![]() |
VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring, Release 4.0
|
|||||
Statistics
![]() |
||||||
|
Table of ContentsStatisticsMonitoring | Statistics Monitoring | Statistics | Accounting Reset
Monitoring | Statistics | Address PoolsRestore Refresh Server IP Address: Port Group Requests Retransmissions Responses Malformed Responses Bad Authenticators Pending Requests Timeouts Unknown Type Reset
Monitoring | Statistics | Administrative AAARestore Refresh IP Address Range: Start / End Total Addresses Available Addresses Allocated Addresses Max Allocated Addresses Group IP Address Range: Start / End Total Addresses Available Addresses Allocated Addresses Max Allocated Addresses Reset
Monitoring | Statistics | AuthenticationRestore Refresh IP Address Requests Accepts Rejects Challenge Pending Requests Timeouts Refresh Reset
Monitoring | Statistics | Authentication | ReplicasRestore Refresh Server IP Address:Port Group Requests Retransmissions Accepts Rejects Challenges Malformed Responses Bad Authenticators Pending Requests Timeouts Unknown Type Monitoring | Statistics | Authorization Reset
Monitoring | Statistics | Bandwidth ManagementRestore Refresh Server IP Address:Port Group Requests Retransmissions Accepts Rejects Challenges Malformed Responses Bad Authenticators Pending Requests Timeouts Unknown Type Monitoring | Statistics | Compression Reset
Monitoring | Statistics | DHCPRestore Refresh IPSec Using IPComp Outbound Pre-Compression
L2TP/PPTP Using MPPCOutbound Post-Compression Ratio Inbound Pre-Decompression Inbound Post-Decompression Ratio Monitoring | Statistics | DNS Monitoring | Statistics | Events Monitoring | Statistics | Filtering Reset
Monitoring | Statistics | HTTPRestore Refresh Interface Inbound Packets Pre-Filter Inbound Packets Filtered Inbound Packets Post Filter Outbound Packets Pre-Filter Outbound Packets Filtered Outbound Packets Post Filter Reset
Monitoring | Statistics | IPSecRestore Refresh Octets Sent/Received Packets Sent/Received Packets Sent Sockets/Sessions Active Peak Total HTTP Sessions Login Name
Max ConnectionsIP Address Login Time Encryption Octets Sent/Received Packets Sent/Received Sockets Active Sockets Peak Sockets Total Reset
Monitoring | Statistics | L2TPRestore Refresh IKE (Phase 1) Statistics Active Tunnels
IPSec (Phase 2) StatisticsTotal Tunnels Received Bytes Sent Bytes Received Packets Sent Packets Received Packets Dropped Sent Packets Dropped Received Notifies Sent Notifies Received Phase-2 Exchanges Sent Phase-2 Exchanges Invalid Phase-2 Exchanges Received Invalid Phase-2 Exchanges Sent Rejected Received Phase-2 Exchanges Rejected Sent Phase-2 Exchanges Phase-2 SA Delete Requests Received Phase-2 SA Delete Requests Sent Initiated Tunnels Failed Initiated Tunnels Failed Remote Tunnels Authentication Failures Decryption Failures Hash Validation Failures System Capability Failures No-SA Failures Active Tunnels
Total Tunnels Received Bytes Sent Bytes Received Packets Sent Packets Received Packets Dropped Received Packets Dropped (Anti-Replay) Sent Packets Dropped Inbound Authentications Failed Inbound Authentications Outbound Authentications Failed Outbound Authentications Decryptions Failed Decryptions Encryptions Failed Encryptions System Capability Failures No-SA Failures Protocol Use Failures Reset
Monitoring | Statistics | Load BalancingRestore Refresh Total Tunnels Active Tunnels Maximum Tunnels Failed Tunnels Total Sessions Active Sessions Maximum Sessions Failed Sessions Rx Octets Control / Data Rx Packets Control / Data Rx Discards Control / Data Tx Octets Control / Data Tx Packets Control / Data L2TP Sessions Enabled?
Monitoring | Statistics | NATRole Load Number of Peers Peers Private IP Address
RefreshPublic IP Address Mapped IP Address Role Device Type Load Sessions Priority Duration Monitoring | Statistics | PPTP Reset
Monitoring | Statistics | SSHRestore Refresh Total Tunnels Active Tunnels Maximum Tunnels Total Sessions Active Sessions Maximum Sessions Rx Octets Control / Data Rx Packets Control / Data Rx Discards Control / Data Tx Octets Control / Data Tx Packets Control / Data PPTP Sessions Monitoring | Statistics | SSL Reset
Monitoring | Statistics | TelnetRestore Refresh Unencrypted Inbound Octets Encrypted Inbound Octets Unencrypted Outbound Octets Encrypted Outbound Octets Total Sessions Active Sessions Max Active Sessions Monitoring | Statistics | VRRP Reset
Monitoring | Statistics | MIB-IIRestore Refresh Checksum Errors Version Errors VRID Errors VRID Virtual Routers Interface: 1 (Private), 2 (Public), 3 (External)
Status Became Master Advertisements Received Advertisement Interval Errors Authentication Failures Time-to-Live Errors Priority 0 Packets Received Priority 0 Packets Sent Invalid Type Received Address List Errors Invalid Authentication Errors Mismatch Authentication Errors Packet Length Errors Monitoring | Statistics | MIB-II | Interfaces Reset
Monitoring | Statistics | MIB-II | TCP/UDPRestore Refresh Interface Status Unicast In Unicast Out Multicast In Multicast Out Broadcast In Broadcast Out Reset
Monitoring | Statistics | MIB-II | IPRestore Refresh TCP Segments Received TCP Segments Transmitted TCP Segments Retransmitted TCP Timeout Min TCP Timeout Max TCP Connection Limit TCP Active Opens TCP Passive Opens TCP Attempt Failures TCP Established Resets TCP Current Established UDP Datagrams Received UDP Datagrams Transmitted UDP Errored Datagrams UDP No Port Reset
Monitoring | Statistics | MIB-II | RIPRestore Refresh Packets Received (Total) Packets Received (Header Errors) Packets Received (Address Errors) Packets Received (Unknown Protocols) Packets Received (Discarded) Packets Received (Delivered) Packets Forwarded Outbound Packets Discarded Outbound Packets with No Route Packets Transmitted (Requests) Fragments Needing Reassembly Reassembly Successes Reassembly Failures Fragmentation Successes Fragmentation Failures Fragments Created Monitoring | Statistics | MIB-II | OSPF Refresh
Monitoring | Statistics | MIB-II | ICMPRouter ID Version External LSA Count External LSA Checksum LSAs Originated New LSAs Received LSA Database Limit Designated Routers Neighbors Areas External LSAs Reset
Monitoring | Statistics | MIB-II | ARP TableRestore Refresh Total Received / Transmitted Errors Received / Transmitted Destination Unreachable Received / Transmitted Time Exceeded Received / Transmitted Parameter Problems Received / Transmitted Source Quench Received / Transmitted Redirects Received / Transmitted Echo Requests (PINGs) Received / Transmitted Echo Replies (PINGs) Received / Transmitted Timestamp Requests Received / Transmitted Timestamp Replies Received / Transmitted Address Mask Requests Received / Transmitted Address Mask Replies Received / Transmitted Monitoring | Statistics | MIB-II | Ethernet Reset
Monitoring | Statistics | MIB-II | SNMPRestore Refresh Interface Alignment Errors FCS Errors Carrier Sense Errors SQE Test Errors Frame Too Long Errors Deferred Transmits Single Collisions Multiple Collisions Late Collisions Excessive Collisions MAC Errors: Transmit MAC Errors: Receive Speed (Mbps) Duplex Reset
Restore Refresh Requests Received Bad Version Bad Community String Parsing Errors Silent Drops Proxy Drops StatisticsMonitoring | StatisticsThis section of the Manager shows statistics for traffic and activity on the VPN Concentrator since it was last booted or reset, and for current tunneled sessions, plus statistics in standard MIB-II objects for interfaces, TCP/UDP, IP, ICMP, and the ARP table. Figure 17-1 Monitoring | Statistics Screen
Monitoring | Statistics | AccountingThis screen shows statistics for RADIUS user accounting activity on the VPN Concentrator since it was last booted or reset. To configure the VPN Concentrator to communicate with RADIUS accounting servers, see the Configuration | System | Servers | Accounting screens. Figure 17-2 Monitoring | Statistics | Accounting Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Server IP Address: PortThe IP address of the configured RADIUS user accounting server, and the port number that the VPN Concentrator is using to access the server. Each configured accounting server is a row in this table. The well-known port number for RADIUS accounting is 1646. GroupThe group on which the server is configured. RequestsThe number of accounting request packets sent to this RADIUS accounting server. This number does not include retransmissions. RetransmissionsThe number of accounting request packets retransmitted to this RADIUS accounting server. ResponsesThe number of accounting response packets received from this RADIUS accounting server. Malformed ResponsesThe number of malformed accounting response packets received from this RADIUS accounting server. Malformed packets include packets with an invalid length. Bad authenticators are not included in this number. Bad AuthenticatorsThe number of accounting response packets received from this server that contained invalid authenticators. Pending RequestsThe number of accounting request packets sent to this RADIUS accounting server that have not yet timed out or received a response. TimeoutsThe number of accounting timeouts to this RADIUS server. After a timeout the system may retry the same server, send to a different server, or give up. Retrying the same server is counted as a retransmission as well as a timeout. Sending to a different server is counted as a request as well as a timeout. Unknown TypeThe number of RADIUS packets of unknown type received from this server on the accounting port. Monitoring | Statistics | Address PoolsThis screen shows statistics