ASA24# show crypto accelerator statistics Crypto Accelerator Status ------------------------- [Capability] Supports hardware crypto: True Supports modular hardware crypto: False Max accelerators: 1 Max crypto throughput: 225 Mbps Max crypto connections: 750 [Global Statistics] Number of active accelerators: 1 Number of non-operational accelerators: 0 Input packets: 0 Input bytes: 848 Output packets: 0 Output error packets: 0 Output bytes: 4696 [Accelerator 0] Status: OK Software crypto engine Slot: 0 Active time: 6256 seconds Total crypto transforms: 678 Total dropped packets: 0 [Input statistics] Input packets: 0 Input bytes: 848 Input hashed packets: 0 Input hashed bytes: 0 Decrypted packets: 0 Decrypted bytes: 848 [Output statistics] Output packets: 0 Output bad packets: 0 Output bytes: 4696 Output hashed packets: 0 Output hashed bytes: 0 Encrypted packets: 0 Encrypted bytes: 4696 [Diffie-Hellman statistics] Keys generated: 0 Secret keys derived: 0 [RSA statistics] Keys generated: 6 Signatures: 1 Verifications: 0 Encrypted packets: 0 Encrypted bytes: 0 Decrypted packets: 0 Decrypted bytes: 0 [SSL statistics] Outbound records: 0 Inbound records: 0 [RNG statistics] Random number requests: 65 Random number request failures: 0 [Accelerator 1] Status: OK Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0) Boot microcode : CN1000-MC-BOOT-2.00 SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.03 IPSec microcode : CNlite-MC-IPSECm-MAIN-2.04 Slot: 1 Active time: 6270 seconds Total crypto transforms: 69 Total dropped packets: 0 [Input statistics] Input packets: 0 Input bytes: 0 Input hashed packets: 0 Input hashed bytes: 0 Decrypted packets: 0 Decrypted bytes: 0 [Output statistics] Output packets: 0 Output bad packets: 0 Output bytes: 0 Output hashed packets: 0 Output hashed bytes: 0 Encrypted packets: 0 Encrypted bytes: 0 [Diffie-Hellman statistics] Keys generated: 65 Secret keys derived: 1 [RSA statistics] Keys generated: 0 Signatures: 0 Verifications: 0 Encrypted packets: 0 Encrypted bytes: 0 Decrypted packets: 0 Decrypted bytes: 0 [SSL statistics] Outbound records: 0 Inbound records: 0 [RNG statistics] Random number requests: 3 Random number request failures: 0 ASA24# packet-tracer input inside icmp 192.168.16.223 8 0 172.17.0.15 Phase: 1 Type: ACCESS-LIST Subtype: Result: ALLOW Config: Implicit Rule Additional Information: MAC Access list Phase: 2 Type: FLOW-LOOKUP Subtype: Result: ALLOW Config: Additional Information: Found no matching flow, creating a new flow Phase: 3 Type: ROUTE-LOOKUP Subtype: input Result: ALLOW Config: Additional Information: in 172.17.0.0 255.255.255.0 outside Phase: 4 Type: IP-OPTIONS Subtype: Result: ALLOW Config: Additional Information: Phase: 5 Type: INSPECT Subtype: np-inspect Result: ALLOW Config: class-map inspection_default match default-inspection-traffic policy-map global_policy class inspection_default inspect icmp service-policy global_policy global Additional Information: Phase: 6 Type: INSPECT Subtype: np-inspect Result: ALLOW Config: Additional Information: Phase: 7 Type: NAT Subtype: Result: ALLOW Config: nat (inside) 1 192.168.16.0 255.255.255.0 match ip inside 192.168.16.0 255.255.255.0 outside any dynamic translation to pool 1 (101.53.X.X [Interface PAT]) translate_hits = 370, untranslate_hits = 14 Additional Information: Dynamic translate 192.168.16.223/0 to 101.53.X.X/55665 using netmask 255.255.255.255 Phase: 8 Type: NAT Subtype: host-limits Result: ALLOW Config: nat (inside) 1 192.168.16.0 255.255.255.0 match ip inside 192.168.16.0 255.255.255.0 outside any dynamic translation to pool 1 (101.53.X.X [Interface PAT]) translate_hits = 370, untranslate_hits = 14 Additional Information: Phase: 9 Type: IP-OPTIONS Subtype: Result: ALLOW Config: Additional Information: Phase: 10 Type: FLOW-CREATION Subtype: Result: ALLOW Config: Additional Information: New flow created with id 1571, packet dispatched to next module Result: input-interface: inside input-status: up input-line-status: up output-interface: outside output-status: up output-line-status: up Action: allow ASA24# ASA24# debug crypto condition peer 124.29.X.X ASA24# ASA24# ASA24# ASA24# debug crypto isakmp 200 ASA24# ASA24# ASA24# debug crypto ipsec 200 ASA24# ASA24# ASA24# undebug all ASA24# ASA24# ASA24# debug crypto condition peer 124.29.X.X Duplicate address: 124.29.X.Xis in the filter table ASA24# ASA24#