<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN trouble users? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349804#M1030685</link>
    <description>Are you using EZVPN?&lt;BR /&gt;&lt;BR /&gt;One command that might be useful is "crypto logging session", this will create a syslog event for each new VPN connection established.</description>
    <pubDate>Fri, 16 Mar 2018 12:00:01 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2018-03-16T12:00:01Z</dc:date>
    <item>
      <title>IPSEC VPN trouble users?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349779#M1030681</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My VPN seems to be working fine if thats you are wondering. My concern is much bigger.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to see Who is Connected in the VPN (user name) since it seems that someone, something, somehow has got all the IP Pool from my vpn&lt;/P&gt;
&lt;P&gt;ydrovpnrouter# sh ip loca pool&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;Pool&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Begin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; End&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Free&amp;nbsp; In use&lt;BR /&gt;&amp;nbsp;SDM_POOL_1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.10.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.10.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have several profiles for users to connect through IPSec Client, and I am trying to see who is connected, and if I cannot see by username, I am trying to see Public IP address.&lt;/P&gt;
&lt;P&gt;Commands used so far&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show aaa user all&amp;nbsp; (get 21 output like this)&lt;/P&gt;
&lt;P&gt;--------------------------------------------------&lt;BR /&gt;Unique id 1 is currently in use.&lt;BR /&gt;Accounting:&lt;BR /&gt;&amp;nbsp; log=0x18001&lt;BR /&gt;&amp;nbsp; Events recorded :&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; CALL START&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; INTERIM START&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; INTERIM STOP&lt;BR /&gt;&amp;nbsp; update method(s) :&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NONE&lt;BR /&gt;&amp;nbsp; update interval = 0&lt;BR /&gt;&amp;nbsp; Outstanding Stop Records : 0&lt;BR /&gt;&amp;nbsp; Dynamic attribute list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43F8E1B8 0 00000001 connect-progress(35) 4 No Progress&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43F8E1CC 0 00000001 pre-session-time(253) 4 0(0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43F8E1E0 0 00000001 elapsed_time(322) 4 0(0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43F8E1F4 0 00000001 pre-bytes-in(249) 4 0(0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43F8E208 0 00000001 pre-bytes-out(250) 4 0(0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43F8E21C 0 00000001 pre-paks-in(251) 4 0(0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43F8E230 0 00000001 pre-paks-out(252) 4 0(0)&lt;BR /&gt;&amp;nbsp; No data for type EXEC&lt;BR /&gt;&amp;nbsp; No data for type CONN&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session Id=00000001 Unique Id=00000001&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start Sent=0 Stop Only=N&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; stop_has_been_sent=N&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method List=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Attribute list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 441130EC 0 00000001 session-id(320) 4 1(1)&lt;BR /&gt;&amp;nbsp; No data for type CMD&lt;BR /&gt;&amp;nbsp; No data for type SYSTEM&lt;BR /&gt;&amp;nbsp; No data for type RM CALL&lt;BR /&gt;&amp;nbsp; No data for type RM VPDN&lt;BR /&gt;&amp;nbsp; No data for type AUTH PROXY&lt;BR /&gt;&amp;nbsp; No data for type CALL&lt;BR /&gt;&amp;nbsp; No data for type VPDN-TUNNEL&lt;BR /&gt;&amp;nbsp; No data for type VPDN-TUNNEL-LINK&lt;BR /&gt;&amp;nbsp; No data for type 11&lt;BR /&gt;&amp;nbsp; No data for type IPSEC-TUNNEL&lt;BR /&gt;&amp;nbsp; No data for type RESOURCE&lt;BR /&gt;Debg: No data available&lt;BR /&gt;Radi: No data available&lt;BR /&gt;Interface:&lt;BR /&gt;&amp;nbsp; TTY Num = -1&lt;BR /&gt;&amp;nbsp; Stop Received = 0&lt;BR /&gt;&amp;nbsp; Byte/Packet Counts till Call Start:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start Bytes In = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start Bytes Out = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start Paks&amp;nbsp; In = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start Paks&amp;nbsp; Out = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp; Byte/Packet Counts till Service Up:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pre Bytes In = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pre Bytes Out = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pre Paks&amp;nbsp; In = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pre Paks&amp;nbsp; Out = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp; Cumulative Byte/Packet Counts :&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bytes In = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bytes Out = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Paks&amp;nbsp; In = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Paks&amp;nbsp; Out = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp; StartTime = 21:48:16 PCTime Jun 14 2017&lt;BR /&gt;&amp;nbsp; Component = TTI&lt;BR /&gt;Authen: service=NONE type=NONE method=NONE&lt;BR /&gt;Kerb: No data available&lt;BR /&gt;Meth: No data available&lt;BR /&gt;Preauth: No Preauth data.&lt;BR /&gt;General:&lt;BR /&gt;&amp;nbsp; Unique Id = 00000001&lt;BR /&gt;&amp;nbsp; Session Id = 00000001&lt;BR /&gt;&amp;nbsp; No General Attributes.&lt;BR /&gt;PerU: No data available&lt;BR /&gt;Service Profile: No Service Profile data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sho aaa user all | i NET: Username=&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;BR /&gt;&amp;nbsp; NET: Username=(n/a)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone help? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349779#M1030681</guid>
      <dc:creator>Fotiosmark</dc:creator>
      <dc:date>2020-02-21T15:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN trouble users?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349787#M1030682</link>
      <description>Hi,&lt;BR /&gt;You don't say what type of VPN you are running or on what device, but I assume router from your hostname of your output. I assume you are not using an external aaa server, so cannot tell from the radius accounting logs?&lt;BR /&gt;&lt;BR /&gt;"show crypto session" would show you the public ip addresses of active tunnels as you requested.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Fri, 16 Mar 2018 11:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349787#M1030682</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-03-16T11:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN trouble users?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349797#M1030683</link>
      <description>i dont think there is a way to see the users since it is a router and not an ASA&lt;BR /&gt;the sho cry session indeed shows all the peers connected under crypto. Public ips, ACLs etc. &lt;BR /&gt;I am trying to see who is using the POOL from my VPN Ipsec Client. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;Its a local aaa&lt;BR /&gt;So when I am trying to see show aaa session  I get the below and I don't know why&lt;BR /&gt; sh aaa ses&lt;BR /&gt;Total sessions since last reload: 2667411&lt;BR /&gt;Session Id: 1&lt;BR /&gt;   Unique Id: 1&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 1707429&lt;BR /&gt;   Unique Id: 1707429&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 1707431&lt;BR /&gt;   Unique Id: 1707431&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 1707433&lt;BR /&gt;   Unique Id: 1707433&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 1707447&lt;BR /&gt;   Unique Id: 1707447&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 2119827&lt;BR /&gt;   Unique Id: 2119827&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 2119937&lt;BR /&gt;   Unique Id: 2119937&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 2119959&lt;BR /&gt;   Unique Id: 2119959&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 2119961&lt;BR /&gt;   Unique Id: 2119961&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0&lt;BR /&gt;Session Id: 2119966&lt;BR /&gt;   Unique Id: 2119966&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;&lt;BR /&gt;Also on another router that I am using as a test, when I connect with VPN ipsec client I get the same result...&lt;BR /&gt;ession Id: 49&lt;BR /&gt;   Unique Id: 49&lt;BR /&gt;   User Name: *not available*&lt;BR /&gt;   IP Address: 0.0.0.0   &amp;lt;-------- ????&lt;BR /&gt;   Idle Time: 0&lt;BR /&gt;   CT Call Handle: 0</description>
      <pubDate>Fri, 16 Mar 2018 11:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349797#M1030683</guid>
      <dc:creator>Fotiosmark</dc:creator>
      <dc:date>2018-03-16T11:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN trouble users?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349804#M1030685</link>
      <description>Are you using EZVPN?&lt;BR /&gt;&lt;BR /&gt;One command that might be useful is "crypto logging session", this will create a syslog event for each new VPN connection established.</description>
      <pubDate>Fri, 16 Mar 2018 12:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-trouble-users/m-p/3349804#M1030685</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-03-16T12:00:01Z</dc:date>
    </item>
  </channel>
</rss>