for address pool activity on the VPN Concentrator since it was last booted or reset. This data appears if the VPN Concentrator is configured to assign IP addresses to clients from an internal address pool. To configure address pools, see the Configuration | System | Address Management screens. Figure 17-3 Monitoring | Statistics | Address Pools Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. IP Address Range: Start / EndThe starting and ending IP addresses in the configured address pool. Each configured range is a row in the table. Total AddressesThe total number of IP addresses in this configured pool. Available AddressesThe number of IP addresses available (unassigned) in this pool. Allocated AddressesThe number of IP addresses currently assigned from this pool. Max Allocated AddressesThe maximum number of IP addresses assigned from this pool at any one time. GroupThe names of configured groups. IP Address Range: Start / EndThe starting and ending IP addresses in the group's address pool. Each configured range is a row in the table. Total AddressesThe total number of IP addresses in the address pool of this group. Available AddressesThe number of IP addresses available (unassigned) in this group's pool. Allocated AddressesThe number of IP addresses currently assigned from this group's pool. Max Allocated AddressesThe maximum number of IP addresses assigned from this group's pool at any one time. Monitoring | Statistics | Administrative AAAIf you have configured a TACACS+ server, this screen shows statistics for communications between the VPN Concentrator and the TACACS+ server since the VPN Concentrator was last booted or reset. Figure 17-4 Monitoring | Statistics | Administrative AAA Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. IP AddressThe IP address of the TACACS+ server. RequestsThe number of requests for authentication, information, or authorization from the VPN Concentrator to the TACACS+ server. AcceptsThe number of successful authentications. RejectsThe number of rejected authentications. ChallengePending RequestsThe number of requests that have not yet been answered. TimeoutsThe number of times the VPN Concentrator timed out waiting for a request. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Monitoring | Statistics | AuthenticationThis screen shows statistics for user authentication activity on the VPN Concentrator since it was last booted or reset.
To configure the VPN Concentrator to communicate with authentication servers, see the Configuration | System | Servers | Authentication screens. Figure 17-5 Monitoring | Statistics | Authentication Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Server IP Address:PortThe IP address of the configured authentication server, and the port number that the VPN Concentrator is using to access the server. Each configured authentication server is a row in this table. Internal identifies the internal VPN Concentrator authentication server. When the authentication server is an SDI 5.0 server, this field becomes a link. Click the link to view the Monitoring | Statistics | Authentication | Replicas screen, which displays a list of replicas, and data about them (see the next section). The default, or well-known, port numbers identify an authentication server type: GroupThe group on which the server is configured. RequestsThe total number of authentication request packets sent to this server. This number does not include retransmissions. RetransmissionsThe number of authentication request packets retransmitted to this server. AcceptsThe number of authentication acceptance packets received from this server. RejectsThe number of authentication rejection packets received from this server. ChallengesThe number of authentication challenge packets received from this server. Malformed ResponsesThe number of malformed authentication response packets received from this server. Malformed packets include packets with an invalid length. Bad authenticators are not included in this number. Bad AuthenticatorsThe number of bad authentication response packets received from this server. Bad authenticators contain invalid authenticators or signature attributes. Pending RequestsThe number of authentication request packets destined for this server that have not yet timed out or received a response. TimeoutsThe number of authentication timeouts to this server. After a timeout the system might retry the same server, send to a different server, or give up. Retrying the same server is counted as a retransmission as well as a timeout. Sending to a different server is counted as a request as well as a timeout. Unknown TypeThe number of authentication packets of unknown type received from this server. Monitoring | Statistics | Authentication | ReplicasThis screen shows statistics for SDI 5.0 user authentication activity on the VPN Concentrator since it was last booted or reset. Figure 17-6 Monitoring | Statistics | Authentication | Replicas Screen Server IP Address:PortThe IP address of the configured SDI authentication server, and the port number that the VPN Concentrator is using to access the server. The default, or well-known, port numbers for an SDI 5.0 authentication server is 5500. GroupThe group on which the server is configured. RetransmissionsThe number of authentication request packets retransmitted to this server. AcceptsThe number of authentication acceptance packets received from this server. RejectsThe number of authentication rejection packets received from this server. TimeoutsThe number of authentication timeouts to this server. After a timeout the system might retry the same server, send to a different server, or give up. Retrying the same server is counted as a retransmission as well as a timeout. Sending to a different server is counted as a request as well as a timeout. BadCodeSentThe number of bad code packets received from this server. Bad code packets indicate invalid SecurID token code. BadPinSentThe number of bad pin packets received from this server. Bad pin packets indicate invalid user identification. Monitoring | Statistics | AuthorizationThis screen shows statistics for user authorization activity on the VPN Concentrator since it was last booted or reset. To configure the VPN Concentrator to communicate with authorization servers, see the Configuration | System | Servers | Authorization screens. Figure 17-7 Monitoring | Statistics | Authorization Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Server IP Address:PortThe IP address of the configured authorization server, and the port number that the VPN Concentrator is using to access the server. Each configured authorization server is a row in this table. Internal identifies the internal VPN Concentrator authorization server. The default, or well-known, port numbers identify an authorization server type: GroupThe group on which the server is configured. RequestsThe total number of authorization request packets sent to this server. This number does not include retransmissions. RetransmissionsThe number of authorization request packets retransmitted to this server. AcceptsThe number of authorization acceptance packets received from this server. RejectsThe number of authorization rejection packets received from this server. ChallengesThe number of authorization challenge packets received from this server. Malformed ResponsesThe number of malformed authorization response packets received from this server. Malformed packets include packets with an invalid length. Bad authorizations are not included in this number. Bad AuthenticatorsThe number of bad authorization response packets received from this server. Bad authenticators contain invalid authenticators or signature attributes. Pending RequestsThe number of authorization request packets destined for this server that have not yet timed out or received a response. TimeoutsThe number of authorization timeouts to this server. After a timeout the system might retry the same server, send to a different server, or give up. Retrying the same server is counted as a retransmission as well as a timeout. Sending to a different server is counted as a request as well as a timeout. Unknown TypeThe number of authorization packets of unknown type received from this server. Monitoring | Statistics | Bandwidth ManagementThis screen shows details of the effects of bandwidth management policies on each tunnel. Only tunnels on which bandwidth management policies are enabled appear on this screen. Figure 17-8 Monitoring | Statistics | Bandwidth Management Screen GroupChoose a group from the Group menu to show bandwidth statistics for users in that group only. The default value is --All--, which displays bandwidth statistics for users in all groups. User NameThe user name identifying a tunnel using a bandwidth management policy. Traffic Rate (kbps)ConformedThe current rate of session traffic (as set by the bandwidth management policy). ThrottledThe rate at which packets are being throttled to maintain the conformed rate. Traffic Volume (bytes)ConformedThe number of bytes of session traffic (as set by the bandwidth management policy). ThrottledThe number of bytes being throttled to maintain the conformed rate. Monitoring | Statistics | CompressionIf you have enabled data compression, this screen shows statistics for data compression on the VPN Concentrator since it was last booted or reset. Figure 17-9 Monitoring | Statistics | Compression Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. IPSec Using IPCompThis screen shows statistics for IPSec data compression using the IPComp compression protocol.
