Skip to content

Support Knowledge Base>Submit Feedback

Customer Support Center

How do you enable the Optimized feature of VPN Monitor and what does it do? (KB ID: KB9522)

Article ID: KB9522
Former Article ID:
Published: Jan 29, 2007
Last Modified: Jan 29, 2007
Visible By: Employee, PTAC, Partner, Customer, Public

Back to Previous Page | Knowledge Base Home

Article URL

http://kb.juniper.net/KB9522

Synopsis

When enabling optimization, existing traffic through the VPN is used for the monitoring packet, instead of using the VPN monitor ping, which would normally be sent.  How is Optimization enabled and how is it used? 

Problem

How do you enable the Optimized feature of VPN Monitor and what does it do?

   

Solution

To enable the Optimized feature of VPN Monitor:

From the WebUI:

From the CLI,

  • Enter the following command:

    set vpn <vpnname> monitor optimized [rekey]

 

What is the Optimized feature used for?

When you enable VPN monitoring for a specific tunnel, the security device sends ICMP echo requests (or “pings”) through the tunnel at specified intervals (configured in seconds) to monitor network connectivity through the tunnel.

When Optimized is selected, the VPN monitoring behavior changes as follows:

  • The Juniper firewall device accepts incoming traffic through the VPN tunnel as a substitute for ICMP echo replies.
  • If there is both incoming and outgoing traffic through the VPN tunnel, the device suppresses VPN monitoring pings.

    If you enable VPN monitoring optimization, be aware that VPN monitoring can no longer provide accurate SNMP statistics.

”note: If you upgrade from ScreenOS 4.x to ScreenOS 5.x and find the VPN tunnels are marked down by VPN monitor, it is recommended that you enable the Optimized feature of VPN Monitor.


 

 

Category Description

By Product » Hardware » Firewalls
By Product » Software » Network Operating Systems » ScreenOS Software

Purpose

Troubleshooting

Related Articles


Related Links


Related Files