Debugging VPN Concentrator

Unanswered Question
Nov 26th, 2007
User Badges:

Hi all,

I have a 7206VXR which serves as a VPN concentrator. In fact, there are several dozens of VPNs defined on this machine. For some reason, a recently defined VPN doesn't reach the QM_IDLE state (it stops at MM_NO_STATE). Obviously, it doesn't work.

Every VPN is placed into different VRF so there is no connection among the tunnels. But it seems that the "debug crypto isakamp" command doesn't have any extension regarding VRFs or debugging a particular gateway. So running the "crypto isakamp" debug isn't quite helpful. The problem is that it gives every piece of information it can regarding all gateways and does not separate between them. So all I have it's a huge mess of a debug output.

How can I restrict the "crypto isakamp" debug to a particular gateway / VRF?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)


This Discussion