Outbound Pre-CompressionThe total number of bytes of all outbound data before compression. Outbound Post-CompressionThe total number of bytes of all outbound data after compression. RatioThe ratio of Outbound Pre-Compression to Outbound Post-Compression. Inbound Pre-DecompressionThe total number of bytes of all incoming data before any of it is decompressed. Inbound Post-DecompressionThe total number of bytes of all incoming data after decompression. RatioThe ratio of Inbound Post-Decompression to Inbound Pre-Decompression. L2TP/PPTP Using MPPCThis table shows statistics for L2TP and PPTP data compression using the MPPC compression protocol. These MPPC statistics use the following distinctions. (See Figure 17-10.) All data transmitted can be divided into two groups: data intended for compression (A) and data that is not intended for compression (B). Of the data intended for compression, some of it actually compresses (A1) and some does not (A2). (The compression process would actually cause certain data to expand, so this data is left uncompressed.) Figure 17-10 Distinctions Used for Data Compression Statistics Resets ReceivedThe total number of reset requests received from the remote peer. Resets SentThe total number of reset requests sent to the remote peer. Outbound Pre-CompressionThe total number of bytes of outbound data intended for compression. ("A" in Figure 17-10.) Outbound Post-CompressionThe total number of bytes of outbound data actually compressed. ("A1" in Figure 17-10.) Outbound Not CompressedThe total number of bytes of data intended for compression that were not compressed. The compression process would actually cause certain data to expand, so this data is left uncompressed. ("A2" in Figure 17-10.) Compression RatioThe ratio of Outbound Pre-Compression to (Outbound Post-Compression + Outbound Not Compressed). Not Compressed RatioThe ratio of Outbound Pre-Compressed to Outbound Not Compressed. Inbound Pre-DecompressionThe total number of bytes of incoming data intended for decompression. ("A" in Figure 17-10.) Inbound Post-DecompressionThe total number of bytes of incoming data actually decompressed. ("A1" in Figure 17-10.) Inbound Not CompressedThe total number of uncompressed inbound data bytes of the data. ("A2" in Figure 17-10.) Compression RatioThe ratio of (Inbound Post-Decompression + Inbound Not Compressed) to Inbound Pre-Decompression. Not Compressed RatioThe ratio of Inbound Pre-Decompression to Inbound Not Compressed. Monitoring | Statistics | DHCPThis screen shows statistics for DHCP (Dynamic Host Configuration Protocol) activity on the VPN Concentrator since it was last booted or reset. Each row of the table shows data for each session using an IP address via DHCP. To identify DHCP servers to the VPN Concentrator, see Configuration | System | Servers | DHCP. To configure system-wide DHCP functions within the VPN Concentrator, see Configuration | System | IP Routing | DHCP. To use DHCP to assign addresses to clients, see the Configuration | System | Address Management | Assignment screen. Figure 17-11 Monitoring | Statistics | DHCP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Leased IP AddressThe IP address leased from the DHCP server by the remote client. Lease DurationThe duration of the current IP address lease, shown as HH:MM:SS. Time UsedThe total length of time that this session has had an active IP address lease, shown as HH:MM:SS. Time LeftThe time remaining until the current IP address lease expires, shown as HH:MM:SS. DHCP Server AddressThe IP address of the DHCP server that leased this IP address. Monitoring | Statistics | DNSThis screen shows statistics for DNS (Domain Name System) activity on the VPN Concentrator since it was last booted or reset. To configure the VPN Concentrator to communicate with DNS servers, see the Configuration | System | Servers | DNS screen. Figure 17-12 Monitoring | Statistics | DNS Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. RequestsThe total number of DNS queries the VPN Concentrator made since it was last booted or reset. This number equals the sum of the numbers in the four cells below. ResponsesThe number of DNS queries that were successfully resolved. TimeoutsThe number of DNS queries that failed because there was no response from the server. Server UnreachableThe number of DNS queries that failed because the address of the server is not reachable according to the VPN Concentrator's routing table. Other FailuresThe number of DNS queries that failed for an unspecified reason. Monitoring | Statistics | EventsThis screen shows statistics for all events on the VPN Concentrator since it was last booted or reset. To configure event handling, see the Configuration | System | Events screens. Figure 17-13 Monitoring | Statistics | Events Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Event ClassEvent class denotes the source of the event and refers to a specific hardware or software subsystem within the VPN Concentrator. For a description of event classes, see VPN 3000 Series Concentrator Reference Volume 1: Configuration. Event NumberEvent number is an Cisco-assigned reference number that denotes a specific event within the event class. For example, CONFIG event number 2 is "Reading configuration file." This reference number assists Cisco support personnel if they need to examine event statistics. Count of EventsThe number of times that specific event has occurred on the VPN Concentrator since it was last booted or reset. Monitoring | Statistics | FilteringThis screen shows statistics for filtering of traffic that has passed through the interfaces on the VPN Concentrator since it was last booted or reset. To configure filters, see the Configuration | Policy Management | Traffic Management screens. To apply filters to interfaces, see the Configuration | Interfaces screens. To apply filters to users and groups, see the Configuration | User Management screens. Figure 17-14 Monitoring | Statistics | Filtering Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. InterfaceThe VPN Concentrator network interface through which the filtered traffic has passed. Inbound Packets Pre-FilterThe total number of inbound packets received on this interface. Inbound Packets FilteredThe number of inbound packets that have been filtered and dropped on this interface. Inbound Packets Post FilterThe number of inbound packets that have been filtered and forwarded on this interface. This number equals Inbound Packets Pre-Filter minus Inbound Packets Filtered. Outbound Packets Pre-FilterThe total number of outbound packets received on this interface. Outbound Packets FilteredThe number of outbound packets that have been filtered and dropped on this interface. Outbound Packets Post FilterThe number of outbound packets that have been filtered and forwarded on this interface. This number equals Outbound Packets Pre-Filter minus Outbound Packets Filtered. Monitoring | Statistics | HTTPThis screen shows statistics for HTTP activity on the VPN Concentrator since it was last booted or reset. To configure system-wide HTTP server parameters, see the Configuration | System | Management Protocols | HTTP screen. Figure 17-15 Monitoring | Statistics | HTTP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Octets Sent/ReceivedThe total number of HTTP octets (bytes) sent or received since the VPN Concentrator was last booted or reset. Packets Sent/ReceivedThe total number of HTTP packets sent or received since the VPN Concentrator was last booted or reset. Packets Sent Sockets/SessionsThe number of HTTP sessions on the VPN Concentrator. ActiveThe number of currently active HTTP connections on the VPN Concentrator. PeakThe maximum number of HTTP connections that were simultaneously active on the VPN Concentrator since it was last booted or reset. TotalThe total number of HTTP connections on the VPN Concentrator since it was last booted or reset. HTTP SessionsThis section provides information about HTTP sessions on the VPN Concentrator since it was last booted or reset. Login NameThe name of the administrative user for the HTTP session. IP AddressThe IP address of the HTTP session. Login TimeThe time when the HTTP session began. EncryptionThe encryption method used in the HTTP session. Octets Sent/ReceivedNumber of octets sent or received during the HTTP session. Packets Sent/ReceivedNumber of packets sent or received during the HTTP session. Sockets ActiveThe number of currently active sockets for the HTTP session. Sockets PeakThe maximum number of sockets simultaneously active during the HTTP session. Sockets TotalThe total number of sockets active during the HTTP session. Max ConnectionsThe maximum number of concurrent HTTP connections for the VPN Concentrator since it was last rebooted or reset. Monitoring | Statistics | IPSecThis screen shows statistics for IPSec activityincluding current IPSec tunnelson the VPN Concentrator since it was last booted or reset. These statistics conform to the IETF draft for the IPSec Flow Monitoring MIB. The Monitoring | Sessions | Detail screens also show IPSec data. To configure system-wide IPSec parameters and LAN-to-LAN connections, see the Configuration | System | Tunneling Protocols | IPSec screens. To configure IPSec parameters for users and groups, see Configuration | User Management. To configure IPSec parameters and SAs on rules in filters that govern data traffic, see Configuration | Policy Management | Traffic Management. Figure 17-16 Monitoring | Statistics | IPSec Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. IKE (Phase 1) StatisticsThis table provides IPSec Phase 1 (IKE: Internet Key Exchange) global statistics. During IPSec Phase 1 (IKE), the two peers establish control tunnels through which they negotiate Security Associations. Active TunnelsThe number of currently active IKE control tunnels, both for LAN-to-LAN connections and remote access. Total TunnelsThe cumulative total of all currently and previously active IKE control tunnels, both for LAN-to-LAN connections and remote access. Received BytesThe cumulative total of bytes (octets) received by all currently and previously active IKE tunnels. Sent BytesThe cumulative total of bytes (octets) sent by all currently and previously active IKE tunnels. Received PacketsThe cumulative total of packets received by all currently and previously active IKE tunnels. Sent PacketsThe cumulative total of packets sent by all currently and previously active IKE tunnels. Received Packets DroppedThe cumulative total of packets that were dropped during receive processing by all currently and previously active IKE tunnels. If there is a problem with the content of a packet (such as hash failure, parsing error, or encryption failure) received in Phase 1 or the negotiation of Phase 2, the system drops the packet. This number should be zero or very small; if not, check for misconfiguration. Sent Packets DroppedThe cumulative total of packets that were dropped during send processing by all currently and previously active IKE tunnels. This number should be zero; if not, check for a network problem, check the event log for an internal subsystem failure, or contact Cisco support. Received NotifiesThe cumulative total of notify packets received by all currently and previously active IKE tunnels. A notify packet is an informational packet that is sent in response to a bad packet or to indicate status, for example: error packets, keepalive packets, etc. Sent NotifiesThe cumulative total of notify packets sent by all currently and previously active IKE tunnels. See comments for Received Notifies. Received Phase-2 ExchangesThe cumulative total of IPSec Phase-2 exchanges received by all currently and previously active IKE tunnels, in other words, the total of Phase-2 negotiations received that were initiated by a remote peer. A complete exchange consists of three packets. Sent Phase-2 ExchangesThe cumulative total of IPSec Phase-2 exchanges that were sent by all currently and previously active and IKE tunnels, in other words, the total of Phase-2 negotiations initiated by this VPN Concentrator. Invalid Phase-2 Exchanges ReceivedThe cumulative total of IPSec Phase-2 exchanges that were received, found to be invalid because of protocol errors, and dropped, by all currently and previously active IKE tunnels. In other words, the total of Phase-2 negotiations that were initiated by a remote peer but that this VPN Concentrator dropped because of protocol errors. Invalid Phase-2 Exchanges SentThe cumulative total of IPSec Phase-2 exchanges that were sent and were found to be invalid, by all currently and previously active IKE tunnels. Rejected Received Phase-2 ExchangesThe cumulative total of IPSec Phase-2 exchanges that were initiated by a remote peer, received, and rejected by all currently and previously active IKE tunnels. Rejected exchanges indicate policy-related failures, such as configuration problems. Rejected Sent Phase-2 ExchangesThe cumulative total of IPSec Phase-2 exchanges that were initiated by this VPN Concentrator, sent, and rejected, by all currently and previously active IKE tunnels. See the previous comment. Phase-2 SA Delete Requests ReceivedThe cumulative total of requests to delete IPSec Phase-2 Security Associations received by all currently and previously active IKE tunnels. Phase-2 SA Delete Requests SentThe cumulative total of requests to delete IPSec Phase-2 Security Associations sent by all currently and previously active IKE tunnels. Initiated TunnelsThe cumulative total of IKE tunnels that this VPN Concentrator initiated. The VPN Concentrator initiates tunnels only for LAN-to-LAN connections. Failed Initiated TunnelsThe cumulative total of IKE tunnels that this VPN Concentrator initiated and that failed to activate. Failed Remote TunnelsThe cumulative total of IKE tunnels that remote peers initiated and that failed to activate. Authentication FailuresThe cumulative total of authentication attempts that failed, by all currently and previously active IKE tunnels. Authentication failures indicate problems with preshared keys, digital certificates, or user-level authentication. Decryption FailuresThe cumulative total of decryptions that failed, by all currently and previously active IKE tunnels. This number should be at or near zero; if not, check for misconfiguration or SEP module problems. Hash Validation FailuresThe cumulative total of hash validations that failed, by all currently and previously active IKE tunnels. Hash validation failures usually indicate misconfiguration or mismatched preshared keys or digital certificates. System Capability FailuresThe cumulative total of system capacity failures that occurred during processing of all currently and previously active IKE tunnels. These failures indicate that the system has run out of memory, or that the tunnel count exceeds the system maximum. No-SA FailuresThe cumulative total of nonexistent-Security Association failures that occurred during processing of all currently and previously active IKE tunnels. These failures occur when the system receives a packet for which it has no Security Association, and might indicate synchronization problems. IPSec (Phase 2) StatisticsThis table provides IPSec Phase 2 global statistics. During IPSec Phase 2, the two peers negotiate Security Associations that govern traffic within the tunnel. Active TunnelsThe number of currently active IPSec Phase-2 tunnels, both for LAN-to-LAN connections and remote access. Total TunnelsThe cumulative total of all currently and previously active IPSec Phase-2 tunnels, both for LAN-to-LAN connections and remote access. Received BytesThe cumulative total of bytes (octets) received by all currently and previously active IPSec Phase-2 tunnels, before decompression. In other words, total bytes of IPSec-only data received by the IPSec subsystem, before decompressing the IPSec payload. Sent BytesThe cumulative total of bytes (octets) sent by all currently and previously active IPSec Phase-2 tunnels, after compression. In other words, total bytes of IPSec-only data sent by the IPSec subsystem, after compressing the IPSec payload. Received PacketsThe cumulative total of packets received by all currently and previously active IPSec Phase-2 tunnels. Sent PacketsThe cumulative total of packets sent by all currently and previously active IPSec Phase-2 tunnels. Received Packets DroppedThe cumulative total of packets dropped during receive processing by all currently and previously active IPSec Phase-2 tunnels, excluding packets dropped due to anti-replay processing. If there is a problem with the content of a packet, the system drops the packet. This number should be zero or very small; if not, check for misconfiguration. Received Packets Dropped (Anti-Replay)The cumulative total of packets dropped during receive processing due to anti-replay errors, by all currently and previously active IPSec Phase-2 tunnels. If the sequence number of a packet is a duplicate or out of bounds, there might be a faulty network or a security breach, and the system drops the packet. Sent Packets DroppedThe cumulative total of packets dropped during send processing by all currently and previously active IPSec Phase-2 tunnels. This number should be zero; if not, check for a network problem, check the event log for an internal subsystem failure, or contact Cisco support. Inbound AuthenticationsThe cumulative total number of inbound individual packet authentications performed by all currently and previously active IPSec Phase-2 tunnels. Failed Inbound AuthenticationsThe cumulative total of inbound packet authentications that failed, by all currently and previously active IPSec Phase-2 tunnels. Failed authentications could indicate corrupted packets or a potential security attack ("man in the middle"). Outbound AuthenticationsThe cumulative total of outbound individual packet authentications performed by all currently and previously active IPSec Phase-2 tunnels. Failed Outbound AuthenticationsThe cumulative total of outbound packet authentications that failed, by all currently and previously active IPSec Phase-2 tunnels. This number should be zero or very small; if not, check the event log for an internal IPSec subsystem problem. DecryptionsThe cumulative total of inbound decryptions performed by all currently and previously active IPSec Phase-2 tunnels. Failed DecryptionsThe cumulative total of inbound decryptions that failed, by all currently and previously active IPSec Phase-2 tunnels. This number should be zero or very small; if not, check for misconfiguration or SEP module problems. EncryptionsThe cumulative total of outbound encryptions performed by all currently and previously active IPSec Phase-2 tunnels. Failed EncryptionsThe cumulative total of outbound encryptions that failed, by all currently and previously active IPSec Phase-2 tunnels. This number should be zero or very small; if not, check for IPSec subsystem or SEP module problems. System Capability FailuresThe total number of system capacity failures that occurred during processing of all currently and previously active IPSec Phase-2 tunnels. These failures indicate that the system has run out of memory or some other critical resource; check the event log. No-SA FailuresThe cumulative total of nonexistent-Security Association failures which occurred during processing of all currently and previously active IPSec Phase-2 tunnels. These failures occur when the system receives an IPSec packet for which it has no Security Association, and might indicate synchronization problems. Protocol Use FailuresThe cumulative total of protocol use failures that occurred during processing of all currently and previously active IPSec Phase-2 tunnels. These failures indicate errors parsing IPSec packets. Monitoring | Statistics | L2TPThis screen shows statistics for L2TP activity on the VPN Concentrator since it was last booted or reset, and for current L2TP sessions. The Monitoring | Sessions | Detail screens also show L2TP data. To configure system-wide L2TP parameters, see the Configuration | System | Tunneling Protocols | L2TP screen. To configure L2TP parameters for users and groups, see Configuration | User Management. To configure L2TP on rules in filters that govern data traffic, see Configuration | Policy Management | Traffic Management. Figure 17-17 Monitoring | Statistics | L2TP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Total TunnelsThe total number of L2TP tunnels successfully established since the VPN Concentrator was last booted or reset. Active TunnelsThe number of L2TP tunnels that are currently active. Maximum TunnelsThe maximum number of L2TP tunnels that have been simultaneously active on the VPN Concentrator since it was last booted or reset. Failed TunnelsThe number of L2TP tunnels that failed to become established since the VPN Concentrator was last booted or reset. Total SessionsThe total number of user sessions successfully established through L2TP tunnels since the VPN Concentrator was last booted or reset. Active SessionsThe number of user sessions that are currently active through PPTP tunnels. The L2TP Sessions table shows statistics for these sessions. Maximum SessionsThe maximum number of user sessions that have been simultaneously active through L2TP tunnels on the VPN Concentrator since it was last booted or reset. Failed SessionsThe number of sessions that failed to become established through L2TP tunnels since the VPN Concentrator was last booted or reset. Rx Octets Control / DataThe number of L2TP control / data channel octets (bytes) received by the VPN Concentrator since it was last booted or reset. Rx Packets Control / DataThe number of L2TP control / data channel packets received by the VPN Concentrator since it was last booted or reset. Rx Discards Control / DataThe number of L2TP control / data channel packets received and discarded by the VPN Concentrator since it was last booted or reset. Tx Octets Control / DataThe number of L2TP control/data channel octets (bytes) transmitted by the VPN Concentrator since it was last booted or reset. Tx Packets Control / DataThe number of L2TP control/data channel packets transmitted by the VPN Concentrator since it was last booted or reset. L2TP SessionsThis table shows statistics for active L2TP sessions on the VPN Concentrator. Each active session is a row. Remote IPThe IP address of the remote host that established the L2TP tunnel for this session, in other words, the tunnel endpoint IP address. The Monitoring | Sessions screen shows the IP address assigned to the client using the tunnel. UsernameThe username for the session within an L2TP tunnel. This is typically the login name of the remote user. SerialThe serial number of the session within an L2TP tunnel. If there are multiple sessions using a tunnel, each session has a unique serial number. Receive OctetsThe total number L2TP data octets (bytes) received by this session. Receive PacketsThe total number of L2TP data packets received by this session. Receive DiscardsThe total number of L2TP data packets received and discarded by this session. Receive ZLBThe total number of L2TP Zero Length Body acknowledgement data packets received by this session. ZLB packets are sent as acknowledgement packets when there is no data packet on which to piggyback an acknowledgement. Transmit OctetsThe total number of L2TP data octets (bytes) transmitted by this session. Transmit PacketsThe total number of L2TP data packets transmitted by this session. Transmit ZLBThe total number of L2TP Zero Length Body acknowledgement packets transmitted by this session. ZLB packets are sent as acknowledgement packets when there is no data packet on which to piggyback an acknowledgement. Monitoring | Statistics | Load BalancingThis screen shows statistics for load balancing on the VPN Concentrator since it was last booted or reset. Figure 17-18 Monitoring | Statistics | Load Balancing Screen Enabled?Indicates whether load balancing has been enabled on this VPN Concentrator. RoleThe role of this VPN Concentrator within the virtual cluster. It is either a virtual cluster master or a secondary device. LoadThe percentage of the cluster's total session load that this VPN Concentrator is carrying. Number of PeersThe number of other VPN Concentrators in the virtual cluster. PeersThe peers chart shows configuration details and session statistics of the other VPN Concentrators in the virtual cluster. Private IP AddressThe private IP address of the peer. Public IP AddressThe public IP address of the peer. Mapped IP AddressThe NAT address of the peer, if it has one. RoleThe role of the peer within the virtual cluster. It is either a virtual cluster master or a secondary device. Device TypeThe VPN Concentrator model (such as 3005 or 3015) of the peer. LoadThe percentage of the cluster's total session load that the peer is carrying. You can view this information only from the virtual cluster master device. If you are viewing this field from a secondary device, its value is N/A. SessionsThe number of currently active sessions on the peer. You can view this information only from the virtual cluster master device. If you are viewing this field from a secondary device, its value is N/A. PriorityThe likelihood that this peer will become the master at power-up or if the current master fails. For more information on priorities, see the Configuration | System | Load Balancing section. DurationThe length of time this device has been connected to the virtual cluster. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Monitoring | Statistics | NATThis screen shows statistics for NAT (Network Address Translation) activity on the VPN Concentrator since it was last booted or reset. Figure 17-19 Monitoring | Statistics | NAT screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Packets In/OutThe total of NAT packets inbound and outbound since the last time the VPN Concentrator was rebooted or reset. Translations ActiveThe number of currently active NAT sessions. Translations PeakThe maximum number of NAT sessions that were simultaneously active on the VPN Concentrator since it was last booted or reset. Translations TotalThe total number of NAT sessions on the VPN Concentrator since it was last booted or reset. NAT SessionsThe following sections provide detailed information about active NAT sessions on the VPN Concentrator. Source IP Address/PortThe source IP address and port for the NAT session. Destination IP Address/PortThe destination IP address and port for the NAT session. Translated IP Address/PortThe translated IP address and port for the NAT session. The VPN Concentrator uses this port number to keep track of which devices initiate data transfer; by keeping this record, the VPN Concentrator is able to correctly route responses. DirectionThe direction, inbound or outbound, of the data transferred for the NAT session. AgeThe number of half seconds remaining until the NAT session times out. TypeThe type of packets for the NAT session. The possible types are: Translated Bytes/PacketsThe total number of translated bytes and packets for the NAT session. Monitoring | Statistics | PPTPThis screen shows statistics for PPTP activity on the VPN Concentrator since it was last booted or reset, and for current PPTP sessions. The Monitoring | Sessions | Detail screens also show PPTP data. To configure system-wide PPTP parameters, see the Configuration | System | Tunneling Protocols | PPTP screen. To configure PPTP parameters for users and groups, see Configuration | User Management. To configure PPTP on rules in filters that govern data traffic, see Configuration | Policy Management | Traffic Management. Figure 17-20 Monitoring | Statistics | PPTP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Total TunnelsThe total number of PPTP tunnels created since the VPN Concentrator was last booted or reset, including those tunnels that failed to be established. Active TunnelsThe number of PPTP tunnels that are currently active. Maximum TunnelsThe maximum number of PPTP tunnels that have been simultaneously active on the VPN Concentrator since it was last booted or reset. Total SessionsThe total number of user sessions through PPTP tunnels since the VPN Concentrator was last booted or reset. Active SessionsThe number of user sessions that are currently active through PPTP tunnels. The PPTP Sessions table shows statistics for these sessions. Maximum SessionsThe maximum number of user sessions that have been simultaneously active through PPTP tunnels on the VPN Concentrator since it was last booted or reset. Rx Octets Control / DataThe number of PPTP control/data octets (bytes) received by the VPN Concentrator since it was last booted or reset. Rx Packets Control / DataThe number of PPTP control/data packets received by the VPN Concentrator since it was last booted or reset. Rx Discards Control / DataThe number of PPTP control/data packets received and discarded by the VPN Concentrator since it was last booted or reset. Tx Octets Control / DataThe number of PPTP control/data octets (bytes) transmitted by the VPN Concentrator since it was last booted or reset. Tx Packets Control / DataThe number of PPTP control/data packets transmitted by the VPN Concentrator since it was last booted or reset. PPTP SessionsThis table shows statistics for active PPTP sessions on the VPN Concentrator. Each active session is a row. Peer IPThe IP address of the peer host that established the PPTP tunnel for this session, in other words, the tunnel endpoint IP address. The Monitoring | Sessions screen shows the IP address assigned to the client using the tunnel. UsernameThe username for the session within a PPTP tunnel. This is typically the login name of the remote user. Receive OctetsThe total number of PPTP data octets (bytes) received by this session. Receive PacketsThe total number of PPTP data packets received by this session. Receive DiscardsThe total number of PPTP data packets received and discarded by this session. Receive ZLBThe total number of PPTP Zero Length Body acknowledgement data packets received by this session. ZLB packets are sent as GRE acknowledgement packets when there is no data packet on which to piggyback an acknowledgement. Transmit OctetsThe total number of PPTP data octets (bytes) transmitted by this session. Transmit PacketsThe total number of PPTP data packets transmitted by this session. Transmit ZLBThe total number of PPTP Zero Length Body acknowledgement packets transmitted by this session. ZLB packets are sent as GRE acknowledgement packets when there is no data packet on which to piggyback an acknowledgement. ACK TimeoutsThe total number of acknowledgement timeouts seen on PPTP data packets for this session. When the system times out waiting for a data packet on which to piggyback an acknowledgement, it sends a ZLB instead. Therefore, this number should equal the Transmit ZLB number. FlowThe state of packet flow control for this PPTP session:
Monitoring | Statistics | SSHThis screen shows statistics for SSH (Secure Shell) protocol traffic on the VPN Concentrator since it was last booted or reset. To configure SSH, see Configuration | System | Management Protocols | SSH. Figure 17-21 Monitoring | Statistics | SSH Screen Octets Sent / ReceivedThe total number of SSH octets (bytes) sent / received since the VPN Concentrator was last booted or reset. Packets Sent / ReceivedThe total number of SSH packets sent / received since the VPN Concentrator was last booted or reset. Total SessionsThe total number of SSH sessions since the VPN Concentrator was last booted or reset. Active SessionsThe number of currently active SSH sessions. Max SessionsThe maximum number of simultaneously active SSH sessions on the VPN Concentrator. Monitoring | Statistics | SSLThis screen shows statistics for SSL (Secure Sockets Layer) protocol traffic on the VPN Concentrator since it was last booted or reset. To configure SSL, see Configuration | System | Management Protocols | SSL. Figure 17-22 Monitoring | Statistics | SSL Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Unencrypted Inbound OctetsThe number of octets (bytes) of inbound traffic output by the decryption engine. Encrypted Inbound OctetsThe number of octets (bytes) of encrypted inbound traffic sent to the decryption engine. This number includes negotiation traffic. Unencrypted Outbound OctetsThe number of unencrypted outbound octets (bytes) sent to the encryption engine. Encrypted Outbound OctetsThe number of octets (bytes) of outbound traffic output by the encryption engine. This number includes negotiation traffic. Total SessionsThe total number of SSL sessions. Active SessionsThe number of currently active SSL sessions. Max Active SessionsThe maximum number of SSL sessions simultaneously active at any one time. Monitoring | Statistics | TelnetThis screen shows statistics for Telnet activity on the VPN Concentrator since it was last booted or reset, and for current Telnet sessions. To configure the VPN Concentrator's Telnet server, see the Configuration | System | Management Protocols | Telnet screen. Figure 17-23 Monitoring | Statistics | Telnet Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Active SessionsThe number of active Telnet sessions. The Telnet Sessions table shows statistics for these sessions. Attempted SessionsThe total number of attempts to establish Telnet sessions on the VPN Concentrator since it was last booted or reset. Successful SessionsThe total number of Telnet sessions successfully established on the VPN Concentrator since it was last booted or reset. Telnet SessionsThis table shows statistics for active Telnet sessions on the VPN Concentrator. Each active session is a row. Client IP Address:PortThe IP address and TCP source port number of this session's remote Telnet client. Inbound Octets TotalThe total number of Telnet octets (bytes) received by this session. Inbound Octets CommandThe number of octets (bytes) containing Telnet commands or options, received by this session. Inbound Octets DiscardedThe number of Telnet octets (bytes) received and dropped during input processing by this session. Outbound Octets TotalThe total number of Telnet octets (bytes) transmitted by this session. Outbound Octets DroppedThe number of outbound Telnet octets dropped during output processing by this session. Monitoring | Statistics | VRRPThis screen shows status and statistics for VRRP (Virtual Router Redundancy Protocol) activity on the VPN Concentrator since it was last booted or reset. To configure VRRP, see the Configuration | System | IP Routing | Redundancy screen. Figure 17-24 Monitoring | Statistics | VRRP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Checksum ErrorsThe total number of VRRP packets received with an invalid VRRP checksum value. Version ErrorsThe total number of VRRP packets received with an unknown or unsupported version number. The VPN Concentrator supports VRRP version 2 as defined in RFC 2338. VRID ErrorsThe total number of VRRP packets received with an invalid VRRP Group ID number. VRIDThe identification number that uniquely identifies the group of virtual routers to which this VPN Concentrator belongs. Virtual RoutersThis table shows statistics for the virtual router on each configured VRRP interface on this VPN Concentrator. Interface: 1 (Private), 2 (Public), 3 (External)The Ethernet interface configured for VRRP. StatusThe status of the VRRP router in this VPN Concentrator: Became MasterThe total number of times that this VPN Concentrator has become a VRRP Master router after having a different role. This number should be the same in all columns. Advertisements ReceivedThe total number of VRRP advertisements received by this interface. Advertisement Interval ErrorsThe total number of VRRP advertisement packets received by this interface, in which the advertisement interval differs from the interval configured on this VPN Concentrator. Authentication FailuresThe total number of VRRP packets received by this interface that do not pass the authentication check. Time-to-Live ErrorsThe total number of VRRP packets received by this interface with IP TTL (Time-To-Live) not equal to 255. All VRRP packets must have TTL = 255. Priority 0 Packets ReceivedThe total number of VRRP packets received by this interface with a priority of 0. Priority 0 packets indicate that the current Master router has stopped participating in VRRP. Priority 0 Packets SentThe total number of VRRP packets sent by this interface with a priority of 0. Priority 0 packets indicate that the current Master router has stopped participating in VRRP. Invalid Type ReceivedThe number of VRRP packets received by this interface with an invalid value in the Type field. For VRRP version 2, the only valid Type value is 1, which indicates an advertisement packet. Address List ErrorsThe total number of packets received for which the address list does not match the list configured on this VPN Concentrator. Invalid Authentication ErrorsThe total number of packets received by this interface with an unknown authentication type. Mismatch Authentication ErrorsThe total number of packets received by this interface with an authentication type that differs from the configured authentication type. Packet Length ErrorsThe total number of packets received by this interface with a packet length less than the length of the VRRP header. Monitoring | Statistics | MIB-IIThis section of the Manager lets you view statistics that are recorded in standard MIB-II objects on the VPN Concentrator. MIB-II (Management Information Base, version 2) objects are variables that contain data about the system. They are defined as part of the Simple Network Management Protocol (SNMP); and SNMP-based network management systems can query the VPN Concentrator to gather the data. Each subsequent screen displays the data for a standard MIB-II group of objects:
To configure and enable the VPN Concentrator's SNMP server, see the Configuration | System | Management Protocols | SNMP screen. Figure 17-25 Monitoring | Statistics | MIB-II Screen Monitoring | Statistics | MIB-II | InterfacesThis screen shows statistics in MIB-II objects for VPN Concentrator interfaces since the system was last booted or reset. This screen also shows statistics for VPN tunnels as logical interfaces. RFC 2233 defines interface MIB objects. Figure 17-26 Monitoring | Statistics | MIB-II | Interfaces Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. InterfaceThe VPN Concentrator interface: StatusThe operational status of this interface:
Unicast InThe number of unicast packets that were received by this interface. Unicast packets are those addressed to a single host. Unicast OutThe number of unicast packets that were routed to this interface for transmission, including those that were discarded or not sent. Unicast packets are those addressed to a single host. Multicast InThe number of multicast packets that were received by this interface. Multicast packets are those addressed to a specific group of hosts. Multicast OutThe number of multicast packets that were routed to this interface for transmission, including those that were discarded or not sent. Multicast packets are those addressed to a specific group of hosts. Broadcast InThe number of broadcast packets that were received by this interface. Broadcast packets are those addressed to all hosts on a network. Broadcast OutThe number of broadcast packets that were routed to this interface for transmission, including those that were discarded or not sent. Broadcast packets are those addressed to all hosts on a network. Monitoring | Statistics | MIB-II | TCP/UDPThis screen shows statistics in MIB-II objects for TCP and UDP traffic on the VPN Concentrator since it was last booted or reset. RFC 2012 defines TCP MIB objects, and RFC 2013 defines UDP MIB objects. Figure 17-27 Monitoring | Statistics | MIB-II | TCP/UDP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. TCP Segments ReceivedThe total number of segments received, including those received in error and those received on currently established connections. Segment is the official TCP name for what is often called a data packet. TCP Segments TransmittedThe total number of segments sent, including those on currently established connections but excluding those containing only retransmitted bytes. Segment is the official TCP name for what is casually called a data packet. TCP Segments RetransmittedThe total number of segments retransmitted; that is, the number of TCP segments transmitted containing one or more previously transmitted bytes. Segment is the official TCP name for what is casually called a data packet. TCP Timeout MinThe minimum value permitted for TCP retransmission timeout, measured in milliseconds. TCP Timeout MaxThe maximum value permitted for TCP retransmission timeout, measured in milliseconds. TCP Connection LimitThe limit on the total number of