cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
344
Views
0
Helpful
2
Replies

Tunnel is up but no traffic

D@1984
Level 1
Level 1

I have configured a tunnel and doing 'show crypto ikev2 sa' and 'show crypto ipsec sa', I can see that there is no issue. by doing pings, 'show access-list' verifying the hits, and doing 'show crypto ipsec sa', I can see the encrypted packets increasing, however I have 0 decaps!

I assume that the other end might not responding, but how can I prove that the traffic actually passing through the tunnel? Is there any command I can use? perhaps packet capture or debug(I have an ISR router)?

 

2 Replies 2

Hi D@1984 

 You can prove it by showing the encaps. If you have encaps packets means the traffic is leaving you router/firewall and it is not returning as you have no decaps.

 Ask the other side to verify the access-list.

Kamal Malhotra
Cisco Employee
Cisco Employee

Encaps in the 'show crypto ipse sa' and ESP packets in the outbound captures on the WAN interface should be enough evidence. You can also recommend them to check for decals on their device and also for inbound packet captures on the WAN interface of the peer device.