How to monitor Tunnel Uptime?
I'd like to know how long the tunnel has been up for in order to know whether renegotiation of phase1 and phase2 are working successfully. I'm pinging every 60 seconds to ensure it should stay alive but I can't see a way of checking it has actually stayed alive past the 1hr (p2) and 12hr (p1) lifetimes.
You can't really tell that except from reading the full log.
If you look at the output of setkey -D you can see when the phase 1 entry was created, but if that was ever re-negotiated then you'd only see the latest entry there. (Or perhaps an occasional older one in some cases)