TCP connections that the system can support. A value of -1 means there is no limit. TCP Active OpensThe number of TCP connections that went directly from an unconnected state to a connection-synchronizing state, bypassing the listening state. These connections are allowed, but they are usually in the minority. TCP Passive OpensThe number of TCP connections that went from a listening state to a connection-synchronizing state. These connections are usually in the majority. TCP Attempt FailuresThe number of TCP connection attempts that failed. Technically this is the number of TCP connections that went to an unconnected state, plus the number that went to a listening state, from a connection-synchronizing state. TCP Established ResetsThe number of established TCP connections that abruptly closed, bypassing graceful termination. TCP Current EstablishedThe number of TCP connections that are currently established or are gracefully terminating. UDP Datagrams ReceivedThe total number of UDP datagrams received. Datagram is the official UDP name for what is casually called a data packet. UDP Datagrams TransmittedThe total number of UDP datagrams sent. Datagram is the official UDP name for what is casually called a data packet. UDP Errored DatagramsThe number of received UDP datagrams that could not be delivered for reasons other than the lack of an application at the destination port (UDP No Port). Datagram is the official UDP name for what is casually called a data packet. UDP No PortThe total number of received UDP datagrams that could not be delivered because there was no application at the destination port. Datagram is the official UDP name for what is casually called a data packet. Monitoring | Statistics | MIB-II | IPThis screen shows statistics in MIB-II objects for IP traffic on the VPN Concentrator since it was last booted or reset. RFC 2011 defines IP MIB objects. Figure 17-28 Monitoring | Statistics | MIB-II | IP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Packets Received (Total)The total number of IP data packets received by the VPN Concentrator, including those received with errors. Packets Received (Header Errors)The number of IP data packets received and discarded due to errors in IP headers, including bad check sums, version number mismatches, other format errors, etc. Packets Received (Address Errors)The number of IP data packets received and discarded because the IP address in the destination field was not a valid address for the VPN Concentrator. This count includes invalid addresses (for example, 0.0.0.0) and addresses of unsupported classes (for example, Class E). Packets Received (Unknown Protocols)The number of IP data packets received and discarded because of an unknown or unsupported protocol. Packets Received (Discarded)The number of IP data packets received that had no problems preventing continued processing, but that were discarded (for example, for lack of buffer space). This number does not include any packets discarded while awaiting reassembly. Packets Received (Delivered)The number of IP data packets received and successfully delivered to IP user protocols (including ICMP) on the VPN Concentrator; i.e., the VPN Concentrator was the final destination. Packets ForwardedThe number of IP data packets received and forwarded to destinations other than the VPN Concentrator. Outbound Packets DiscardedThe number of outbound IP data packets that had no problems preventing their transmission to a destination, but that were discarded (for example, for lack of buffer space). Outbound Packets with No RouteThe number of outbound IP data packets discarded because no route could be found to transmit them to their destination. This number includes any packets that the VPN Concentrator could not route because all of its default routers are down. Packets Transmitted (Requests)The number of IP data packets that local IP user protocols (including ICMP) supplied to transmission requests. This number does not include any packets counted in Packets Forwarded. Fragments Needing ReassemblyThe number of IP fragments received by the VPN Concentrator that needed to be reassembled. Reassembly SuccessesThe number of IP data packets successfully reassembled. Reassembly FailuresThe number of failures detected by the IP reassembly algorithm (for whatever reason: timed out, errors, etc.). This number is not necessarily a count of discarded IP fragments since some algorithms can lose track of the number of fragments by combining them as they are received. Fragmentation SuccessesThe number of IP data packets that have been successfully fragmented by the VPN Concentrator. Fragmentation FailuresThe number of IP data packets that have been discarded because they needed to be fragmented but could not be fragmented (for example, because the Don't Fragment flag was set). Fragments CreatedThe number of IP data packet fragments that have been generated by the VPN Concentrator. Monitoring | Statistics | MIB-II | RIPThis screen shows statistics in MIB-II objects for RIP version 2 traffic on the VPN Concentrator since it was last booted or reset. RFC 1724 defines RIP version 2 MIB objects. To configure RIP on interfaces, see Configuration | Interfaces. Figure 17-29 Monitoring | Statistics | MIB-II | RIP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Global Route ChangesThe total number of route changes made to the IP route database by RIP. This number does not include changes that only refresh the age route of a route. Global QueriesThe total number of responses sent to RIP queries from other systems. InterfacesThis table shows a row of statistics for each configured interface. Interface AddressThe IP address configured on the interface. Received Bad PacketsThe number of RIP response packets received by this interface that were subsequently discarded for any reason (such as wrong version or unknown command type). Received Bad RoutesThe number of routes in valid RIP packets received by this interface that were ignored for any reason (such as unknown address family or invalid metric). Sent UpdatesThe number of triggered RIP updates actually sent by this interface. This number does not include full updates sent containing new information. Monitoring | Statistics | MIB-II | OSPFThis screen shows statistics in MIB-II objects for OSPF version 2 traffic on the VPN Concentrator since it was last booted or reset. RFC 1850a defines OSPF version 2 MIB objects. To configure OSPF on interfaces, see Configuration | Interfaces. To configure system-wide OSPF parameters, see Configuration | System | IP Routing. Figure 17-30 Monitoring | Statistics | MIB-II | OSPF Screen RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Router IDThe VPN Concentrator OSPF router ID. This ID uniquely identifies the VPN Concentrator to other OSPF routers in its domain. While the format is that of an IP address, it functions only as an identifier and not an address. By convention, however, this identifier is the same as the IP address of the interface that is connected to the OSPF router network. 0.0.0.0 means no router is configured. VersionThe current version number of the OSPF protocol running on the VPN Concentrator. External LSA CountThe number of external Link-State Advertisements (LSAs) in the link-state database. LSAs from neighboring OSPF Autonomous Systems (AS) describe the state of the AS router's interfaces and routing paths. External LSA ChecksumThe sum of the check sums of the external Link-State Advertisements in the link-state database. You can use this sum to determine if there has been a change in the OSPF router link-state database of the system, and to compare its database with other routers. LSAs OriginatedThe number of new Link-State Advertisements that the system has originated. This number increments each time the OSPF router originates a new LSA. New LSAs ReceivedThe number of Link-State Advertisements received that are completely new LSAs. This number does not include newer instances of self-originated LSAs. LSA Database LimitThe maximum number of external LSAs that can be stored in the link-state database. A value of -1 means there is no limit. Designated RoutersThis table shows a row of statistics for each enabled VPN Concentrator interface. When OSPF routing is enabled on an interface, that interface communicates with other OSPF routers in its area, and each area elects one OSPF router to be the Designated Router. Interface AddressThe IP address of the VPN Concentrator interface that communicates with its area. Interface NameThe VPN Concentrator interface that communicates with its area: Designated RouterThe IP address of the Designated Router in this OSPF area. Backup Designated RouterThe IP address of the backup Designated Router in this OSPF area. NeighborsThis table shows a row of statistics for each OSPF neighbor, for all areas in which the VPN Concentrator participates. A neighbor is another OSPF router in an OSPF area, and this table includes all such areas for the VPN Concentrator. IP AddressThe IP address of the neighboring OSPF router. Router IDThe router ID of the neighboring OSPF router, which uniquely identifies it to other OSPF routers in its domain. While the format is that of an IP address, it functions only as an identifier. By convention, however, it is the same as the IP address of the interface that is connected to the OSPF router network. StateThe state of the relationship with this neighboring OSPF router:
AreasThis table shows a row of statistics for each OSPF Area. Area IDThe Area ID identifies the subnet area within the OSPF Autonomous System or domain. While its format is the same as an IP address, it functions only as an identifier and not an address. 0.0.0.0 identifies a special areathe backbonethat contains all area border routers. SPF RunsThe number of times that the system has calculated the intra-area route table (SPF, or Shortest Path First table) using the link-state database of this area. AS Border RoutersThe total number of Autonomous System border routers reachable within this area. Area Border RoutersThe total number of area border routers reachable within this area. Area LSA CountThe total number of Link-State Advertisements in the link-state database of this area, excluding AS external LSAs. Area LSA ChecksumThe sum of the check sums of the Link-State Advertisements in the link-state database of this area. This sum excludes external LSAs. You can use this sum to determine if there has been a change in the link-state database of the area, and to compare its database with other routers. External LSAsThis table shows a row for each external Link-State Advertisement in the link-state database. Area IDThe Area ID identifies the Area from which the LSA was received. TypeThe LSA type. Each LSA type has a different format:
