08-26-2011 06:18 AM
If there is a router ISRG2 2900 with SEC license and without HSEC license, there is a limit in count of cumulative encrypted VPN tunnels of 225. Which commands can show us a number of current tunnels on the router, so we can see if we are near this limit of 225?
08-26-2011 06:47 AM
Hello,
Unfortunately I dont think there is a command that would give you the exact number of current VPN tunnels.
You could try to estimate or count from the output of either one of the following commands:
show crypto isa sa
show crypto session brief
I hope this helps.
Raga
08-26-2011 06:56 AM
Yes, I can count number of isakmps SAs, or ipsec SAs, or crypro session, but I would like to know what exactly Cisco counts when they put a limit of "225 cumulative encrypted tunnels" on router.
08-26-2011 06:58 AM
Well, I hate to say it (I'm soo not an SDM fan) but the SDM does give you the number of active VPN tunnels, you might wanna give it a shot:
http://www.youtube.com/watch?v=7BeYUMw3Q8M
I hope this helps.
08-26-2011 07:01 AM
The limitation is on 225 concurrent VPN Tunnels, so most likely they are counting ISAKMP SAs.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide