Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
adeboer
New Contributor

Can't tell if my tunnels are flapping or not

Anyone able to tell me if the tunnel is flapping by looking at these tunnel messages from our FAZ? I can do some debugging too, just thought it was weird about the constant negotiations/installs of the SA.

2 REPLIES 2
Alby23
Contributor II

The best way you will find to really know if a Phase1 and a Phase2 are up or not it's via SNMP Polling.

 

VPN activity logs are not so useful in my opinion; you will find better information via CLI command like "diagnose vpn tunnel list" and so on but these ones give you a "pics" of the status in that specific moment.

For history situation, SNMP is the one.

neonbit
Valued Contributor

I'd recommend enabling an event monitor on your FAZ to create an alert/email if the VPN goes down:

 

Top Kudoed Authors