Link State IDEither a router ID or an IP address that identifies the piece of the routing domain being described by the LSA. Router IDThe identifier of the router in the Autonomous System that originated this LSA. SequenceThe sequence number of this LSA. Sequence numbers are linear. They are used to detect old and duplicate LSAs. The larger the number, the more recent the LSA. AgeThe age of the LSA in seconds. Monitoring | Statistics | MIB-II | ICMPThis screen shows statistics in MIB-II objects for ICMP traffic on the VPN Concentrator since it was last booted or reset. RFC 2011 defines ICMP MIB objects. Figure 17-31 Monitoring | Statistics | MIB-II | ICMP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Total Received / TransmittedThe total number of ICMP messages that the VPN Concentrator received / sent. This number includes messages counted as Errors Received / Transmitted. ICMP messages solicit and provide information about the network environment. Errors Received / TransmittedThe number of ICMP messages that the VPN Concentrator received but determined to have ICMP-specific errors (bad ICMP check sums, bad length, etc.). The number of ICMP messages that the VPN Concentrator did not send due to problems within ICMP such as a lack of buffers. Destination Unreachable Received / TransmittedThe number of ICMP Destination Unreachable messages received / sent. Destination Unreachable messages apply to many network situations, including inability to determine a route, an unusable source route specified, and the Don't Fragment flag set for a packet that must be fragmented. Time Exceeded Received / TransmittedThe number of ICMP Time Exceeded messages received / sent. Time Exceeded messages indicate that the lifetime of the packet has expired, or that a router cannot reassemble a packet within a time limit. Parameter Problems Received / TransmittedThe number of ICMP Parameter Problem messages received / sent. Parameter Problem messages indicate a syntactic or semantic error in an IP header. Source Quench Received / TransmittedThe number of ICMP Source Quench messages received / sent. Source Quench messages provide rudimentary flow control; they request a reduction in the rate of sending traffic on the network. Redirects Received / TransmittedThe number of ICMP Redirect messages received / sent. Redirect messages advise that there is a better route to a particular destination. Echo Requests (PINGs) Received / TransmittedThe number of ICMP Echo (request) messages received / sent. Echo messages are probably the most visible ICMP messages. They test the communication path between network entities by asking for Echo Reply response messages. Echo Replies (PINGs) Received / TransmittedThe number of ICMP Echo Reply messages received / sent. Echo Reply messages are sent in response to Echo messages, to test the communication path between network entities. Timestamp Requests Received / TransmittedThe number of ICMP Timestamp (request) messages received / sent. Timestamp messages measure the propagation delay between network entities by including the originating time in the message, and asking for the receipt time in a Timestamp Reply message. Timestamp Replies Received / TransmittedThe number of ICMP Timestamp Reply messages received / sent. Timestamp Reply messages are sent in response to Timestamp messages, to measure propagation delay in the network. Address Mask Requests Received / TransmittedThe number of ICMP Address Mask Request messages received / sent. Address Mask Request messages ask for the address (subnet) mask for the LAN to which a router connects. Address Mask Replies Received / TransmittedThe number of ICMP Address Mask Reply messages received / sent. Address Mask Reply messages respond to Address Mask Request messages by supplying the address (subnet) mask for the LAN to which a router connects. Monitoring | Statistics | MIB-II | ARP TableThis screen shows entries in the Address Resolution Protocol mapping table since the VPN Concentrator was last booted or reset. ARP matches IP addresses with physical MAC addresses, so the system can forward traffic to computers on its network. RFC 2011 defines MIB entries in the ARP table. The entries are sorted first by Interface, then by IP Address. To speed display, the Manager might construct multiple 64-row tables. Use the scroll controls (if present) to view the entire series of tables. You can also delete dynamic, or learned, entries in the mapping table. Figure 17-32 Monitoring | Statistics | MIB-II | ARP Table Screen RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Arp EntriesThe total number of entries in the ARP table. InterfaceThe VPN Concentrator network interface on which this mapping applies: Physical AddressThe hardwired MAC (Medium Access Control) address of a physical network interface card, in 6-byte hexadecimal notation, that maps to the IP Address. Exceptions are: IP AddressThe IP address that maps to the physical address. Mapping TypeAction / DeleteTo remove a dynamic, or learned, mapping from the table, click Delete. There is no confirmation or undo. The Manager deletes the entry and refreshes the screen. To delete an entry, you must have the administrator privilege to Modify Config under General Access Rights. See Administration | Access Rights | Administrators. You cannot delete static mappings. Monitoring | Statistics | MIB-II | EthernetThis screen shows statistics in MIB-II objects for Ethernet interface traffic on the VPN Concentrator since it was last booted or reset. IEEE standard 802.3 describes Ethernet networks, and RFC 1650 defines Ethernet interface MIB objects. To configure Ethernet interfaces, see Configuration | Interfaces. Figure 17-33 Monitoring | Statistics | MIB-II | Ethernet Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. InterfaceThe Ethernet interface to which the data in this row applies. Only configured interfaces are shown. Alignment ErrorsThe number of frames received on this interface that are not an integral number of bytes long and do not pass the FCS (Frame Check Sequence; used for error detection) check. FCS ErrorsThe number of frames received on this interface that are an integral number of bytes long but do not pass the FCS (Frame Check Sequence) check. Carrier Sense ErrorsThe number of times that the carrier sense signal was lost or missing when trying to transmit a frame on this interface. SQE Test ErrorsThe number of times that the SQE (Signal Quality Error) Test Error message was generated for this interface. The SQE message tests the collision circuits on an interface. Frame Too Long ErrorsThe number of frames received on this interface that exceed the maximum permitted frame size. Deferred TransmitsThe number of frames for which the first transmission attempt on this interface is delayed because the medium is busy. This number does not include frames involved in collisions. Single CollisionsThe number of successfully transmitted frames on this interface for which transmission is inhibited by exactly one collision. This number is not included in the Multiple Collisions number. Multiple CollisionsThe number of successfully transmitted frames on this interface for which transmission is inhibited by more than one collision. This number does not include the Single Collisions number. Late CollisionsThe number of times that a collision is detected on this interface later than 512 bit-times into the transmission of a packet. 512 bit-times = 51.2 microseconds on a 10-Mbps system. Excessive CollisionsThe number of frames for which transmission on this interface failed due to excessive collisions. MAC Errors: TransmitThe number of frames for which transmission on this interface failed due to an internal MAC sublayer transmit error. This number does not include Carrier Sense Errors, Late Collisions, or Excessive Collisions. MAC Errors: ReceiveThe number of frames for which reception on this interface failed due to an internal MAC sublayer receive error. This number does not include Alignment Errors, FCS Errors, or Frame Too Long Errors. Speed (Mbps)This interface's nominal bandwidth in megabits per second. DuplexThe current LAN duplex transmission mode for this interface: Monitoring | Statistics | MIB-II | SNMPThis screen shows statistics in MIB-II objects for SNMP traffic on the VPN Concentrator since it was last booted or reset. RFC 1907 defines SNMP version 2 MIB objects. To configure the VPN Concentrator SNMP server, see Configuration | System | Management Protocols | SNMP. Figure 17-34 Monitoring | Statistics | MIB-II | SNMP Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Requests ReceivedThe total number of SNMP messages received by the VPN Concentrator. Bad VersionThe total number of SNMP messages received that were for an unsupported SNMP version. The VPN Concentrator supports SNMP version 2. Bad Community StringThe total number of SNMP messages received that used an SNMP community string the VPN Concentrator did not recognize. See Configuration | System | Management Protocols | SNMP Communities to configure permitted community strings. To protect security, the VPN Concentrator does not include the usual default public community string. Parsing ErrorsThe total number of syntax or transmission errors encountered by the VPN Concentrator when decoding received SNMP messages. Silent DropsThe total number of SNMP request messages that were silently dropped because the reply exceeded the maximum allowable message size. Proxy DropsThe total number of SNMP request messages that were silently dropped because the transmission of the reply message to a proxy target failed for some reason (other than a timeout).
|
|||||
|
|