Splunk Dashboard: IPSec and VPN Security

Remote-access inventory, tunnel configuration, and weak cryptographic settings.

This dashboard shows VPN clients and IPSec tunnels, including authentication, encryption, key exchange, DH groups, PFS, and security findings.

Panels

PanelPurpose
VPN InventoryEstablishes which remote-access clients and tunnels are active and where deployed.
Encryption and AuthenticationIdentifies weak encryption, integrity, authentication, or key-exchange choices.
DH and PFS ExposurePrioritizes weak DH groups and tunnels lacking perfect forward secrecy.
Tunnel DetailIdentifies the exact host, endpoint, and configuration requiring change.

Key Data Fields

event.dataset=ipsec, tychon.type=ipsec_tunnel, security.risk_level, security.weak_dh_group, pqc.is_pqc_ready, observer.hostname.

Reading the Dashboard

VPN Inventory

Establishes which VPN clients and IPSec tunnels are active, where they are deployed, and which hosts or endpoints are in scope.

Encryption and Authentication

Groups encryption, integrity, authentication, and key-exchange choices so weak or unexpected configurations can be prioritized.

DH and PFS Exposure

Identifies weak Diffie-Hellman groups and tunnels without perfect forward secrecy. These are configuration indicators; missing values are not proof that a tunnel is secure.

Tunnel Detail

Provides the host, local and remote endpoints, tunnel state, algorithms, and findings needed to assign endpoint-level remediation.

Filtering and Performance

Use the dashboard time range and global filters to narrow the population before interpreting counts. Preserve host, application, platform, algorithm, and risk filters when moving to related dashboards. Aggregations summarize the filtered events; missing optional fields mean that a value was not emitted or observed, not that the condition is false.

Related Dashboards

Use the overview page to move between this dashboard and the other dashboard definitions.