eG Monitoring
 

Measures reported by WgTunnelTest

A VPN (Virtual Private Network) creates secure connections between computers or networks in different locations. Each connection is known as a tunnel. When a VPN tunnel is created, the two tunnel endpoints authenticate with each other. Data in the tunnel is encrypted. Only the sender and the recipient of the traffic can read it.

Using the WatchGuard Firewall, administrators can configure multiple VPN tunnels based on the volume of data traffic handled by their network and the security/privacy requirements of the network. Often bandwidth management can be enabled on the firewall configurations to prevent unauthorized access to the network and to optimize the usage of network resources. Improper firewall configurations can therefore result in a few VPN tunnels hogging the bandwidth resources and choking the network! To avoid this, administrators should periodically check the efficacy of the firewall configuration, identify the issues in the firewall settings and rectify the same! This is where the WgTunnelTest test helps!

This test auto discovers the VPN tunnels configured using the WatchGuard Firewall and closely monitors the amount of data traffic and packets sent and received via every tunnel. In addition, this test clearly indicates the number of various error – prone packets that were sent and received through each VPN tunnel. In the process, the test accurately points to that tunnel that is handling an abnormally high volume of traffic and is hence hogging the bandwidth resources available to the network! This way, the test enables administrators to understand whether/not their firewall configurations are effective, and if not, initiate measures to fine-tune them.

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
Inbound_traffic Indicates the amount of traffic that was received through this VPN tunnel since the connection was established. KB Comparing the value of these measures across the VPN tunnels helps you in identifying the VPN tunnel that is receiving/transmitting the highest amount of traffic.
Outbound_traffic Indicates the amount of traffic that was transmitted through this VPN tunnel since the connection was established. KB
Inbound_packets Indicates the number of packets that were received through this VPN tunnel during the last measurement period. Number Comparing the values of these measures across the VPN tunnels helps you in identifying the VPN tunnel that has received/transmitted the maximum number of packets.
Outbound_packets Indicates the number of packets that were transmitted through this VPN tunnel during the last measurement period. Number
In_pkts_disc_dec_error Indicates the number of packets that were discarded due to decrypt errors when received by this VPN tunnel during the last measurement period. Number Ideally, the value of this measure should be zero.
Out_pkts_disc_decrypt Indicates the number of packets that were discarded due to decrypt errors when transmitted through this VPN tunnel during the last measurement period. Number Ideally, the value of this measure should be zero.
In_pkts_disc_auth_error Indicates the number of packets that were discarded due to authentication errors during the last measurement period while being received by this VPN tunnel. Number Ideally, the value of this measure should be zero.
Out_pkts_disc_auth Indicates the number of packets that were discarded due to authentication errors during the last measurement period while being transmitted through this VPN tunnel. Number Ideally, the value of this measure should be zero.
In_pkts_disc_reply_error Indicates the number of packets that were discarded due to replay errors during the last measaurement period wile being received by this VPN tunnel. Number Ideally, the value of this measure should be zero.
Out_pkts_disc_reply Indicates the number of packets that were discarded due to replay errors during the last measurement period while being transmitted through this VPN tunnel. Number Ideally, the value of this measure should be zero.