cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
744
Views
10
Helpful
6
Replies

VPN Traffic for specific client

sivaaalthi
Level 1
Level 1

Hi All,

I have ASA 5510 8.4 Firewall where more than 20 Site to Site VPN Clients are configured on it.

Could anyone please help me how to see the traffic for one Specific Site to Site VPN.

Actually this site to site vpn is always keep droping for every minute. I'm sure its a problem at the other end.

The remaining 19 VPNS are UP and working without any problem.

Please help me how to see the traffic for specific vlan.

More over we dont have any syslog server in our network.

Is their any chance we can check the traffic on the firewall ?

Any help would be highly appreciated.

Regards,

Chinnu.

1 Accepted Solution

Accepted Solutions

Hi Chinnu,

In order to verify one single VPN connection, do the following:

1- debug crypto condition peer specific_vpn_peer_IP

2- debug crypto ikev1 190 --> 8.4+

    debug crypto isakmp 190 --> 8.2 & 8.3

3- debug crypto ipsec 190

This will show debugging information for one single VPN connection, so we could narrow down the issue.

On the other hand, to check the statistics of this single tunnel:

show crypto ipsec sa peer specific_vpn_peer_IP

A packet-capture would be required in case that the tunnel remains up, but certain traffic does not seem to flow across.

HTH.

Portu.

View solution in original post

6 Replies 6

jocamare
Level 4
Level 4

Packet captures on any of the endpoints will give you some information about the traffic flowing through the tunnel.

Hi Chinnu,

In order to verify one single VPN connection, do the following:

1- debug crypto condition peer specific_vpn_peer_IP

2- debug crypto ikev1 190 --> 8.4+

    debug crypto isakmp 190 --> 8.2 & 8.3

3- debug crypto ipsec 190

This will show debugging information for one single VPN connection, so we could narrow down the issue.

On the other hand, to check the statistics of this single tunnel:

show crypto ipsec sa peer specific_vpn_peer_IP

A packet-capture would be required in case that the tunnel remains up, but certain traffic does not seem to flow across.

HTH.

Portu.

Hi Javier,

Many Many Many Thanks and Thanks a Lot aswell..!!!!

Regards,

Chinnu.

You are very welcome!!

Have a good one

Thanks Javier..!!!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card