Skip to main content
adeboer
New Member
November 30, 2016
Question

Can't tell if my tunnels are flapping or not

  • November 30, 2016
  • 1 reply
  • 5218 views

Anyone able to tell me if the tunnel is flapping by looking at these tunnel messages from our FAZ? I can do some debugging too, just thought it was weird about the constant negotiations/installs of the SA.

    1 reply

    Alby23
    New Member
    December 1, 2016

    The best way you will find to really know if a Phase1 and a Phase2 are up or not it's via SNMP Polling.

     

    VPN activity logs are not so useful in my opinion; you will find better information via CLI command like "diagnose vpn tunnel list" and so on but these ones give you a "pics" of the status in that specific moment.

    For history situation, SNMP is the one.

    neonbit
    New Member
    December 4, 2016

    I'd recommend enabling an event monitor on your FAZ to create an alert/email if the VPN goes down: