10-24-2006 07:32 AM - edited 02-21-2020 02:41 PM
Does anyone know the correct syslog messages that will let me know if my site-to-site VPN is down? Thanks.
10-24-2006 07:53 AM
Well don't have the exact syslog message BUT a quick way to find out if the tunnel is up or not is to issue:
sh isakmp sa - example below...
What you should be looking for is the state i.e. QM_IDLE anything apart from this will indicate a problem
with the tunnel setup.
dst src state pending created
The above is from a PIX.
Hope this helps and pls rate posts!!
10-24-2006 07:55 AM
try command
snmp-server enable traps isakmp tunnel stop
for more details check following links
http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124tcr/tsec_r/sec_s2ht.htm#wp1370703
M.
Hope that helps rate if it does
10-24-2006 09:38 AM
I guess I should have specified.. This is a site-to-site VPN between a PIX 515E and an ASA 5520. The router commands don't really help. Any ideas on the ASA/PIX syslog message to look for downed VPN connections? Thanks.
10-24-2006 10:14 AM
hmmm ...
there are some messages that could be usefull
but dont know if there are the right one :
http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_70/syslog/saslapa.htm
else try to kill your site-to-site vpn and see that the log says :-)
Martin
DK
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide