list of recommended remediation steps that admins can use as a guide to help address the problem.

Five ways to go from reactive to proactive with LiveAssurance

For BlueCat Integrity enterprise customers, moving beyond the reactive mindset when things go awry is now within reach. Below, we explore five examples of issues you might encounter in your DDI environment and how BlueCat LiveAssurance (BCIA) can help you identify and address them before they wreak havoc on your network.

Continuously check for Address Manager and BDDS connectivity

Address Manager or BDDSes are often not the cause of many issues. Instead, changes in other devices within the broader networking environment are often the culprit.

For example, someone made a firewall policy change and inadvertently broke the connection between Address Manager and your BDDSes. With LiveAssurance, you can continuously check for connectivity among critical components to ensure successful DNS deployments or successful failover.

With LiveAssurance, you can receive the following connectivity-related alerts:

  • Connectivity broken between the two DHCP failover servers
  • Communication from Address Manager to BDDSes not working
  • Communication from BDDSes to Address Manager not working

Ensure device backup is at the ready

Device backup is important to ensure that your DDI infrastructure is safe from failure and disruption. However, you are only as safe as your last successful backup. Many things can go wrong during a backup routine that can result in a failure. There’s always a chance that no one notices for an extended period of time that something failed until restoration is actually needed.

With LiveAssurance, you can receive the following backup-related alerts:

  • Backup is not configured
  • Backup is disabled
  • Backup failed—another backup process is running
  • Backup is using insecure protocol
  • Local backup failed
  • Remote backup failed
  • Remote backup is not configured

Optimize your crossover high availability configuration

Using a high availability configuration ensures your services are always available.

For Integrity, BlueCat crossover high availability (xHA) enables two BDDSes to function as a single server; when one fails, the other takes over to ensure service uptime.

Numerous alerts available in LiveAssurance help ensure seamless xHA. For example, it flags when the xHA configuration is not synchronized or notifies you when a DHCP failover state changes. Checks also ensure successful database replication.

With LiveAssurance, you can receive the following alerts related to high availability:

  • Database replication is disabled
  • Database replication stopped
  • Database replication latency nearing critical limit
  • Database replication latency nearing warning limit
  • xHA backbone is overlapping
  • xHA backbone interface not configured
  • xHA failover detected
  • DHCP failover detected
  • One DHCP failover server down
  • DHCP failover cluster down

Flag configuration drifts

Whether they are intentional or not, configuration drifts can sometimes cause problems in your network environment. Notifications about drifts can improve network resilience and prevent unexpected downtime or service degradation.

Our new ‘config drift detected’ alert compares the Address Manager configuration and the local BDDS configuration to notify you of discrepancies.

For example, NTP, the protocol that synchronizes network clocks, is an important component of healthy DNS. While DNS can handle a certain amount of clock drift, once you exceed its threshold, things can go awry. For example, zone transfers can begin to fail, leading to secondary DNS servers dropping the authoritative domains that they host.

Catch everything else you might have missed

Other proactive alerts cover easily forgotten but no less important network elements, like SSL certificate expiration. These alerts include:

  • Certificate(s) expiration nearing
  • Certificate(s) expired
  • Concurrent connects are too high
  • Kernel connection limit has been modified
  • Kernel connection tracking is nearing limit
  • Many pending PNA files on your BDDS (PNA files are notifications from BDDSes. There should only be one; if they are stacking up, there could be an issue.)

More proactive alerts in future releases

In future releases, you can expect to see more proactive alerts.

Want to share your favorite proactive alerts? Join Network VIP (NVIP), our space on Slack for networking professionals to network. You can jump on our #bcia-integrity channel to chime in with your favorites or offer up your thoughts about what you would like to see in our next release.


Published in:


An avatar of the author

Ulrica de Fort-Menares is the Vice President of Product Management for Infrastructure Assurance.

Related content

Close-up of interlocked metal chain links symbolizing connected network objects and relationships in IPAM

How to map your network with user-defined links in Integrity X

Map your network with user-defined links in Integrity X to define and manage custom relationships, such as dual-stack and NAT environments.

Read more
Flock of geese flying in formation across a blue sky, framed by a pink graphic border, symbolizing coordinated network migrat

Automate your DDI modernization path by migrating with Micetro

Automate cross-platform DNS and DHCP migration with Micetro to reduce risk, eliminate manual effort, and modernize infrastructure faster.

Read more
Three armored figures walking toward a futuristic Las Vegas skyline with pyramids, glowing orb, and "Welcome to Fabulous Las

Your journey to intelligent NetOps begins at Cisco Live

Visit BlueCat’s booth or book a meeting now to learn more about how our solutions can help you build a network that supports constant change.

Read more
Stacked colorful wooden directional arrows on a post by a calm seaside with distant hills and blue sky

Replace BIND and ISC with Micetro DNS/DHCP Server (MDDS)

Tired of patching and manually configuring BIND DNS and ISC DHCP? Discover how Micetro MDDS appliances can replace them for modern DDI.

Read more