Hi,
First make sure that your (and your partner's) routing is ok
and that you are permitting correct traffic (check the
logs).
Here are some tools for debugging vpn.
vpn debug on - Turn on vpn debug, and write the output to
vpnd.elg
vpn debug off - Disable vpn debug
vpn debug ikeon - Turn on ike debug and write the output to
ike.elg
vpn debug ikeoff - Disable ike debug
vpn tu - Short for vpn tunnelutil, useful tool for deleting
specific IPSec or IKE SAs for specific peer or user without
interrupting other VPN activities.
ike monitor (commands mon or moff) monitors ike traffic and
writes all IKE captured data into ikemonitor.snoop.
fw monitor is always a useful debugging tool as well.
-lari-
-----Original Message-----
From: Mailing list for discussion of Firewall-1 on behalf of
No Name Available
Sent: Tue 11/6/2007 9:01 PM
To: FW-1-MAILINGLIST AMADEUS.US.CHECKPOINT.COM
Subject: [FW-1] monitoring site to site vpn tunnels
Hi all
Is there any mechanism in Checkpoint to monitor site to site
vpn
tunnels. Does fw-1 generates a snmp trap when it can't
renegotiate phase
1 or 2
Kind regards
Tauseef Khan
Infrastructure Team
Mob: 07796447091
This electronic message contains information from bet365
Group Limited which may be privileged or confidential. The
information is intended to be for the use of the
individual(s) or entity named above. If you are not the
intended recipient be aware that any disclosure, copying,
distribution or use of the contents of this information is
prohibited. If you have received this electronic message in
error, please notify us by telephone or email immediately.
Activity and use of the bet365 Group Limited email system is
monitored to secure its effective operation and for other
lawful business purposes. Communications using this system
will also be monitored and may be recorded to secure
effective operation and for other lawful business purposes.
bet365 Group Limited
Registered office: Hillside, Festival Way, Stoke-on-Trent,
Staffordshire, ST1 5SH
Registered in England no. 3958393
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV amadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http:
//www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner ts.checkpoint.com
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV amadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http:
//www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner ts.checkpoint.com
=================================================
|