cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
498
Views
0
Helpful
2
Replies

Monitoring LAN to LAN Tunnels

johnroche_2
Level 1
Level 1

Hi

I have a number of 3800 ISR with LAN to LAN IPSEC VPNS.

One One Gig port I have 18 VPN's my network monitor on alerts if the physical interface drops. I would like to monitor each tunnel and alert if it fails. I have tried a few different OID.

Can any one recommend what OID to monitor to alert a tunnel down.

2 Replies 2

drolemc
Level 6
Level 6

To monitor LAN to LAN Ipsec VPN tunnel

User these commands on routers.

Router# show crypto ipsec sa

Router# show crypto isakmp sa.

You can view the IPsec and IKE statistics when you select Monitoring > Statistics > IPSec on the VPN Concentrators.

For further information click this link

http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a00801f0f0c.shtml

Thanks for the reply, but I am really looking for snmo monitoring rather than CLI.

I have tried watching phase one but is the tunnel state is UP-NO-IKE it alarms down.

If I watch phase two tunnel numbers, these change and the tunnel alarms down.

Right now I am alarming on the absence of any tunnel.

I am just wondering if there is a better way

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: