Skip to main content
This section provides the purpose, elements, and actions performed on the Diagnostic tools pages.

Purpose

The Gateway Diagnostics section provides tools to test gateway reachability, capture packets, trace paths, check connectivity, view active sessions and interface stats, manage services, run built-in diagnostics, audit spoke gateways for symmetric routing and AZ affinity issues, and download tracelogs.

Elements

Gateway Diagnostics
  • Ping, Packet Capture, Traceroute, Tracepath, and Connectivity sub-tabs or tools, each with run controls and results panels for testing reachability and paths.
  • Active Sessions, Interface Stats, Services, Diagnostics, and Tracelog sub-tabs or tools, each with run/refresh controls and results panels for viewing gateway status and history.
  • Capability Audit For group: Symmetric Routing and AZ Affinity audit tools. Selecting either tool disables the Gateway Instance selector, since each tool selects its own gateway or gateway group scope.

Actions

To test gateway reachability with ping:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Ping tab.
  2. Select Interface (default: Use Route Table) and enter Destination (IP / Host Name).
  3. Click Run to start the ping test. Use Reset to clear the form.
  4. Review the Results panel for reachability and round-trip time.
The Results panel shows ping output and time details.

Parameter Details

To capture packets on a gateway interface:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Packet Capture tab.
  2. Set Interface, IP / Host Name, Port, Duration, and Packet Length as needed. Click Run.
  3. Use Download PCAP File to save captured packets. Optionally, use Filter, Columns, Export, or Search on the packet table.
The packet table shows Time, Interface, Source IP, Destination, Protocol, and other fields.
To trace the path from the gateway to a target:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Traceroute tab.
  2. Select Interface and enter Destination (IP/Host Name). Click Run.
  3. Review the Results panel for hop details (IP, hostname, time). Use Reset to clear.
The Results panel shows hop-by-hop path details.
To check path and MTU to a target:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Tracepath tab.
  2. Select Interface and enter Destination (IP/Host Name). Click Run.
  3. Review the Results panel for path and MTU details. Use Reset to clear.
The Results panel shows path and MTU information.
To check reachability for common services:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Connectivity tab.
  2. Enter HostName, Port, and select Protocol (TCP/UDP). Click Run.
  3. Review the Results panel for DNS, HTTPS, and IP reachability. Use Reset to clear.
The Results panel shows test results for the target.
To view live traffic sessions on the gateway:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Active Sessions tab.
  2. Click Run to retrieve the latest active session data for the selected gateway.
The Active Sessions table displays current traffic sessions (Orig S-IP, Orig D-IP, Proto, State, etc.).
To view real-time interface counters:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Interface Stats tab.
  2. Review the Interface table (packets, errors) and Graph view (bandwidth).
The page shows interface counters and bandwidth use.
To view gateway service status:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Services tab.
  2. Review the Service list. Use Restart for a service if supported.
The Service list shows each service and its status.
To run built-in gateway diagnostic checks:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Diagnostics tab.
  2. Optionally toggle Include Controller to include Controller-side checks.
  3. Click Run to start tests, or use its dropdown to Show Last Diagnostics Result or Submit To Support instead.
  4. Review the output console for findings.
The output console shows the diagnostic result text.
To collect and download gateway logs:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Select the Tracelog tab.
  2. Review the Log list and click Download to save the selected log file.
The Log list shows available trace log files.
To audit spoke gateways for symmetric routing issues:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Under Capability Audit For, select Symmetric Routing.
  2. Click Run. The tool audits every spoke gateway group with Symmetric Routing enabled (no gateway selection is required). Use Cancel to stop an in-progress run, or Reset to clear the results.
  3. Review the summary (Status, Gateways Audited, Gateways Passed, Gateways with Issues) and the Gateways with Issues section for route-table-level findings and remediation guidance.
If no spoke gateways have Symmetric Routing enabled, the tool shows an empty state instead of results.

Parameter Details

To audit a pair of peered gateway groups for AZ affinity issues:
  1. Go to Diagnostics > Diagnostic Tools > Gateway Diagnostics.
    Under Capability Audit For, select AZ Affinity.
  2. Select Gateway Group 1, then select Gateway Group 2 from the gateway groups peered with it (AWS only).
  3. Click Run. Use Reset to clear the selections and results.
  4. Review the findings, or the success message if no issues are found.

Parameter Details