Reference Manual for the ProSafe VPN Firewall FVS318v3
Advanced Virtual Private Networking 6-21
January 2005

How to Check VPN Connections

You can test connectivity and view VPN status information on the FVS318v3 (see also “VPN
Tunnel Control” on page 5-26).
Testing the Gateway A FVS318v3 LAN and the Gateway B LAN
1. Using our example, from a PC attached to the FVS318v3 on LAN A, on a Windows PC click
the Start button on the taskbar and then click Run.
2. Type ping -t 172.23.9.1, and then click OK.
3. This will cause a continuous ping to be sent to the LAN interface of Gateway B. Within two
minutes, the ping response should change from timed out to reply.
4. At this point the connection is established.
5. To test connectivity between the FVS318v3 Gateway A and Gateway B WAN ports, follow
these steps:
a. Using our example, log in to the FVS318v3 on LAN A, go to the main menu Maintenance
section and click the Diagnostics link.
b. To test connectivity to the WAN port of Gateway B, enter 22.23.24.25, and then click
Ping.
c. This causes a ping to be sent to the WAN interface of Gateway B. W ithin two minutes, the
ping response should change from timed out to reply. You may have to run this test several
times before you get the reply message back from the target FVS318v3.
d. At this point the connection is established.
Note: If you want to ping the FVS318v3 as a test of network connectivity, be sure the
FVS318v3 is confi gured to respo nd to a ping on the Internet WAN port by checking the check
box seen in Figure 4-2 on page 4-3. However , to preserve a high degree of security, you should
turn off this feature when you are finished with testing.
6. To view the FVS318v3 event log and status of Security Associations, follow these steps:
a. Go to the FVS318v3 main menu VPN section and click the VPN Status link.
b. The log screen displays a history of the VPN connections, and the IPSec SA and IKE SA
tables will report the status and data transmission statistics of the VPN tunnels for each
policy.