13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Control Center componentsThe first line of the tunnel entry shows the name that was assigned when the tunnelwas created, along with the tunnel type (IPSec, DVCP, or <strong>WatchGuard</strong>). If the tunnelis an IPSec or DVCP tunnel, it also shows the IP address of the destination IPSecdevice (such as another <strong>Firebox</strong>, SOHO, or SOHO|tc). If the tunnel is DVCP, the IPaddress refers to the entire remote network address rather than that of the <strong>Firebox</strong> orequivalent IPSec device.The next two lines display the amount of data sent and received on that tunnel inboth bytes and packets.If the tunnel is IPSec or DVCP, the lines below the packet quantities show when thekey expires and the tunnel is renegotiated. Expiration can be expressed in bytespassed or time deadline. DVCP tunnels that have been configured for both traffic andtime deadline expiration thresholds display both; this type of tunnel expires wheneither event occurs first (time runs out or bytes are passed). These lines below thepacket quantities also show the authentication and encryption levels set for thattunnel.If the tunnel is using <strong>WatchGuard</strong> VPN, the tunnel displays the packet statistics only.Remote VPN tunnelsFollowing the branch office VPN tunnels is an entry for remote VPN tunnels. RemoteVPN tunnels can either be Mobile <strong>User</strong> VPN (with IPSec) or Remote <strong>User</strong> PPTP.If the tunnel is Mobile <strong>User</strong> VPN, the branch displays the same statistics as for theDVCP or IPSec Branch Office VPN as described previously. The tunnel shows thetunnel name, followed by the destination IP address, followed by the tunnel type.Below are the packet statistics, followed by the key expiration, authentication, andencryption specifications.If the remote VPN tunnel is PPTP, then the display shows only the quantity of sentand received packets. Byte count and total byte count are not applicable to PPTPtunnel types.Expanding and collapsing the displayTo expand a branch of the display, click the plus sign (+) next to the entry, or doubleclickthe name of the entry. To collapse a branch, click the minus sign (—) next to theentry. A lack of either a plus or minus sign indicates that there is no furtherinformation about the entry.Red exclamation pointA red exclamation point appearing next to any item indicates that something withinits branch is not functioning properly. For example, a red exclamation point next tothe <strong>Firebox</strong> entry indicates that a <strong>Firebox</strong> is not communicating with either theLiveSecurity Event Processor or Management Station. A red exclamation point nextto a tunnel listing indicates a tunnel is down.When you expand an entry that has a red exclamation point, another exclamationpoint appears next to the specific device or tunnel with the problem. Use this featureto rapidly identify and locate problems with your VPN network.<strong>User</strong> <strong>Guide</strong> 29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!