<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No logs for ikev2 on router in VPN</title>
    <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656798#M284637</link>
    <description>&lt;P&gt;Share config I will check&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2022 12:02:02 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-07-25T12:02:02Z</dc:date>
    <item>
      <title>No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656354#M284625</link>
      <description>&lt;P&gt;Hi. I was hoping to see ikev2 logs after entering "debug crypto ikev2" on a cisco router (C891FJ-K9) but nothing shows up on the router log. What could I be missing here?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 04:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656354#M284625</guid>
      <dc:creator>cisco-ninja</dc:creator>
      <dc:date>2022-07-25T04:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656358#M284626</link>
      <description>&lt;P&gt;is your router have access to IPsec peer? is it pingable if ping enabled on peer side? did you configured default route towards internet (to connect with IPSec peer)?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 04:25:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656358#M284626</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-07-25T04:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656362#M284627</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;is your router have access to IPsec peer?&amp;nbsp; --&amp;gt; sorry not sure what you mean...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;is it pingable if ping enabled on peer side? --&amp;gt; yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;did you configured default route towards internet (to connect with IPSec peer)? --&amp;gt; yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Actually, there is another crypto map using IKEv1 I believe which is working normally.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 04:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656362#M284627</guid>
      <dc:creator>cisco-ninja</dc:creator>
      <dc:date>2022-07-25T04:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656363#M284628</link>
      <description>&lt;P&gt;if it pingable both sides, i can guess that you have access between 2 IPsec peers. is that IKEv1 configured for same peer?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 04:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656363#M284628</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-07-25T04:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656368#M284629</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;sorry i meant it was pingable using the global Ip addresses on both sides. Not able to ping LAN IPs.&lt;BR /&gt;IKEv1 is configured for a different router.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 04:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656368#M284629</guid>
      <dc:creator>cisco-ninja</dc:creator>
      <dc:date>2022-07-25T04:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656768#M284636</link>
      <description>&lt;P&gt;what is the exact debug command you are using? also are you connected to router via Console or SSH/Telnet?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 11:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656768#M284636</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-07-25T11:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656798#M284637</link>
      <description>&lt;P&gt;Share config I will check&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 12:02:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4656798#M284637</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-07-25T12:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658005#M284685</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;debug crypto ikev2&lt;BR /&gt;this is the exact debug command nothing special i hope&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;please see the attached file that i have posed in the beginning.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 03:40:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658005#M284685</guid>
      <dc:creator>cisco-ninja</dc:creator>
      <dc:date>2022-07-27T03:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658006#M284686</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;i was accessing via ssh but i went to the office today and connected via console but same output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 03:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658006#M284686</guid>
      <dc:creator>cisco-ninja</dc:creator>
      <dc:date>2022-07-27T03:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658229#M284689</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1382439"&gt;@cisco-ninja&lt;/a&gt; you are using a policy based VPN (crypto map) you will need to generate interesting traffic before the tunnel will even attempt to establish, and only then will it generate logs. Run a ping to a destination from the VLAN10 network - from the router "ping &amp;lt;dest ip&amp;gt; source vlan 10"&lt;/P&gt;
&lt;P&gt;You've got NAT configured. What is the configuration of list "1"? Are you unintentially translating the internal traffic behind VLAN20 - this would cause a problem with the VPN as the crypto ACL is configured to use zz.zz.zz.zz (VLAN10) as the source.&lt;/P&gt;
&lt;P&gt;Why do you even need NAT if you are tunnelling all traffic over the VPN?&lt;/P&gt;
&lt;P&gt;What the configuration of the ACLs on the VLAN20 interface?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 07:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658229#M284689</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-27T07:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658535#M284709</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;ip nat insde source list 100 interface vlan 20 overload&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;ip access-list NAT-ACL extended&amp;nbsp;&lt;BR /&gt;deny ip &amp;lt;LAN your site&amp;gt; &amp;lt;LAN other site&amp;gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;permit ip &amp;lt;LAN your side&amp;gt; &amp;lt;any&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;ip access-list IKEv2-ACL extended&amp;nbsp;&lt;BR /&gt;permit ip &amp;lt;LAN your site&amp;gt; &amp;lt;LAN other site&amp;gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 12:26:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4658535#M284709</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-07-27T12:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: No logs for ikev2 on router</title>
      <link>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4659805#M284739</link>
      <description>&lt;P&gt;Thank you all for your help!&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;It worked! Thank you so much. Your advice cleared the issue!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 03:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/no-logs-for-ikev2-on-router/m-p/4659805#M284739</guid>
      <dc:creator>cisco-ninja</dc:creator>
      <dc:date>2022-07-29T03:03:49Z</dc:date>
    </item>
  </channel>
</rss>

