Reference Manual for the ProSafe VPN Firewall FVS114
Advanced Virtual Private Networking
6-21
202-10098-01, April 2005
How to Check VPN Connections
You can test connectivity and view VPN status information on the FVS114 (see also
“VPN Tunnel
Control” on page 5-26
).
Testing the Gateway A FVS114 LAN and the Gateway B LAN
1.
Using our example, from a PC attached to the FVS114 on LAN A, on a Windows PC click the
Start
button on the taskbar and then click
Run
.
2.
Type
ping -t
172.23.9.1
, and then click
OK
.
3.
This will cause a continuous ping to be sent to the LAN interface of Gateway B. Within two
minutes, the ping response should change from timed out to reply.
4.
At this point the connection is established.
5.
To test connectivity between the FVS114 Gateway A and Gateway B WAN ports, follow these
steps:
a.
Using our example, log in to the FVS114 on LAN A, go to the main menu Maintenance
section and click the
Diagnostics
link.
b.
To test connectivity to the WAN port of Gateway B, enter
22.23.24.25
, and then click
Ping
.
c.
This causes a ping to be sent to the WAN interface of Gateway B. Within two minutes, the
ping response should change from timed out to reply. You may have to run this test several
times before you get the reply message back from the target FVS114.
d.
At this point the connection is established.
Note
: If you want to ping the FVS114 as a test of network connectivity, be sure the FVS114 is
configured to respond to a ping on the Internet WAN port by checking the check box seen in
Figure 4-2
on
page 4-4
. However, to preserve a high degree of security, you should turn off
this feature when you are finished with testing.
6.
To view the FVS114 event log and status of Security Associations, follow these steps:
a.
Go to the FVS114 main menu VPN section and click the
VPN Status
link.
b.
The log screen displays a history of the VPN connections, and the IPSec SA and IKE SA
tables will report the status and data transmission statistics of the VPN tunnels for each
policy.