Monitoring VPN Tunnels
Check Point Maestro R80.20SP Administration Guide | 91
Monitoring VPN Tunnels
Because VPN tunnels synchronize between all Security Appliances, use traditional tools to monitor
tunnels.
SmartConsole
You must not activate the
Monitoring
Software Blade in the Security Group object. But, you can still use the
tunnels information in SmartConsole to see VPN tunnel status and details.
SNMP
n
You can use the
tunnelTable
sub-tree in Check Point MIB .1.3.6.1.4.1.2620.500.9002 to see VPN
status with SNMP.
n
For VSX environments, search for the
SNMP Monitoring
section in the
for VSX-related SNMP information.
CLI Tools
Use these commands:
n
To see VPN statistics for each Security Appliance, in the Expert mode run:
# cpstat -f all vpn
n
To monitor VPN tunnels for each Security Appliance, in the Expert mode run:
# vpn tu
VPN tunnels are synchronized to all Security Appliances, therefore you can run this command from
the scope of one Security Appliance.
n
To monitor VPN tunnels in the non-interactive mode, in Gaia gClish run:
> vpn shell t
Note
- In a VSX environment, you must run these commands from the context of the applicable Virtual
System.