<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identify VPN downtimes or re-establishments in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246718#M41235</link>
    <description>&lt;P&gt;thank you so much &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt; !!!&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2025 03:35:46 GMT</pubDate>
    <dc:creator>TINTIN8</dc:creator>
    <dc:date>2025-04-17T03:35:46Z</dc:date>
    <item>
      <title>Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246709#M41229</link>
      <description>&lt;P&gt;Hi Gurus,&lt;/P&gt;&lt;P&gt;Is there any way to identify VPN disconnections/re-establishments looking at the log server logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ex—we get logs like"Child SA exchange: Exchange failed: timeout reached," but we're not sure what the logs mean. Can we identify, looking at the logs, that the VPN tunnel went down "this" time and reconnected "this" time, etc.?&lt;/P&gt;&lt;P&gt;Our partners say your tunnel went down during a "time period," but we can't really check our logs and determine what happened to the VPN tunnel. Did it go down? What time did it re-establish?&lt;/P&gt;&lt;P&gt;Any help to clear this is highly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 23:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246709#M41229</guid>
      <dc:creator>TINTIN8</dc:creator>
      <dc:date>2025-04-16T23:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246710#M41230</link>
      <description>&lt;P&gt;The best way I found to do this is look for "key install" in the logs.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 00:12:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246710#M41230</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-17T00:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246712#M41231</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;. However, this doesn't tell me what time the tunnel went down. I can see the Key install when the VPN gets re-established, but it still won't tell me what time it went down/disconnected, or was it in some kind of idle state.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 00:18:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246712#M41231</guid>
      <dc:creator>TINTIN8</dc:creator>
      <dc:date>2025-04-17T00:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246713#M41232</link>
      <description>&lt;P&gt;From my experience, whenever I would see those in the logs, it was sure sign tunnel was down or would get re-established.&lt;/P&gt;
&lt;P&gt;I will double check in the lab tomorrow.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 00:27:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246713#M41232</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-17T00:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246714#M41233</link>
      <description>&lt;P&gt;The only thing that generally can be found in logs is establishment (eg key install).&lt;/P&gt;
&lt;P&gt;In R82, you can create monitoring objects that I presume will give you some indication when the VPN goes down.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 01:22:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246714#M41233</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-17T01:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246718#M41235</link>
      <description>&lt;P&gt;thank you so much &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt; !!!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 03:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246718#M41235</guid>
      <dc:creator>TINTIN8</dc:creator>
      <dc:date>2025-04-17T03:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246719#M41236</link>
      <description>&lt;P&gt;No problem.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 03:47:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246719#M41236</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-17T03:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246720#M41237</link>
      <description>&lt;P&gt;Do you have some kind of monitoring over your firewall? there is an snmp oid for tunnel state - so you could use that.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;oid 1.3.6.1.4.1.2620.500.9002
kind table&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;from snmp-mib (https://support.checkpoint.com/results/sk/sk90470)
      tunnelState OBJECT-TYPE
            SYNTAX  INTEGER {
                          active(3),
                          destroy(4),
                          idle(129),
                          phase1(130),
                          down(131),
                          init(132)
             		}&lt;/LI-CODE&gt;&lt;P&gt;for some reason my lab-gw sends tunnelstate as non-integer values (strings), but value is the same:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 06:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246720#M41237</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2025-04-17T06:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246749#M41251</link>
      <description>&lt;P&gt;If you have enabled Permanent Tunnels, you see Key Install only after tunnel was down or during renegotiation (controlled by the parameters you set).&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 11:21:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246749#M41251</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-04-17T11:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identify VPN downtimes or re-establishments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246752#M41254</link>
      <description>&lt;P&gt;I attached short video of what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;was referring to, but, keep in mind, this is ONLY available if gateway is on R82.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 11:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identify-VPN-downtimes-or-re-establishments/m-p/246752#M41254</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-17T11:35:46Z</dc:date>
    </item>
  </channel>
</rss>

