cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
344
Views
0
Helpful
1
Replies

LAN-to-LAN VPN IKE SAs

rajesh444
Level 1
Level 1

Hi,

I have a LAN-to-LAN VPN setup between a Cisco VPN 3030 Concentrator [A]and a 2621 router [B] with AIM card. Sometimes, when clearing the existing session on both ends and initiating a new one I notice the following on the router:

Router#show crypto isa sa

dst src state conn-id slot

B A QM_IDLE 30 0

A B QM_IDLE 31 0

Which combination of source and destination is valid? I have also noticed that the IPSec session is unstable when the Concentrator tends to be the destination for the IKE session as seen on the router.

Thanks,

RAJ

1 Reply 1

7sboals
Level 1
Level 1

I have the same setup (VPN 3030 to 2621), and it shows:

router concentrator QM_IDLE XX XX