<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I detect how long the IPSEC tunnel has been up on the router? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231607#M860739</link>
    <description>&lt;P&gt;How can I detect how long the IPSEC tunnel has been up on the router? Is there any similiar command such as "show vpn-sessiondb l2l" on the router? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:20:03 GMT</pubDate>
    <dc:creator>yuhuiyao</dc:creator>
    <dc:date>2019-03-11T15:20:03Z</dc:date>
    <item>
      <title>How can I detect how long the IPSEC tunnel has been up on the router?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231607#M860739</link>
      <description>&lt;P&gt;How can I detect how long the IPSEC tunnel has been up on the router? Is there any similiar command such as "show vpn-sessiondb l2l" on the router? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231607#M860739</guid>
      <dc:creator>yuhuiyao</dc:creator>
      <dc:date>2019-03-11T15:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: How can I detect how long the IPSEC tunnel has been up on th</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231608#M860740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh crypt session detail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 12:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231608#M860740</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-04-17T12:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can I detect how long the IPSEC tunnel has been up on th</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231609#M860741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. Do you mean life time? It does not seem to be accurate. I have an ISP issue last night about 10 hour and 45 minutes ago, EIGRP provides the accurate information about the outage. However, I can not get the same information from show crypto session detail. See below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface: Tunnel1000&lt;/P&gt;&lt;P&gt;Uptime: 1w2d&lt;/P&gt;&lt;P&gt;Session status: UP-ACTIVE&lt;/P&gt;&lt;P&gt;Peer: 38.96.183.104 port 4500 fvrf: (none) ivrf: (none)&lt;/P&gt;&lt;P&gt;      Phase1_id: 192.168.20.104&lt;/P&gt;&lt;P&gt;      Desc: (none)&lt;/P&gt;&lt;P&gt;  IKE SA: local 192.168.10.104/4500 remote 38.96.183.104/4500 Active&lt;/P&gt;&lt;P&gt;          Capabilities:N connid:1031 lifetime:07:24:02&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit 47 host 192.168.10.104 host 38.96.183.104&lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 333824 drop 0 life (KB/Sec) 4585091/2335&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 337190 drop 93 life (KB/Sec) 4585139/2335&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface: Tunnel115&lt;/P&gt;&lt;P&gt;Uptime: 1w6d&lt;/P&gt;&lt;P&gt;Session status: UP-ACTIVE&lt;/P&gt;&lt;P&gt;Peer: 38.96.183.222 port 4500 fvrf: (none) ivrf: (none)&lt;/P&gt;&lt;P&gt;      Phase1_id: 192.168.255.104&lt;/P&gt;&lt;P&gt;      Desc: (none)&lt;/P&gt;&lt;P&gt;  IKE SA: local 192.168.10.104/4500 remote 38.96.183.222/4500 Active&lt;/P&gt;&lt;P&gt;          Capabilities:N connid:1032 lifetime:14:35:51&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit 47 host 192.168.10.104 host 38.96.183.222&lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 257754 drop 0 life (KB/Sec) 4456450/749&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 263821 drop 37 life (KB/Sec) 4456536/749&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hsc-dr-rtr-01# show ip ei nei&lt;/P&gt;&lt;P&gt;IP-EIGRP neighbors for process 3&lt;/P&gt;&lt;P&gt;H   Address                 Interface       Hold Uptime   SRTT   RTO  Q  Seq&lt;/P&gt;&lt;P&gt;                                            (sec)         (ms)       Cnt Num&lt;/P&gt;&lt;P&gt;4   172.20.255.218          Tu115             11 10:45:06   76  1320  0  209&lt;/P&gt;&lt;P&gt;3   172.20.250.1            Tu1000            13 10:45:06  178  1320  0  15843&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 12:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231609#M860741</guid>
      <dc:creator>yuhuiyao</dc:creator>
      <dc:date>2009-04-17T12:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can I detect how long the IPSEC tunnel has been up on th</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231610#M860742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does look like you have a discrepancy, but I'm not sure it's the tunnel that went down or the eigrp process had a glitch. If your gre tunnels went down, they would show here. According to this they've been up for 1w2d and 1w6d respectively. (Uptime)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 12:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231610#M860742</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-04-17T12:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: How can I detect how long the IPSEC tunnel has been up on th</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231611#M860743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since EIGRP sends hello messages quite frequently and will drop a neighbor when it misses 3 hello messages, EIGRP is pretty good at detecting failures on a link. Once the IPSec session gets established it may not send much traffic at some times. If the outage happened at a time when there was not much to go through the IPSec I believe that it is quite possible for the crypto session to be maintained over the outage and I am guessing that this is what happened in this instance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 16:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-detect-how-long-the-ipsec-tunnel-has-been-up-on-the/m-p/1231611#M860743</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-04-17T16:43:41Z</dc:date>
    </item>
  </channel>
</rss>

