Clear VPN Tunnel phase1/phase2

Answered Question
Nov 5th, 2009

Is it possible to clear individual tunnels without bringing them all down? I've seen the clear crypt ips sa & cl crypt isa sa, but that's global. Is there something that I can do to pinpoint individual tunnels to kill?

Thanks!

Correct Answer by hdashnau about 7 years 3 months ago

If its an ASA, you can also teardown specific tunnels using their index numbers.

To get the index number do "show vpn-sessiondb <(l2l,remote,svc,webvpn)>" command

To log it off do "vpn-sessiondb logoff index " command

-heather

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
hdashnau Thu, 10/29/2009 - 08:14

If its an ASA, you can also teardown specific tunnels using their index numbers.

To get the index number do "show vpn-sessiondb <(l2l,remote,svc,webvpn)>" command

To log it off do "vpn-sessiondb logoff index " command

-heather

cameron.moody Thu, 11/05/2009 - 09:34

I'm not aware of a command that will let you specify for just phase 1 of a peer.

clear crypto session remote will reset phase 1 and 2 though

Actions

This Discussion