cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Community Helping Community

124
Views
0
Helpful
1
Replies
Beginner

Site to Site ikev1 VPN enquiry

Hi,

 

I have an ASA running on an OS 9.0.x.

I am trying to figure out how to see the phase 1 settings i.e the Hash, Encryption, DH group, lifetime that is being used by a particular active VPN connection, I have the information for the peer IP of the VPN connection but I am unable to find a command that displays the phase1 setting currently being used by the VPN connection. 

 

I would also like to know what command is used to set a lifetime on phase2(IPsec) portion of the VPN.

 

Thank you

1 REPLY 1
VIP Advisor RJI VIP Advisor
VIP Advisor

Re: Site to Site ikev1 VPN enquiry

Hi,

Use the command "show crypto ikev2 sa" or "show crypto ikev1 sa" depending on your IKE version in use to display the IKE SA algorithms in use for the active session.

 

The command "crypto map CRYPTO_MAP_NAME 1 set security-association lifetime seconds xxxxxx" to set IPSec SA lifetime.

 

HTH

CreatePlease to create content
Content for Community-Ad
FusionCharts will render here