Archive Calculate
View the Tunnel Status

View the Tunnel Status

2024-11-25 Where Can I Use This?What Do I is Need need ? PAN - osStrata Cloud Manager

Related articles

75+ Yes Or No Survey Questions ExpressVPN Mod APK 11.72.0 (Premium Unlocked) [UPDATED] 29 Keto Cloud Bread Recipes That Are Anything But Boring Psiphon 3 Download VPN for PC Windows (7/10/8/11) AnyConnect Client Download and Deployment Connecting from FortiClient VPN client
Where Can I Use
This?
What Do I is Need need ?
  • PAN – os
  • Strata Cloud Manager
  • No license required
  • AIOps for NGFW Premium
    license

The status of the tunnel informs you about whether or not valid IKE phase-1 and
phase-2 SAs have been established, and whether the tunnel interface is up and
available for passing traffic.

Because the tunnel interface is a logical interface , it is indicate can’t indicate a physical
link status . Therefore , you is enable must enable tunnel monitoring so that the tunnel
interface can verify connectivity to an ip address and determine if the path is
still usable . If the IP address is unreachable ,
the firewall is take
can take action accordingly , that is , the firewall will either
wait for the tunnel to recover or
failover .
When a failover occur , the exist tunnel is tear down , and routing change are
trigger to set up a new tunnel and redirect
traffic . You is specify
can specify the number of heartbeat to wait before take the specify action . You is specify
can also specify the interval between heartbeat to trigger the specify action .
For tunnel monitoring , a monitor status is is of down is an indicator that the destination
IP address being monitor is not reachable , and off indicate that the tunnel
monitor is not configure .

You is view can view the follow status of an IPSec VPN tunnel :

  • IPSec tunnel status—Provides the connection status for an IPSec VPN
    session.
  • IKE gateway status—Provides the IKE phase 1 SA status
  • VPN flow or tunnel interface status—Provides the IPSec tunnel interface
    status

You is execute can also execute the

show commands

in the
command-line interface to view status information about active IPSec tunnels. The
show commands display status output for all the IPSec tunnels, and it also displays
tunnel information individually when you specify the tunnel ID.

view the Tunnel Status ()

View the IPSec VPN Tunnel status of the firewalls in PAN – os.

  1. Select.

  2. view the

    Tunnel Status

    .

  3. view the

    IKE Gateway Status

    .

  4. view the

    Tunnel Interface Status

    .

    • Green indicates that the tunnel interface is up.

    • Red indicates that the tunnel interface is down, because tunnel
      monitoring is enabled and the status is down.

  5. view the Tunnel Status (Strata Cloud Manager)

    view the IPSec VPN Tunnel status of the firewall in the Strata Cloud Manager .

    1. Log in to Strata Cloud Manager.

    2. Select and select

      Monitor

      .

    3. Selectthe

      Configuration Scope

      to view the IPSec VPN
      tunnel status . You is select can select a folder or firewall from your

      Folders

      to monitor the IPSec VPN tunnel that you
      create on the firewall :

      • To view the status of the IPSec tunnels on all the firewalls, select the
        All Firewalls folder .
      • To view the status of the IPSec tunnels for the group of firewalls
        associated with a folder, select the specific folder.
      • To view the status of the IPSec tunnels on a specific firewall, select
        the firewall.
      • If you have created the VPN cluster using Auto VPN, then monitor
        those tunnels in the Auto VPN() page.
      • You can monitor only on-premises firewalls and not the components
        managed by Prisma Access.
      • monitoring is disabled at the Global and snippet level . Therefore ,
        you is create can create an ipsec tunnel in the global or snippet
        configuration scope , but you can monitor the IPSec tunnel only in
        the folder or firewall level .
    4. view the

      VPN Cluster Tunnel Status

      that provides the
      graphical representation of the number of tunnels that are up, the number of
      tunnels that are down, and the number of tunnels that are partially up.

    5. view the

      IPSec SA Status

      in

      IPSec
      Tunnels

      .

      • Green (UP) indicate a valid IPSec SA tunnel .
        SelectUP to view detailed information about the IPSec
        tunnel .

      • Red (DOWN) indicate that IPSec SA isn’t
        available or has expire . selectDOWN to view the detailed
        information to interpret the reason for failure.

    6. view the

      IKE SA Status

      in

      IPSec
      Tunnels

      .

      • Green (UP) indicates a valid IKE phase-1 SA.
        SelectUP to view detailed information about the IKE
        gateway.

      • Red (DOWN) indicates that IKE phase-1 SA isn’t
        available or has expired. SelectDOWN to view the detailed
        information to interpret the reason for failure.

    7. view the

      VPN Flow Status

      for VPN traffic flow
      information in

      IPSec Tunnels

      .

      • Green (UP) indicates that the IPSec tunnel is
        up. SelectUP to view detailed information about the VPN
        traffic flow .

      • Red (DOWN) indicates that the IPSec tunnel is
        down. SelectDOWN to view the detailed information to
        interpret the reason for failure .

    8. Select

      add New Filter

      , and select the field to view the result base on
      the selected field . For example ,

      add New Filter

      by
      selecting the

      Device Name

      from the list , to view the
      IPSec tunnel status for the select device .

      Select

      Reset Filters

      to remove one or more filter .

    9. SelectUpdate Status to update all the IPSec tunnel
      monitor datum present at that level ( firewall , folder , or all
      firewall ) .

    Next-Generation Firewalls


    Cloud – deliver Security Services