Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JohnManchester
New Contributor

Network traffic stats for a IPsec/Auto Key (IKE) Phase 1 tunnel & its local interface

Hi All I have posted this in the VPN discussion but I don't know if there is a more appropriate forum topic. Please let me know! At work, we have a "IPsec/Auto Key (IKE)" VPN setup on our firewall. The Phase 1 is called "Phase1_VPN". The Phase 1 Local Interface is "Phase1_LocalInterface". When I run snmpwalk, I get the following output.

[ul]
  • snmpwalk ................. 1.3.6.1.2.1.2.2.1.2
  • IF-MIB::ifDescr.40 = STRING: Phase1_LocalInterface
  • IF-MIB::ifDescr.69 = STRING: Phase1_VPN[/ul]

    Therefore, I can use snmp to record network traffic on this interface & tunnel using the following OIDs.

    [ul]
  • Phase1_LocalInterface[ul]
  • InOctets = 1.3.6.1.2.1.2.2.1.10.40
  • OutOctets = 1.3.6.1.2.1.2.2.1.16.40[/ul]
  • Phase1_VPN[ul]
  • InOctets = 1.3.6.1.2.1.2.2.1.10.69
  • OutOctets = 1.3.6.1.2.1.2.2.1.16.69[/ul][/ul]

    However, I would like to understand the relationship between the network traffic statistics reported on "Phase1_LocalInterface" & "Phase1_VPN". Is all traffic that passes through "Phase1_VPN" also shown on "Phase1_LocalInterface" and hence should "Phase1_VPN" traffic be a subset of "Phase1_LocalInterface"? This appears to be the case for OutOctets as the network monitoring system shows Phase1_VPN out traffic as always lower than Phase1_LocalInterface. However, the networking monitoring system shows Phase1_VPN in traffic to be higher than Phase1_LocalInterface traffic (5 Mbps rather than 200 Kbps). This doesn't make any sense to me! Is anybody able to help explain what we are seeing? Thanks John

  • 0 REPLIES 0
    Labels
    Top Kudoed Authors