Hi,
If you're accesing an application via an IPsec tunnel, you should see the following:
sh cry isa sa --> will display the status of phase 1 which is going to be Active or QM_IDLE
sh cry ips sa --> will disply the SAs for each pair of subnets communicating through the tunnel
If you don't get any output, perhaps the communication is taking place without going through the tunnel?
Federico.