Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Timothy_Hall
Champion Champion
Champion

S2S VPN State & Statistics per tunnel/peer?

Does anyone know a way to pull current statistics from a particular Site to Site VPN tunnel for troubleshooting purposes?  What I'm looking for is the equivalent of the Cisco show vpn-sessiondb command like this:

cisco0.png

This command is useful for seeing if Tx/Rx counters are incrementing to confirm two-way communication for a VPN, and verify current rekey/lifetime timers.  Usually I would just run a packet capture and look for the presence of IKE/IPSEC traffic but there has to be a better way.  What I've tried:

1) cpstat -f all vpn - Dumps very detailed VPN statistics but they are global and no apparent way to focus on a particular tunnel.

2) vpn tu - Just shows SA states with no statistics

3) SmartView Monitor - Tunnels...Monitor Traffic of this tunnel.  Shows the live tunnel state and also allows graphing of top sources/destinations/connections including statistics but no apparent way to do it for all traffic in the tunnel.  I'd imagine this raw data can be acquired by the rtm driver via the rtm monitor command on the gateway, but there is practically no documentation for how to use it.

4) I suppose Accounting could be set on the rule matching traffic to/from the tunnel, but those stats would only be updated every 10 minutes.

Any other suggestions?

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
(1)
4 Replies
the_rock
Legend
Legend

0 Kudos
the_rock
Legend
Legend

Does command like below give you anything more?

Andy

 

[Expert@quantum-firewall:0]# vpn tu tlist -p 4.205.75.119

+-----------------------------------------+----------------------------------+---------------------+
| Peer: 4.205.75.119 - Azure | MSA: 7fdb539aa848 | i: 0 ref: 1 |
| Methods: ESP Tunnel PFS AES-256 SHA256..| | i: 1 ref: 1 |
| My TS: 0.0.0.0/0 | | i: 2 ref: 1 |
| Peer TS: 0.0.0.0/0 | | i: 3 ref: 1 |
| MSPI: 1800001 (i: 3, p: 0, d: 1) | No outbound SPI | |
| Tunnel created: | IPsec | |
| Tunnel expiration: | Disconnected | |
+-----------------------------------------+----------------------------------+---------------------+

(0) Site-to-Site tunnels are up:
IPsec 0
NAT-T 0

(0) Number of Active Clients:
NAT-T 0
Visitor Mode 0
SSL 0
L2TP 0
strongSwan 0

[Expert@quantum-firewall:0]#

0 Kudos
CheckPointerXL
Advisor

vpn tu tlist start it will trigger statistic counters for every phase2

Then, You can monitor encrypted/decrypted kbytes data by vpn tu tlist

0 Kudos
the_rock
Legend
Legend

I dont believe thats good enough for Tim. I had that already on and did not give me anything close to what he showed from Cisco.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events