03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

FortiOS Handbook<br />

Monitoring and troubleshooting<br />

This section provides some general maintenance and monitoring procedures for VPNs.<br />

The following topics are included in this section:<br />

Monitoring VPN connections<br />

Testing VPN connections<br />

Testing VPN connections<br />

Logging VPN events<br />

VPN troubleshooting tips<br />

Monitoring VPN connections<br />

You can use the monitor to view activity on IPsec VPN tunnels and to start or stop those<br />

tunnels. The display provides a list of addresses, proxy IDs, and timeout information for<br />

all active tunnels. See “IPsec Monitor” on page 37.<br />

Monitoring connections to remote peers<br />

The list of tunnels provides information about VPN connections to remote peers that have<br />

static IP addresses or domain names. You can use this list to view status and IP<br />

addressing information for each tunnel configuration. You can also start and stop<br />

individual tunnels from the list.<br />

To view the list of static-IP and dynamic-DNS tunnels go toVPN > Monitor > IPsec<br />

Monitor.<br />

Monitoring dialup IPsec connections<br />

The list of dialup tunnels provides information about the status of tunnels that have been<br />

established for dialup clients. The list displays the IP addresses of dialup clients and the<br />

names of all active tunnels. The number of tunnels shown in the list can change as dialup<br />

clients connect and disconnect.<br />

To view the list of dialup tunnels go to VPN > Monitor > IPsec Monitor.<br />

If you take down an active tunnel while a dialup client such as FortiClient is still<br />

connected, FortiClient will continue to show the tunnel connected and idle. The dialup<br />

client must disconnect before another tunnel can be initiated.<br />

The list of dialup tunnels displays the following statistics:<br />

The Name column displays the name of the tunnel.<br />

The meaning of the value in the Remote gateway column changes, depending on the<br />

configuration of the network at the far end:<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 235<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!