Problems with VPN tunnel across the internet being unstable, what device can I place between my firewall and the ISP router to plug into and diagnose?

Posted on 2009-05-18
Last Modified: 2013-12-14
I need to monitor our connection over a VPN tunnel between 2 firewalls across the Internet and be able to see if the problem is on the ISP carrier side, any recommendations for network device. I have 2 sonicwall firewalls that connect the 2 offices via VPN tunnel, but the remote office has been having slow connections and freezing up after installing a new Fibre internet connection with Embarq.  When I call them to tell them the circuit is acting flaky, they tell me everything is fine on there equipment it must be on ours.  The only way to prove it is to bypass my firewall and if I do that I disconnect our remote office completely.  Would placing a layer 3 switch in between our firewall and their router allow me to plug a laptop in and run testing, bypassing our firewalls?  Anyone out there that might have a suggestion for me to check on our LANs or firewalls to see if the problem really is on our side.

Thanks, frustrated in Florida
Question by:esmf23it
  • 3
  • 2
LVL 23

Accepted Solution

debuggerau earned 500 total points
ID: 24417407
Any switch that contains port mirroring should allow you to sniff the traffic, however a cheap old hub may do the trick, although limited to 10Meg.

I think you will find it difficult to diagnose the traffic since it is VPN encrypted traffic, rather look at the logs on the firewalls for hints to why it is happening firstly, then move into the routers etc.

Internet VPN's are not rock solid and it might be better to ensure your internet connection is stable on both ends but inserting a monitoring machine in the DMZ and get latency stats out of the pings from remote site. Be even better with SNMP enabled devices and a RMON service.

And then there is the conditions, time of day, certain peak usage, voice or video calls? which all give some incite to the issue..


Author Comment

ID: 24431403
debuggerau, Thanks for the thoughts and insight. I do want to place a machine in the DMZ that is created by putting a switch in between our firewall and the ISP's router.  Embarq (ISP) has assured me that since it is a fibre connection and we don't share the connection that we should have a very stable connection and should not experience peaks in performance.  We have noticed that the real slow downs tend to come in the mid afternoon range. So would you think I can find a hub that would operate at 100mbps?
LVL 23

Expert Comment

ID: 24437763
If you do, please let me know...

Technology moves so quick, they went to switches before the 100Meg was available, so not that I know..

Author Comment

ID: 24445569
I tried to use on of our layer 2 switches to create a VLAN across 3 of the ports. Port 1 plugged the cable from the ISP's router, port 2 plugged into the firewall, plug 3 left available to plug in a computer.  It would not work with the switch, I will try it with the hub next, as soon as I can find one.
LVL 23

Expert Comment

ID: 24446733
layer 2 switch is ok, just as long as it has mirrored port feature...

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This solves the problem of diagnosing why an internet connection is no longer working. It also helps identify the likely cause of the lost connection if the procedure fails to re-establish your internet connection. It helps to pinpoint the likely co…
Network ports are the threads that hold network communication together. They are an essential part of networking that can be easily ignore or misunderstood, my goals is to show those who don't have a strong network foundation how network ports opera…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question