5.1 7-IPSec-Troubleshooting
5.1 7-IPSec-Troubleshooting
5.1 7-IPSec-Troubleshooting
Troubleshooting VPN using debug commands. Start with the debug crypto isakmp command
and walk through a successful ISAKMP SA creation. After issue, the clear crypto session
command and ping a host from one side to the other side.
R3# Debug crypto isakmp
This command, displays the encryption algorithm, hash algorithm, authentication method, and
Diffie-Hellman group configured on the device.
This command will give a quick list of all IKE and IPSec SA sessions. Using the commands can
easily verify whether an IPSec tunnel is active, down, or still negotiating.
This command verify and check crypto ACLs for hit counts.