Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Monitoring IPSec with SNMP

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mattboston
      last edited by

      I'm running pfSense 2.3.2 and I already have existing monitors setup in my Icinga system to monitor remote IP addresses of my client's system, but I'd like to be able to monitor if the Phase 1 or Phase 2 tunnels drop.  Is this possible with SNMP?  The reason the IP monitor isn't ideal is because our client sometimes takes the remote server offline for maintenance and doesn't tell us.  So we'd like to be alerted if the server goes down (server ping/port connection) and IPSec monitor if tunnel drops.  If not, can a script be written to give me the same details that I can have Icinga/NRPE execute?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        It is not possible via the built-in SNMP, but it can be done with the net-snmp package using extended commands. You'd have to setup one extended command per tunnel that would check the output of, for example "ipsec status con1000" for the first P2 of the first P1, "ipsec status con1001" for the second P2 of the first P1, "ipsec status con2000" for the first P2 of the second P1 and so on. Not so simple, but it can be done.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • M
          mattboston
          last edited by

          Ok, let me take a look at the ipsec command.  Thanks

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.