cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
599
Views
5
Helpful
1
Replies

IPSec understanding

WaleedOmar58740
Level 1
Level 1

Hi Folks,

 

I have some problems and confusion with IPSec phases and Ike version and relationship with fqdn.

I can set up tunnels but I'm not sure how troubleshooting
If you have any resources or documentations for that please update me

1 Reply 1

balaji.bandi
Hall of Fame
Hall of Fame

You can use below commands for diagnosis each phase:

 

Phase 1 = "show crypto isakmp sa" or "show crypto ikev1 sa" or "show crypto ikev2 sa"

Phase 2 = "show crypto ipsec sa"

 

Here is the step by step troubleshooting guide :

 

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help