cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1432
Views
0
Helpful
3
Replies

How I know my vpn site is up or what commands I cn use to chek it.?

Hi Guys

How can I check if my vpn is working > I cannot ping the other side I cannot log into the another VPN asa. 5510. Is any commands I can run?

1 Accepted Solution

Accepted Solutions

danmoren
Level 1
Level 1

You could also use the following two commands:

show crypto isakmp sa

show crypto ipsec sa

They will show you if Phase 1 and Phase 2 are up respectively.

Witht the first you can see if Phase1 is completing or if it is failing at some point.

If Phase1 is up, then with the second command you will be able to see if Phase2 is up, and if you are sending and/or receiving traffic across the tunnel.

View solution in original post

3 Replies 3

You can use the following command to see if you VPN is up:

asa#sh vpn-sessiondb l2l

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Thanks guys...

the issue was a bot attack on the remote site....rebooting the AA fix the issue Cisco Engineer told me is no fix.

danmoren
Level 1
Level 1

You could also use the following two commands:

show crypto isakmp sa

show crypto ipsec sa

They will show you if Phase 1 and Phase 2 are up respectively.

Witht the first you can see if Phase1 is completing or if it is failing at some point.

If Phase1 is up, then with the second command you will be able to see if Phase2 is up, and if you are sending and/or receiving traffic across the tunnel.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: