cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
29860
Views
3
Helpful
4
Replies

debug crypto isakmp on ASA

NAVIN PARWAL
Level 2
Level 2

Folks,

I have an ASA and would like to see why my ipsec tunnel is not coming up.

I enable logging. and then type in "debug crypto isakmp", but see nothing, in old pix could, it was so easy to troubleshoot but with 7.x code is there a good command to see debug output?

4 Replies 4

husycisco
Level 7
Level 7

Hi Navin

try

debug crypto isakmp 50

Also using syslogs is really useful. You know ASDM has one built-in. Set the loggig level to notifications

Regards

JORGE RODRIGUEZ
Level 10
Level 10

if doing the debug from telnet session you need to enable terminal monitor, try this.

ciscoasa#terminal monitor

then use your debug , to disable it issue terminal no monitor

HTH

Jorge

Jorge Rodriguez

Quick trick, since debug can run away on you making it hard to enter commands. do this enter the NO version of the command first then enter the command like.

no debug crypto isa

debug crypto isa

that way if it takes off all you do is hit up arrow once and return to end the command.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card