- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi Gurus,
Is there any way to identify VPN disconnections/re-establishments looking at the log server logs?
Ex—we get logs like"Child SA exchange: Exchange failed: timeout reached," but we're not sure what the logs mean. Can we identify, looking at the logs, that the VPN tunnel went down "this" time and reconnected "this" time, etc.?
Our partners say your tunnel went down during a "time period," but we can't really check our logs and determine what happened to the VPN tunnel. Did it go down? What time did it re-establish?
Any help to clear this is highly appreciated.
The only thing that generally can be found in logs is establishment (eg key install).
In R82, you can create monitoring objects that I presume will give you some indication when the VPN goes down.
I attached short video of what @PhoneBoy was referring to, but, keep in mind, this is ONLY available if gateway is on R82.
Andy
The best way I found to do this is look for "key install" in the logs.
Andy
Thanks @the_rock . However, this doesn't tell me what time the tunnel went down. I can see the Key install when the VPN gets re-established, but it still won't tell me what time it went down/disconnected, or was it in some kind of idle state.
From my experience, whenever I would see those in the logs, it was sure sign tunnel was down or would get re-established.
I will double check in the lab tomorrow.
Andy
thank you so much @the_rock !!!
No problem.
I attached short video of what @PhoneBoy was referring to, but, keep in mind, this is ONLY available if gateway is on R82.
Andy
If you have enabled Permanent Tunnels, you see Key Install only after tunnel was down or during renegotiation (controlled by the parameters you set).
The only thing that generally can be found in logs is establishment (eg key install).
In R82, you can create monitoring objects that I presume will give you some indication when the VPN goes down.
Do you have some kind of monitoring over your firewall? there is an snmp oid for tunnel state - so you could use that.
oid 1.3.6.1.4.1.2620.500.9002
kind table
from snmp-mib (https://support.checkpoint.com/results/sk/sk90470)
tunnelState OBJECT-TYPE
SYNTAX INTEGER {
active(3),
destroy(4),
idle(129),
phase1(130),
down(131),
init(132)
}for some reason my lab-gw sends tunnelstate as non-integer values (strings), but value is the same:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY