Tunnel monitoring using internal src to external dst?

Reply
Highlighted
L2 Linker

Tunnel monitoring using internal src to external dst?

Is it possible to monitor VPN tunnels using an internal source IP on my tunnel interface and the external IP of the other system? I won't always have control/access to the other side of the tunnel, I may only know the local subnet(s) and the external IP.


Accepted Solutions
Highlighted
Cyber Elite

Re: Tunnel monitoring using internal src to external dst?

Hello,

The 'destination IP' can be anything that is pingable on the other end of the tunnel. Perhaps the internal interface of the other sides firewall? Just soemthing that is always %100 up so you dont get false positives.

 

Does this help?

View solution in original post


All Replies
Highlighted
L7 Applicator

Re: Tunnel monitoring using internal src to external dst?

if you 'number' all your tunnels (set a /30 subnet ip on each end) you can simply monitor the remote tunnel interface

reaper - PANgurus.com
I drink and I know things
Highlighted
L2 Linker

Re: Tunnel monitoring using internal src to external dst?

I don't follow you. I don't have access to each end, I only have access to my end. I know the external IP and the local subnets of the other end. The other end is generally not a PA firewall.

 

Can you give an example of what should be set for IPsec Tunnel -> Tunnel Monitor -> Destination IP ?

 

 

Highlighted
Cyber Elite

Re: Tunnel monitoring using internal src to external dst?

Hello,

The 'destination IP' can be anything that is pingable on the other end of the tunnel. Perhaps the internal interface of the other sides firewall? Just soemthing that is always %100 up so you dont get false positives.

 

Does this help?

View solution in original post

Highlighted
L2 Linker

Re: Tunnel monitoring using internal src to external dst?

Okay, I've got it figured out. I also see the tunnel-status-up and tunnel-status-down messages in the system logs.

 

Are there any plans to add a GUI indicator for tunnel monitoring status?

Highlighted
Cyber Elite

Re: Tunnel monitoring using internal src to external dst?

Already have one Network Tab-> IPSec Tunnels

Highlighted
L2 Linker

Re: Tunnel monitoring using internal src to external dst?

That doesn't show monitoring status...the tunnel may be up, but monitoring might be in a down state because of a changed IP address (for example).

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!