2 years ago
VPN Tunnel Monitoring
We have several Cisco IPSec Aggregate Tunnels that we are monitoring on our ASA. The problem is, many of them have a 30 minute idle timeout. I don't really need (or want) an alert if a VPN tunnel...
On 12/21/2022 at 8:14 AM, Kirby Timm said:I'd love to see what you've got Stuart! Thanks in advance.
We had another one today. VPN tunnel was idle timeout closed and was down for about 14 hours. I give a ping through the VPN tunnel and it comes right up, so there wasn't any "problem" with the tunnel. I can see how trying to monitor VPN tunnels can be super tricky because how are you going to determine if the tunnel is down because of an issue or down because of idle timeout.
We have resorted to using logs for this -- the reason for the tunnel being down is only presented in the log entries, and not in any OIDs, unfortunately.
Very curious to see what LogicMonitor has used as a solution for this as well.