Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Warren_T
Explorer

IPSec tunnel down time for a specific peer IP

 

Hi Team,

Is there any way to find when the tunnel went down?

Current version:R81.10/R81.20/R82

0 Kudos
3 Replies
CaseyB
Advisor

If you have "Set Permanent Tunnels" enabled on the VPN there should be a log message.

perm_tun.png

 

If you do not have that configured, you would need to do some research without a monitoring system in place. Here are some paths you can explore to find when a tunnel drops.

  • You could see if the peer sent errors your way at a specific time:
    • blade:VPN AND <VPN PEER PUBLIC IP> AND action:Reject
  • Check the Phase 2 timer in the community.
    • If the Phase 2 is set to 1 hour, do a search on:
      • blade:VPN AND <VPN PEER PUBLIC IP> AND action:"Key Install"
      • Add an hour to the last timestamp and that's probably when it went down

 

Keep in-mind it is perfectly normal for a tunnel to go down if there is no traffic traversing the tunnel after certain criteria; however, it should come back right away once traffic is initiated on the tunnel.

With certain monitoring third-party solutions, you can track the status via SNMP, but I prefer to use ICMP monitors as it is more accurate as it is always sending traffic and acting as a keepalive. 

R82 adds network probes, but I'm not sure how the up / down reporting looks for those yet.

0 Kudos
Vincent_Bacher
MVP Silver
MVP Silver

You should be able to see this in SmartLog.

Filter for the VPN blade and search for the peer gateway IP address or the object name. Then you should see VPN control messages such as IKE key install, SA delete, or similar log entries that indicate tunnel activity and down events.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Yes, there is. Just search for "key install" (without quotes) in smart console logs tab, should give you an idea.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events