cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
828
Views
10
Helpful
3
Replies

Lan 2 Lan Ipsec Debug commands

Hawk
Level 1
Level 1

Does anyone recommend any troubleshooting steps for establishing a tunnel with a remote peer? I do not have admin control of the other side.  I expect things to work but would like to see specifically how experienced admins are troubleshooting phase 1 & phase 2 connections?

1 Accepted Solution

Accepted Solutions

mkazam001
Level 3
Level 3

in addition to previous cmds:

 

sh crypto isakmp sa detail
sh crypto ipsec sa peer peer-ip
sh vpn-sessiondb l2l
sh vpn-sessiondb l2l [filter name x.x.x.x]

clear crypto ikev1 sa peer peer-ip bounce tunnel phase 1
clear crypto ipsec sa peer peer-ip bounce tunnel for phase 2

debug crypto ikev1 130 | ipsec 130

 

regards, mk

View solution in original post

3 Replies 3

Hi,

IKEv1:
debug crypto condition peer X.X.X.X
debug crypto ikev1 200

IKEv2:
debug crypto condition peer 3.3.3.1
debug crypto ikev2 platform 100
debug crypto ikev2 protocol 127

Confirm IKE/IPSec SAs:-
show crypto ikev2|ikev1 sa
show crypto ipsec sa

mkazam001
Level 3
Level 3

in addition to previous cmds:

 

sh crypto isakmp sa detail
sh crypto ipsec sa peer peer-ip
sh vpn-sessiondb l2l
sh vpn-sessiondb l2l [filter name x.x.x.x]

clear crypto ikev1 sa peer peer-ip bounce tunnel phase 1
clear crypto ipsec sa peer peer-ip bounce tunnel for phase 2

debug crypto ikev1 130 | ipsec 130

 

regards, mk

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: