ASA S2S VPN Troubleshooting Query
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-19-2021 05:37 AM - edited 07-19-2021 05:38 AM
Hi Guys,
Is there a command/debug/capture for the ASA whereby I can see the decapsulated packets from a site to site VPN. Usually I just capture on the interface it egresses but not getting any hits like it should.
Would be good to see what is sent as trying to prove what is being sent from a remote party.
Thanks
George
- Labels:
-
IPSEC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-19-2021 06:13 AM
use the below troubleshoot guide :
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-21-2021 06:45 AM
use the command "show crypto ipsec sa <PeerIP>" to confirm if you are receiving the decap packets in VPN tunnel
then apply the packet capture on the inside interface of Cisco VPN ASA from which the packet will leave for a destination
Please rate for useful post
