- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Gurus,
Is there any way to identify VPN disconnections/re-establishments looking at the log server logs?
Ex—we get logs like"Child SA exchange: Exchange failed: timeout reached," but we're not sure what the logs mean. Can we identify, looking at the logs, that the VPN tunnel went down "this" time and reconnected "this" time, etc.?
Our partners say your tunnel went down during a "time period," but we can't really check our logs and determine what happened to the VPN tunnel. Did it go down? What time did it re-establish?
Any help to clear this is highly appreciated.
The only thing that generally can be found in logs is establishment (eg key install).
In R82, you can create monitoring objects that I presume will give you some indication when the VPN goes down.
I attached short video of what @PhoneBoy was referring to, but, keep in mind, this is ONLY available if gateway is on R82.
Andy
The best way I found to do this is look for "key install" in the logs.
Andy
Thanks @the_rock . However, this doesn't tell me what time the tunnel went down. I can see the Key install when the VPN gets re-established, but it still won't tell me what time it went down/disconnected, or was it in some kind of idle state.
From my experience, whenever I would see those in the logs, it was sure sign tunnel was down or would get re-established.
I will double check in the lab tomorrow.
Andy
thank you so much @the_rock !!!
No problem.
I attached short video of what @PhoneBoy was referring to, but, keep in mind, this is ONLY available if gateway is on R82.
Andy
If you have enabled Permanent Tunnels, you see Key Install only after tunnel was down or during renegotiation (controlled by the parameters you set).
The only thing that generally can be found in logs is establishment (eg key install).
In R82, you can create monitoring objects that I presume will give you some indication when the VPN goes down.
Do you have some kind of monitoring over your firewall? there is an snmp oid for tunnel state - so you could use that.
oid 1.3.6.1.4.1.2620.500.9002
kind table
from snmp-mib (https://support.checkpoint.com/results/sk/sk90470)
tunnelState OBJECT-TYPE
SYNTAX INTEGER {
active(3),
destroy(4),
idle(129),
phase1(130),
down(131),
init(132)
}for some reason my lab-gw sends tunnelstate as non-integer values (strings), but value is the same:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 16 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY