How should I certify the security of a VPN?

I am connecting two LAN's on internet using a VPN on two linux servers using 
iptables. A part of the project is a security audit of the whole system, so I 
must document that I've done some exhaustive attempts to break the security 
and I've find everything O.K.

I don't know where to begin :D

What would you do to test security on this environment? How should I certify 
the security?

Thanks in advance :)

