SNMP Polling - IPSec Tunnel Status

Reply
L3 Networker

SNMP Polling - IPSec Tunnel Status

I have downloaded the MIB's but cant find anything which would enable me to monitor the status of an IPSec tunnel.

 

Is it possible to monitor IPSec tunnel Up/Down via SNMP?

L2 Linker

Re: SNMP Polling - IPSec Tunnel Status

There are following traps but not sure if there is OID to monitor.

 

panVPNTunnelStatusDownTrap

panVPNTunnelStatusUpTrap

L7 Applicator

Re: SNMP Polling - IPSec Tunnel Status

Hello,

What I do is make sure I apply an IP address to each tunnel interface. Then have a monitoring solution that monitors the far end of the tunnel so that if its unreachable, there is something wrong with the tunnel possibly. Using a SIEM is another method if you are parsing the logs.

 

Just some thoughts.

L1 Bithead

Re: SNMP Polling - IPSec Tunnel Status

The tunnel interfaces show up as interfaces via SNMP, we monitor the status of them using IF-MIB

L7 Applicator

Re: SNMP Polling - IPSec Tunnel Status

@patmal

Not sure, but isn't the status of the tunnel interface always "up" even if the IPSec tunnel is down?

L3 Networker

Re: SNMP Polling - IPSec Tunnel Status

Yep, you are correct
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!