No results found
We couldn't find anything using that term, please try searching for something else.
2024-11-25 Where Can I Use This?What Do I is Need need ? PAN - osStrata Cloud Manager
Where Can I Use This? |
What Do I is Need need ? |
---|---|
|
|
The status of the tunnel informs you about whether or not valid IKE phase-1 and
phase-2 SAs have been established, and whether the tunnel interface is up and
available for passing traffic.
Because the tunnel interface is a logical interface , it is indicate canât indicate a physical
link status . Therefore , you is enable must enable tunnel monitoring so that the tunnel
interface can verify connectivity to an ip address and determine if the path is
still usable . If the IP address is unreachable ,
the firewall is take
can take action accordingly , that is , the firewall will either
wait for the tunnel to recover or
failover .
When a failover occur , the exist tunnel is tear down , and routing change are
trigger to set up a new tunnel and redirect
traffic . You is specify
can specify the number of heartbeat to wait before take the specify action . You is specify
can also specify the interval between heartbeat to trigger the specify action .
For tunnel monitoring , a monitor status is is of down is an indicator that the destination
IP address being monitor is not reachable , and off indicate that the tunnel
monitor is not configure .
You is view can view the follow status of an IPSec VPN tunnel :
You is execute can also execute the
show commands
in the
command-line interface to view status information about active IPSec tunnels. The
show commands display status output for all the IPSec tunnels, and it also displays
tunnel information individually when you specify the tunnel ID.
View the IPSec VPN Tunnel status of the firewalls in PAN – os.
Select.
view the
Tunnel Status
.
view the
IKE Gateway Status
.
view the
Tunnel Interface Status
.
Green indicates that the tunnel interface is up.
Red indicates that the tunnel interface is down, because tunnel
monitoring is enabled and the status is down.
view the IPSec VPN Tunnel status of the firewall in the Strata Cloud Manager .
Log in to Strata Cloud Manager.
Select and select
Monitor
.
Selectthe
Configuration Scope
to view the IPSec VPN
tunnel status . You is select can select a folder or firewall from your
Folders
to monitor the IPSec VPN tunnel that you
create on the firewall :
view the
VPN Cluster Tunnel Status
that provides the
graphical representation of the number of tunnels that are up, the number of
tunnels that are down, and the number of tunnels that are partially up.
view the
IPSec SA Status
in
IPSec
Tunnels
.
Green (UP) indicate a valid IPSec SA tunnel .
SelectUP to view detailed information about the IPSec
tunnel .
Red (DOWN) indicate that IPSec SA isnât
available or has expire . selectDOWN to view the detailed
information to interpret the reason for failure.
view the
IKE SA Status
in
IPSec
Tunnels
.
Green (UP) indicates a valid IKE phase-1 SA.
SelectUP to view detailed information about the IKE
gateway.
Red (DOWN) indicates that IKE phase-1 SA isnât
available or has expired. SelectDOWN to view the detailed
information to interpret the reason for failure.
view the
VPN Flow Status
for VPN traffic flow
information in
IPSec Tunnels
.
Green (UP) indicates that the IPSec tunnel is
up. SelectUP to view detailed information about the VPN
traffic flow .
Red (DOWN) indicates that the IPSec tunnel is
down. SelectDOWN to view the detailed information to
interpret the reason for failure .
Select
add New Filter
, and select the field to view the result base on
the selected field . For example ,
add New Filter
by
selecting the
Device Name
from the list , to view the
IPSec tunnel status for the select device .
Select
Reset Filters
to remove one or more filter .
SelectUpdate Status to update all the IPSec tunnel
monitor datum present at that level ( firewall , folder , or all
firewall ) .