Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

How to capture spoke to spoke VPN traffic on ASA

Hi, I am debugging intermittent hairpin VPN traffic between EZVPN clients, ASA 5520 is ezvpn server. I am trying to determine where the packet is dropped.

From one client continuous ping to the other client is issued, the ping packets should go to ASA's outside interface, decrypted and encrypted and again be sent out the same outside interface. When I do capture for the ping packets on ASA's outside interface, nothing is captured even when ping is successful.

ping capture from ezvpn client to ASA inside network is fine.

How should I do packet capture in this VPN hairpin scenario? Thanks a lot for your help.

4 REPLIES

Re: How to capture spoke to spoke VPN traffic on ASA

What is the access-list you are using to capture on the outside interface?

Regards

Farrukh

Community Member

Re: How to capture spoke to spoke VPN traffic on ASA

EZVPN client is running at network extension mode, each user is using 172.16.0.0/28 address space, so the ACL I am using is something like this: access-list ping_acl extended permit icmp host 172.16.0.1 host 172.16.0.17

Re: How to capture spoke to spoke VPN traffic on ASA

Try the following:

access-list ping_acl extended permit icmp host 172.16.0.1 host 172.16.0.17 log

access-list ping_acl extended permit icmp host 172.16.0.17 host 172.16.0.1 log

See if you get hits in the log (besides the capture).

Also make sure you clear the VPN sessions/connections before testing, an easy way would be

clear local-host all

clear crypto isakmp sa

clear crypto ipsec sa

Regards

Farrukh

Community Member

Re: How to capture spoke to spoke VPN traffic on ASA

Thank you for your help, unfortunately this is not a lab environment, I can not do any of those clear commands unless a maintenance window is scheduled.

792
Views
0
Helpful
4
Replies
CreatePlease to create content