"Overlay" SD-WAN tab

The "Overlay" SD-WAN Dashboard has these parts:

  • The Overview view appears at the beginning of the dashboard.

    Helps identify issues immediately.

  • The Per Security Gateway view allows users to drill down to understand the root cause and take corrective action.

Example:

"Overlay" overview widgets

# Widget Description

1

Gateway Status

Shows:

  • The total number of Security Gateways seen in the past 5 days.

  • The number of Security Gateways in the state "UP seen in the past 5 minutes."

  • The number of Security Gateways in the state "DOWN".

2

Links Status

Shows ISP and tunnel status counters.

3

Lowest Scored Gateways - Overlay

Shows Security Gateway with the lowest overlay health scores.

4

Gateway Overlay Health Score

Shows overlay health score over time for the bottom Security Gateways.

5

Overlay VPN SLA

Relevant for R82.20, Gateways with Lower version will be seen as Excellent or "DOWN" based on their tunnel status.

Shows the Overlay VPN tunnel SLA status by Security Gateway.

The color can change based on the status.

The status can be:

  • Excellent - All overlay VPN tunnels meet the required threshold. In version below R82.20 this is the only status for active overlay tunnels.

  • Good - At least one overlay VPN tunnel did not meet the required threshold, but no vpn_peer_name has all of its tunnels failing.

  • Poor - All tunnels that belong to at least one vpn_peer_name did not meet the required threshold.

  • Down - Overlay VPN tunnels are down or unavailable in the main Overlay VPN SLA widget.

6

Gateways by Overlay Tunnels status

Shows:

  • Security Gateways with tunnels in the state "UP"

  • Security Gateways with tunnels in the state "Partially Down"

  • Security Gateways with tunnels in the state "DOWN"

7

Tunnel Status | Gateways

Shows percentage tunnels in the state "UP" for Security Gateways with tunnels in the state "DOWN".

8

MAP

A map view showing the Security Gateways Status and the tunnels status between the Security Gateways.

"Overlay" Gateway drill-down widgets

To drill into a "Site" view, select the relevant Security Gateway from the list under the overview.

You can shorten the list by filtering the relevant Security Gateway in the site filter in the upper part of the page.

Example:

# Widget Description

1

VPN Overview & Drops

Shows:

  • IKE peers

  • SAs

  • IKE errors

  • Kernel-limit hits

  • Overlay drops

  • Fragmentation drops

2

VPN Restarts

Shows VPN restart counters by component and type:

  • IKED (process)

  • VPND (process)

  • Policy

  • VPNRAD (process)

3

VPN Overlay Tunnels MOS

Shows tunnel Mean Opinion Score from 1 to 5 over time.

4

Tunnel Status table

Shows:

  • Security Gateway

  • ISP

  • Source IP address

  • Peer ISP (Version R82.20 +)

  • Peer Name (Version R82.20 +)

  • Peer IP address

  • VPN state

  • Latency

  • Jitter

  • Packet loss

5

Tunnel Status (per Gateway - peer)

Shows tunnel status timeline.

6

Overlay Tunnels Jitter / Packet Loss / Latency

Shows tunnel quality metrics over time.

7

Network Traffic | ISP

Shows sent and received traffic by interface.

8

VPN Events per Minute by Type

Shows VPN event-rate spikes by event type.

9

Overlay Tunnel Connection Drops per Peer / ISP

Shows tunnel connection drops by peer and ISP.

10

IPSec Fragmentation Count & Drops

Shows fragmentation and drops to help identify MTU issues.

11

IKE SA Counts by Type

Shows inbound, outbound, and peer-initiated IKE SA counts.

12

IKE SA Usage vs Limits

Compares current IKE SA usage with platform limits.

13

Concurrent IKE Negotiations

Shows concurrent IKE negotiation activity.