<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Command to check IPSEC tunnel on ASA 5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110421#M393253</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i did &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; sh vpn-sessiondb&amp;nbsp;&amp;nbsp;&amp;nbsp; l2l&lt;/P&gt;&lt;P&gt;Session Type: LAN-to-LAN&lt;/P&gt;&lt;P&gt;Connection&amp;nbsp;&amp;nbsp; : 10.x.x.x.&lt;BR /&gt;Index&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Addr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10..x.x.x&lt;BR /&gt;Protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : IKE IPsec&lt;BR /&gt;Encryption&amp;nbsp;&amp;nbsp; : AES256&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hashing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : SHA1&lt;BR /&gt;Bytes Tx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3902114912&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bytes Rx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 4164563005&lt;BR /&gt;Login Time&amp;nbsp;&amp;nbsp; : 21:10:24 UTC Sun Dec 16 2012&lt;BR /&gt;Duration&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 22d 18h:55m:43s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does this show&lt;/P&gt;&lt;P&gt;Here IP address 10.x&amp;nbsp; is of this ASA&amp;nbsp; or remote site?&lt;/P&gt;&lt;P&gt;Duration shows how long tunnel is up?&lt;/P&gt;&lt;P&gt;What does login time shows?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jan 2013 16:11:20 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2013-01-08T16:11:20Z</dc:date>
    <item>
      <title>Command to check IPSEC tunnel on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110419#M393250</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to check how many tunnels IPSEC are running over ASA 5520.&lt;/P&gt;&lt;P&gt;Tried commands which we use on Routers no luck &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110419#M393250</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T00:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Command to check IPSEC tunnel on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110420#M393251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try to use the following commands. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;show vpn-sessiondb l2l&lt;/LI&gt;&lt;LI&gt;show vpn-sessiondb ra-ikev1-ipsec&lt;/LI&gt;&lt;LI&gt;show vpn-sessiondb summary&lt;/LI&gt;&lt;LI&gt;show vpn-sessiondb license-summary&lt;/LI&gt;&lt;LI&gt;and try other forms of the connection with "show vpn-sessiondb ?"&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some of the command formats depend on your ASA software level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully the above information was helpfull &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 15:57:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110420#M393251</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-08T15:57:45Z</dc:date>
    </item>
    <item>
      <title>Command to check IPSEC tunnel on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110421#M393253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i did &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; sh vpn-sessiondb&amp;nbsp;&amp;nbsp;&amp;nbsp; l2l&lt;/P&gt;&lt;P&gt;Session Type: LAN-to-LAN&lt;/P&gt;&lt;P&gt;Connection&amp;nbsp;&amp;nbsp; : 10.x.x.x.&lt;BR /&gt;Index&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Addr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10..x.x.x&lt;BR /&gt;Protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : IKE IPsec&lt;BR /&gt;Encryption&amp;nbsp;&amp;nbsp; : AES256&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hashing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : SHA1&lt;BR /&gt;Bytes Tx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3902114912&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bytes Rx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 4164563005&lt;BR /&gt;Login Time&amp;nbsp;&amp;nbsp; : 21:10:24 UTC Sun Dec 16 2012&lt;BR /&gt;Duration&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 22d 18h:55m:43s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does this show&lt;/P&gt;&lt;P&gt;Here IP address 10.x&amp;nbsp; is of this ASA&amp;nbsp; or remote site?&lt;/P&gt;&lt;P&gt;Duration shows how long tunnel is up?&lt;/P&gt;&lt;P&gt;What does login time shows?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110421#M393253</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-01-08T16:11:20Z</dc:date>
    </item>
    <item>
      <title>Command to check IPSEC tunnel on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110422#M393255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The field with "Connection: x.x.x.x" lists the remote VPN device IP address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The field with "Login Time" lists the time/date when the L2L VPN was formed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The field with "Duration" shows how long the L2L VPN has been up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rest of the fields give information on the encryption, data transfered etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:14:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110422#M393255</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-08T16:14:39Z</dc:date>
    </item>
    <item>
      <title>Command to check IPSEC tunnel on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110423#M393258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we can say currently it has only 1 Active IPSEC VPN right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i do &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show vpn-sessiondb&amp;nbsp; summary&lt;/P&gt;&lt;P&gt;Active Session Summary&lt;/P&gt;&lt;P&gt;Sessions:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active : Cumulative : Peak Concurrent : Inactive&lt;BR /&gt;&amp;nbsp; IPsec LAN-to-LAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;&amp;nbsp; Totals&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to understand what does cumulative and peak mean here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110423#M393258</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-01-08T16:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Command to check IPSEC tunnel on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110424#M393264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Peak: Tells how many VPNs have been up at the most at the same time&lt;/LI&gt;&lt;LI&gt;Cumulative: Counts the total amount of connections that have been up on the device&amp;nbsp; &lt;UL&gt;&lt;LI&gt;You can for example have only one L2L VPN configured and when it comes up, goes down and comes up again it will already give the Cumulative value of 2.&lt;/LI&gt;&lt;LI&gt;In other words it means how many times a VPN connection has been formed (even if you have configured only one) on the ASA since the last reboot or since the last reset of these statistics&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case the above output would mean that L2L VPN type connection has been formed 3 times since the last reboot or clearing of these statistics. All the formings could be from this same L2L VPN connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT: And yes, there is only 1 Active VPN connection when you issued that command on your firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110424#M393264</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-08T16:22:45Z</dc:date>
    </item>
    <item>
      <title>Command to check IPSEC tunnel on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110425#M393266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for answering all my questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/command-to-check-ipsec-tunnel-on-asa-5520/m-p/2110425#M393266</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-01-08T16:56:24Z</dc:date>
    </item>
  </channel>
</rss>

