05-07-2024 11:43 AM - edited 05-07-2024 12:31 PM
Is there a way to verify VPN use and uptime? I believe that the below command will only show output for the duration of the security association, which could be for an unknown time period. Do you know a way to verify when counters were last cleared for the below command?
sh crypto ipsec sa peer x.x.x.x
I'm trying to determine if a VPN can be turned off and need output from the VPN headends (routers in this case) as proof of VPN inactivity.
FYI this is a policy based VPN.
Cisco IOS XE Software, Version 03.16.10.S
ASR 10002
05-07-2024 12:00 PM - edited 05-07-2024 12:02 PM
@hocus-pokus-alakazoo if it's a policy based VPN it requires regular traffic to maintain the VPN, so if there are IPSec SAs then the VPN is in use.
05-07-2024 12:26 PM
yes, this is a policy based vpn
05-07-2024 12:02 PM
Show crypto isakmp sa detail
Show crypto ipsec sa detail
Show crypto session sa detail
Check the lifetime for phaseI and PhaseII from above three command
MHM
05-07-2024 12:34 PM
this is a policy based VPN and there has been no traffic on it for a while. I want to know how long there's been no traffic so as to tear down the SA.
05-07-2024 12:40 PM
@hocus-pokus-alakazoo With a policy based VPN there needs to be interesting traffic to establish and maintain the VPN. If there is no activity the lifetime timers will expire, the SA will not be renewed and the tunnel will be torn down automatically. If the tunnel goes down (due to lack of interesing traffic) only when interesting traffic is sent/received will the tunnel be re-established. SA lifetimes are 24 hours maximum, so if there are IPSec SA then the tunnel has been used recently.
05-07-2024 12:45 PM
The tunnel phaseI and phaseII
PhaseI lifetime is 24 hours' after that vpn will delete if
there is no traffic and we use keepalive on demand
If we use keepalive periodic then phaseI auto re-nego after 24 hrs
Now For phaseII' if you see encrypt and decrypt SPI then there is active traffic between two peer' if you dont see SPI then there is no traffic.
MHM
05-07-2024 01:03 PM - edited 05-07-2024 01:28 PM
so it sounds like there is no way to tell how long the SA has been dead beyond 24 hours....we can't conclude that a VPN has been inactive for say "30 days"?
05-07-2024 01:08 PM - edited 05-07-2024 01:08 PM
@hocus-pokus-alakazoo with a policy based VPN there will be no IPSec SA if the timers have expired due to lack of interesting traffic.
05-07-2024 01:08 PM
No we can not.
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide