![]() |
VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring, Release 4.0
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Sessions
![]() |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Table of ContentsSessionsMonitoring | Sessions Reset
Monitoring | Sessions | DetailRestore Refresh Group Session Summary Table Active LAN-to-LAN Sessions
LAN-to-LAN Sessions TableActive Remote Access Sessions Active Management Sessions Total Active Sessions Peak Concurrent Sessions Concurrent Sessions Limit Total Cumulative Sessions [ Remote Access Sessions | Management Sessions ]
Remote Access Sessions TableConnection Name IP Address Protocol, Encryption, Login Time, Duration, Bytes Tx, Bytes Rx [ LAN-to-LAN Sessions | Management Sessions ]
Management Sessions TableUsername Public IP Address Assigned IP Address Group Client Type and Operating System Version Protocol, Encryption, Login Time, Duration, Bytes Tx, Bytes Rx Monitoring | Sessions | Protocols Monitoring | Sessions | SEPs Monitoring | Sessions | Encryption Monitoring | Sessions | Top Ten Lists Monitoring | Sessions | Top Ten Lists | Data Monitoring | Sessions | Top Ten Lists | Duration Monitoring | Sessions | Top Ten Lists | Throughput SessionsMonitoring | SessionsThe following screen shows comprehensive data for all active user and administrator sessions on the VPN Concentrator. Figure 16-1 Monitoring | Sessions Screen ResetTo reset, or start anew, the screen contents, click Reset. The system temporarily resets a counter for the chosen statistics without affecting the operation of the device. You can then view statistical information without affecting the actual current values of the counters or other management sessions. The function is like that of a vehicle's trip odometer, versus the regular odometer. RestoreTo restore the screen contents to their actual statistical values, click Restore. This icon displays only if you previously clicked the Reset icon. RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. GroupChoose a group from the menu to monitor sessions for that group only. The default value is --All--, which displays sessions for all groups. Session Summary TableThis table shows summary totals for LAN-to-LAN, remote access, and management sessions. A session is a VPN tunnel established with a specific peer. In most cases, one user connection = one tunnel = one session. However, one IPSec LAN-to-LAN tunnel counts as one session, but it allows many host-to-host connections through the tunnel. Active LAN-to-LAN SessionsThe number of IPSec LAN-to-LAN sessions that are currently active. Active Remote Access SessionsThe number of PPTP, L2TP, IPSec remote-access user, L2TP over IPSec, and IPSec through NAT sessions that are currently active. Active Management SessionsThe number of administrator management sessions that are currently active. Total Active SessionsThe total number of sessions of all types that are currently active. Peak Concurrent SessionsThe highest number of sessions of all types that were concurrently active since the VPN Concentrator was last booted or reset. Concurrent Sessions LimitThe maximum number of concurrently active sessions permitted on this VPN Concentrator. This number is model-dependent, for example, model 3060 = 5000 sessions. Total Cumulative SessionsThe total cumulative number of sessions of all types since the VPN Concentrator was last booted or reset. LAN-to-LAN Sessions TableThis table shows parameters and statistics for all active IPSec LAN-to-LAN sessions, initially sorted alphanumerically by connection name. Each session here identifies only the outer LAN-to-LAN connection or tunnel, not individual host-to-host sessions within the tunnel. [ Remote Access Sessions | Management Sessions ]Click these active links to go to the other session tables on this Manager screen. Connection NameThe name of the IPSec LAN-to-LAN connection. To display detailed parameters and statistics for this connection, click this name. See the Monitoring | Sessions | Detail screen. IP AddressThe IP address of the remote peer VPN Concentrator or other secure gateway that initiated this LAN-to-LAN connection. Protocol, Encryption, Login Time, Duration, Bytes Tx, Bytes RxSee Table 16-1 for definitions of these parameters. Remote Access Sessions TableThis table shows parameters and statistics for all active remote-access sessions. Each session is a single-user connection from a remote client to the VPN Concentrator. Remote-access sessions include PPTP, L2TP, IPSec remote-access user, L2TP over IPSec, and IPSec through NAT sessions. Click a column header in this table to sort the table entries in ascending alphanumeric order, using that column as the sort key field. [ LAN-to-LAN Sessions | Management Sessions ]Click these active links to go to the other session tables on this Manager screen. Username The username or login name for the session. The field shows To display detailed parameters and statistics for this session, click this name. See the Monitoring | Sessions | Detail screen. Public IP AddressThe public IP address of the client for this remote-access session. This is also known as the "outer" IP address. It is typically assigned to the client by the ISP, and it lets the client function as a host on the public network. Assigned IP AddressThe private IP address assigned to the remote client for this session. This is also known as the "inner" or "virtual" IP address, and it lets the client appear to be a host on the private network. GroupThe group name of the client for this remote-access session. Clicking the column head for Group sorts the table entries in ascending alphanumeric order and also sorts the usernames within each group in ascending alphanumeric order. Client Type and Operating SystemThe client type of connected clients, and, when available, the associated operating system, sorted by username. For example:
VersionThe software version number (for example, rel. 3.6,_int 50) for connected clients, sorted by username. Protocol, Encryption, Login Time, Duration, Bytes Tx, Bytes RxSee Table 16-1 for definitions of these parameters. Management Sessions TableThis table shows parameters and statistics for all active administrator management sessions on the VPN Concentrator. [ LAN-to-LAN Sessions | Remote Access Sessions ]Click these active links to go to the other session tables on this Manager screen. AdministratorThe administrator username or login name for the session. IP AddressThe IP address of the manager workstation that is accessing the system. Local indicates a direct connection through the Console port on the system. Protocol, Encryption, Login Time, Duration, Bytes Tx, Bytes RxSee Table 16-1 for definitions of these parameters. Table 16-1 Parameter definitions for Monitoring | Sessions Screen Monitoring | Sessions | DetailThese Manager screens show detailed parameters and statistics for a specific remote-access or LAN-to-LAN session. The parameters and statistics differ depending on the session protocol. There are unique screens for: The Manager displays the appropriate screen when you click a highlighted connection name or username on the Monitoring | Sessions screen. Figure Figure 16-2 shows an example of one kind of detail screen. Depending on the type of connection you select, your detail screen might look somewhat different from the example shown. But, each session detail screen shows three tables: summary data, bandwidth management information, and detail data. The summary data echoes the session data from the Monitoring | Sessions screen. The Bandwidth Statistics table shows information about the effect of policing on that session. The session detail table shows all the relevant parameters for each session and subsession. See Table 16-2 for definitions of the possible session detail parameters, in alphabetical order. Figure 16-2 Example of a Monitoring | Sessions | Detail Screen RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. Back to SessionsTo return to the Monitoring | Sessions screen, click Back to Sessions. Monitoring | Sessions | Detail ParametersTable 16-2 Parameter Definitions for Monitoring | Sessions | Detail Screens
Monitoring | Sessions | ProtocolsThis screen graphically displays the protocols used by currently active user and administrator sessions on the VPN Concentrator. Figure 16-3 Monitoring | Sessions | Protocols Screen RefreshTo update the screen and its data, click Refresh. The date and time indicate when the screen was last updated. GroupChoose a group from the menu to show protocols used by currently active users in that group only. The default value is --All--, which displays protocols for users in all groups. Active SessionsThe number of currently active sessions. Total SessionsThe total number of sessions since the VPN Concentrator was last booted or reset. ProtocolThe protocol that the session is using:
SessionsThe number of active sessions using this protocol. The sum of this column equals the total number of Active Sessions shown above. Bar Graph
|
![]() |
Note This screen appears on models 3015-3080 only. |
This screen graphically displays the SEP (Scalable Encryption Processing) or SEP-E (Enhanced SEP) modules used by currently active user and administrator sessions on the VPN Concentrator. SEP modules perform data encryption functions in hardware.
To update the screen and its data, click Refresh. The date and time indicate when the screen was last updated.
Choose a group from the menu to display SEP modules for that group only. The default value is --All--, which displays SEP modules for all groups.
The number of currently active sessions.
The total number of sessions since the VPN Concentrator was last booted or reset.
The SEP module that the sessions are using.
The number of active sessions using this SEP module. The sum of this column equals the total number of Active Sessions shown above.

The percentage of sessions using this SEP module relative to the total active sessions, as a horizontal bar graph. Each segment of the bar in the column heading represents 25 percent.
The percentage of sessions using this SEP module relative to the total active sessions, as a number. The sum of this column equals 100 percent (rounded).
This screen graphically displays the data encryption algorithms used by currently active user and administrator sessions on the VPN Concentrator.
To update the screen and its data, click Refresh. The date and time indicate when the screen was last updated.
Choose a group from the menu to monitor data encryption algorithms used by currently active users in that group only. The default value is --All--, which displays data encryption algorithms for all groups.
The number of currently active sessions.
The total number of sessions since the VPN Concentrator was last booted or reset.
The data encryption algorithm that the sessions are using:
The number of active sessions using this encryption algorithm. The sum of this column equals the total number of Active Sessions shown above.

The percentage of sessions using this encryption algorithm relative to the total active sessions, as a horizontal bar graph. Each segment of the bar in the column heading represents 25 percent.
The percentage of sessions using this encryption algorithm relative to the total active sessions, as a number. The sum of this column equals 100 percent (rounded).
This section of the Manager shows statistics for the top 10 currently active VPN Concentrator sessions, sorted by:
This screen shows statistics for the top 10 currently active VPN Concentrator sessions, sorted by data, total bytes transmitted and received.
To update the screen and its data, click Refresh. The date and time indicate when the screen was last updated.
Choose a group from the menu to show session statistics for that group only. The default value is --All--, which displays session statistics for all groups.
The login username for the session.
The IP address of the session user. This is the address assigned to or supplied by a remote user, or the host address of a networked user. Local identifies the console directly connected to the VPN Concentrator.
The protocol that the session is using:
The data encryption algorithm that the session is using:
The date and time that this session logged in: MM/DD/YYYY HH:MM:SS. Time is in 24-hour notation.
The total number of bytes transmitted and received by this session. N/A = the session is not passing data, in other words, it is an administrator session.
This screen shows statistics for the top 10 currently active VPN Concentrator sessions, sorted by duration: total time connected.
To update the screen and its data, click Refresh. The date and time indicate when the screen was last updated.
Choose a group from the menu to show session statistics for that group only. The default value is --All--, which displays session statistics for all groups.
The login username for the session.
The IP address of the session user. This is the address assigned to or supplied by a remote user, or the host address of a networked user. Local identifies the console directly connected to the VPN Concentrator.
The protocol that the session is using:
The data encryption algorithm that the session is using.
The date and time that this session logged in: MM/DD/YYYY HH:MM:SS. Time is in 24-hour notation.
The total amount of time that this session has been connected: HH:MM:SS.
This screen shows statistics for the top 10 currently active VPN Concentrator sessions, sorted by average throughput (bytes/sec).
To update the screen and its data, click Refresh. The date and time indicate when the screen was last updated.
Choose a group from the menu to show session statistics for that group only. The default value is --All--, which displays session statistics for all groups.
The login username for the session.
The IP address of the session user. This is the address assigned to or supplied by a remote user, or the host address of a networked user. Local identifies the console directly connected to the VPN Concentrator.
The protocol that the session is using:
The data encryption algorithm that the session is using.
The date and time that this session logged in: MM/DD/YYYY HH:MM:SS. Time is in 24-hour notation.
The average throughput of the session, which is [total bytes transmitted and received] divided by total connect time. N/A = the session is not passing data, in other words, it is an administrator session.