cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
27137
Views
0
Helpful
8
Replies

How can I debug VPN connections on a Cisco ASA?

whiteford
Level 1
Level 1

Hi,

I have a Cisco ASA and I am trying to get a Cisco 877 DSL router connected to it using the ASDM VPN wizard, but can't.

I have just had the 877 DSL router connect to my Cisco Concentrator and have simlpy changed the peer address on the router to now point to the ASA's external IP instead of the Concentrator. The Concentrator is good because I like it's real-time event viewer and it can tell me if the Concentrator is even seeing the connection attempt, but how can I dall this on the ASA?

Thanks

8 Replies 8

srue
Level 7
Level 7

debug crypto isakmp

debug crypto ipsec

Can I do anything through the ASDM?

Plus how do I undebug those commands?

you can enable logging debug to the asdm and see the loggin messages on the asdm console. "un all" should stop the debug

you can enable logging debug to the asdm and see the loggin messages on the asdm console. "un all" should stop the debug

you can enable logging debug to the asdm and see the loggin messages on the asdm console. "un all" should stop the debug

Thanks, what's the best way to show the VPN's up via CLI?

show isa sa

- that will show the status of phase 1

show cry ipsec sa

- that will show the status of phase 2, as well as number of encrypted/decrypted packets

this command also help

show vpn-sessiondb detail l2l

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: