
VPN Infrastructure Diagnostics & Troubleshooting
Diagnose and resolve VPN issues across all vendor platforms
What You Can Do
You get systematic VPN troubleshooting workflows that identify root causes of connectivity failures, performance degradation, and configuration errors across Cisco, Fortinet, Palo Alto, and other major platforms. The skill walks you through configuration audits, log analysis, and remediation steps to restore service quickly and document the resolution process.
Features
Analyze settings for Cisco ASA, VyOS, Fortinet, Palo Alto, SonicWall, and custom implementations against security and performance baselines
Identify latency bottlenecks, bandwidth constraints, and encryption overhead through packet capture analysis and throughput testing
Parse VPN server and client logs to pinpoint authentication failures, tunnel drops, and protocol mismatches
Detect misconfigurations in encryption, key exchange, NAT-T, fragmentation, and routing that block or degrade connectivity
Step-by-step guides to verify tunnel establishment, firewall rules, routing tables, and NAT behavior
Tune encryption algorithms, buffer sizes, and MTU settings to maximize throughput without sacrificing security
Create runbooks for recurring VPN problems so your team can troubleshoot independently
Example Output
Example 1: Multi-Site VPN Connectivity Failure
Issue: Site B cannot reach Site A over IPSec tunnel.
Diagnosis Output:
✓ Phase 1 (IKE) — Established
✗ Phase 2 (IPSec) — Failed to negotiate
└ Mismatch: Site B offers AES-256-GCM, Site A only supports AES-128-CBC
└ Action: Update Site A IKE proposal to accept AES-256-GCM
✓ Firewall rules — Allow UDP 500, 4500 ✓
✗ Routing — Site B's firewall blocks 10.0.1.0/24 traffic
└ Action: Add static route on Site B firewall for 10.0.1.0/24 via VPN tunnel
Resolution: Update Site A Phase 2 proposal + add firewall route on Site B
Example 2: Client VPN Performance Degradation
Issue: VPN clients see 80% throughput drop after update.
Diagnosis Output:
✓ Tunnel established, authenticated, connected
✗ Performance metrics (baseline → current):
- Throughput: 150 Mbps → 30 Mbps (80% drop)
- Latency: 5ms → 45ms (9x increase)
- Packet loss: 0% → 3%
Root cause: Post-update logs show SHA-512 + AES-256-GCM negotiated
(high CPU overhead on older client CPUs)
Fix: Revert to SHA-256 + AES-128-GCM or deploy CPU-optimized client
Example 3: VPN Configuration Audit Summary
Audit: Cisco ASA Pair (Active/Standby)
✓ Strong: Phase 1 uses AES-256, DPD enabled, IKEv2 only
⚠ Warning: Phase 2 includes deprecated 3DES-CBC
⚠ Warning: NAT-T disabled (blocks enterprise proxies)
✗ Critical: Perfect Forward Secrecy disabled on Phase 2
Remediations:
1. Remove 3DES-CBC from Phase 2 proposal
2. Enable NAT-T on both ASA units
3. Enable PFS in Phase 2 with group14/20
What's Included
- SKILL.md: Complete VPN troubleshooting workflows with decision trees for Cisco, Fortinet, Palo Alto, and generic IPSec/L2TP/PPTP scenarios
- VPN Configuration Audit Checklist: Security baseline and performance tuning items for each vendor
- Troubleshooting Runbook Template: Document recurring issues with symptoms, root causes, and remediation steps
- Log Analysis Reference: Common VPN errors across vendors with interpretation and fixes
- Performance Tuning Guide: Encryption algorithm selection, buffer/MTU optimization, and throughput testing methodology
- Multi-Site Connectivity Flowchart: Step-by-step verification of Phase 1/2, firewall rules, routing, and NAT
Who It's For
- Network Engineers — Diagnose and fix VPN failures without vendor escalation
- System Administrators — Troubleshoot remote access VPN client issues for end users
- Security Teams — Audit VPN configurations for compliance and encryption strength
- MSP/Managed Service Providers — Standardize VPN troubleshooting across customer sites
- DevOps/Infrastructure Teams — Debug site-to-site connectivity issues blocking deployments
Best For
- IPSec tunnel establishment failures (Phase 1/Phase 2 negotiation issues)
- Client VPN connectivity problems and performance degradation
- Configuration audits and security policy validation across multi-vendor environments
- Post-incident root cause analysis and documentation
- Performance tuning for VPN gateways and clients







