cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
417
Views
10
Helpful
4
Replies

VPN monitoring

marcio.tormente
Level 4
Level 4

Hello folks,

Can anyone tell me how can I make shure that a specific trafic is going to VPN Tunnel?

How can I monitor this trafic on ASDM or CLI?

I have a network that shoulb be pass though the VPN, but I'm not sure if is working.

Thanks

Marcio

4 Replies 4

Philip D'Ath
VIP Alumni
VIP Alumni

In the ASDM go "Monitor" and then "VPN".  If the encryption/decryption counters are increasing then traffic is flowing over that VPN connection.

Hello Philip,

I have many differents IP range that pass though the VPN, see only the encryption/decryption counters doesn´t show me if a specific range or IP is going to or not the VPN.

I need monitoring a specific IP or range.

Thanks

I would use "Tools/Packet Tracer" and simulate the flow and see if it reports it is going via VPN.

Marvin Rhoads
Hall of Fame
Hall of Fame

From the cli, use the command:

show crypto ipsec sa

That will show you all the pairwise Security Associations (SAs) - i.e .source and destination subnets for each given site-site VPN.