cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
12248
Views
46
Helpful
2
Replies

debug crypto ipsec sa for a specific peer

NAVIN PARWAL
Level 2
Level 2

Folks,

It is possible for me to run a debug crpto isakmp or debug cryto ipsec sa for a specific peer? I have many peers attached to the ASA and would like to see debug for only one.

Thanks

2 Replies 2

Jason Gervia
Cisco Employee
Cisco Employee

You'll have to do a crypto condition, ie:

debug crypto condition peer 1.1.1.1

and then

debug crypto isa

To get the messages for the peer with address 1.1.1.1

Thanks, just wanted to say that 12 years later this was exactly what I was looking for :D