cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5660
Views
5
Helpful
2
Replies

Cisco ASA IPSec Site-to-Site VPN Logs via ASDM.

eng.khaled.omar
Level 1
Level 1
Hi All,

 

Is there a way to show the IPSec Site-to-Site VPN logs from Cisco ASA using ASDM?

 

I created a IPSec VPN using Cisco ASA but the VPN tunnel is not UP, i want to see the logs via ASDM indicating why the VPN tunnel is not established, cannot find such logs in ASDM. 

 

Regards,

 

Khaled

2 Replies 2

Alan Ng'ethe
Level 3
Level 3

The logging asdm informational command should allow you to see IKE negotiation failures.

Remember to rate helpful posts and/or mark as a solution if your issue is resolved.

The original poster asks about using ASDM to view logs that relate to problems with a configured VPN. I believe that there are several aspects to this question. First is the aspect of how to use ASDM to view log messages. Correct configuration of logging on the ASA (including logging asdm) should allow them to use ASDM to view syslog messages. The second aspect of the question is whether syslog will include messages about failures in IKE negotiation. If debug for crypto isakmp is enabled then syslog should contain messages about IKE negotiation. But if there is no debug running then I do not believe that syslog would contain messages about IKE negotiation. The third aspect of the question is whether the original poster wants to see messages in real time (or near real time) or wants to see messages from some time in the past. The ASA has limited ability to store syslog messages. So you should be able to see messages in real time or near real time. But to see messages from a time in the past you probably need to have some device in the network that will receive and store the syslog messages from the ASA.

 

HTH

 

Rick

HTH

Rick
Review Cisco Networking for a $25 gift card