Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nyklon
Explorer
Jump to solution

Skyline VPN tunnel telemetry

I have multiple ikev2 tunnels running on different gateways and have setup skyline and the required backend.  I am getting data from the firewalls but the vpn vti interfaces are showing 0bps.  I would expect to see some kind of data from the gateways regarding the tunnels bandwidth usage.  Are there additional steps to get this data through skyline outside the skyline setup sk?  This is a Maestro environment.

 

Thanks

Jim

0 Kudos
1 Solution

Accepted Solutions
D_Schoenberger
Employee
Employee

Hi @Nyklon ,

 

VTIs are virtual interfaces which do not receive/transmit packets - they are logical only, for providing a nexthop to which traffic can be routed.

 

Traffic that is routed via a VTI is intercepted by the kernel, encrypted, and transmitted via the real physical interface of the gateway. Likewise, decrypted traffic is received on the external, real physical, interface of the gateway and transmitted by the internal, real physical, interface of the gateway. Because of this interception, no packet ever actually reaches the RX/TX queues of the vpntX interfaces, so the OS won't report them in the output of "ifconfig".

 

Hope this clears things up a bit.

View solution in original post

0 Kudos
5 Replies
Arik_Ovtracht
Employee
Employee

Hi @Nyklon

What do you see when you run CPview on the firewalls? Is the correct data displayed there?

Nyklon
Explorer

no cpview shows no information for the vpn tunnels.    Below is the cpview.  vpnt101 and 102 are used and actually using most of the bandwidth across the firewall.  vpnt103 and 104 are down so can be ignored.

cpview no tunnel statscpview no tunnel stats

0 Kudos
Arik_Ovtracht
Employee
Employee

In that case, the issue is not with Skyline itself, but with the data producers from CPview.

I will loop in the relevant feature owners, and will try to put an update here once we have some conclusions.

0 Kudos
Arik_Ovtracht
Employee
Employee

Hi @Nyklon,

looks like this issue would require more investigation from us - can you please open a support ticket for it? You can mention my name (Arik Ovtracht) on the ticket to get the investigation task directly to me.

0 Kudos
D_Schoenberger
Employee
Employee

Hi @Nyklon ,

 

VTIs are virtual interfaces which do not receive/transmit packets - they are logical only, for providing a nexthop to which traffic can be routed.

 

Traffic that is routed via a VTI is intercepted by the kernel, encrypted, and transmitted via the real physical interface of the gateway. Likewise, decrypted traffic is received on the external, real physical, interface of the gateway and transmitted by the internal, real physical, interface of the gateway. Because of this interception, no packet ever actually reaches the RX/TX queues of the vpntX interfaces, so the OS won't report them in the output of "ifconfig".

 

Hope this clears things up a bit.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events