The Firewall Tunnels dashboard provides visibility into site-to-site VPN tunnels and, where supported by the firewall integration, their current status.
How do I monitor when a VPN tunnel is down?
When the VPN tunnel status is available in Auvik, create an Alerts v2 device-based alert using the VPN Tunnel is Down condition.
- Go to Manage Alerts.
- Create a new Alerts v2 alert.
- Select the firewall or firewalls to monitor.
- Select the VPN Tunnel is Down condition.
- Use Tunnel Name contains or Tunnel Name equals to identify the tunnel or group of tunnels to monitor.
- Add the tunnel name to the alert name or trigger message so the notification identifies the affected tunnel.
- Configure the appropriate alert delay if brief VPN renegotiations should not generate an alert.
- Select the notification channel or channels.
- Save and enable the alert.
The alert is evaluated only for VPN tunnels whose status is populated in Auvik. Confirm that the intended tunnel appears in the Firewall Tunnels dashboard before creating the alert.
What if the VPN tunnel does not appear or has no status?
First confirm that:
- The firewall has been discovered by Auvik.
- The firewall is polling successfully.
- The required device credentials are valid.
- The VPN tunnel appears in the Firewall Tunnels dashboard.
- The firewall integration supports reporting the tunnel status to Auvik.
If the tunnel is not available through the native firewall integration, a custom SNMP poller may be used when the firewall exposes a supported tunnel-status OID.
A custom SNMP poller requires:
- The vendor’s MIB or OID documentation.
- SNMP enabled and reachable from the Auvik collector.
- A valid SNMP credential in Auvik.
- A value that reliably represents the tunnel’s Up or Down state.
After creating the poller, confirm that Auvik is receiving current values before creating an alert based on the poller.
See:
How do I manage custom SNMP Pollers?
https://support.auvik.com/hc/en-us/articles/206617226-How-do-I-manage-custom-SNMP-Pollers
How can I see the current values of SNMP Pollers?
https://support.auvik.com/hc/en-us/articles/210462766-How-can-I-see-the-current-values-of-SNMP-Pollers
How do I reduce alerts during brief tunnel renegotiations?
If a tunnel briefly changes state during normal renegotiation or failover, configure an Alert Delay so the condition must remain true before the alert triggers.
Use a delay appropriate for the environment and test it against normal tunnel behavior. Avoid using a delay that could hide a genuine outage.
See:
How to set Alert Delays with Alerts v2
How do I test the alert?
Test during a planned maintenance window using a non-production tunnel whenever possible.
- Confirm the tunnel is visible and currently up in the Firewall Tunnels dashboard.
- Trigger a controlled tunnel state change during the maintenance window.
- Confirm that the Alerts v2 alert is generated.
- Verify that the notification is delivered to the expected channel.
- Restore the tunnel.
- Confirm that the alert clears when the tunnel returns to the expected state.
Do not intentionally interrupt a production VPN tunnel unless the change has been approved and the impact is understood.