
Cisco Systems, Inc.
All contents are Copyright © 1992–2004 Cisco Systems, Inc. All rights reserved. Important Notices and Privacy Statement.
Page 8 of 9
IV size: 8 bytes
replay detection support: Y
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0x86EA4824(2263500836)
transform: esp-3des esp-sha-hmac ,
in use settings ={Tunnel, }
slot: 0, conn id: 201, flow_id: 2, crypto map: dynmap
sa timing: remaining key lifetime (k/sec): (4462290/3450)
IV size: 8 bytes
replay detection support: Y
outbound ah sas:
outbound pcp sas:
Cisco1751#
sh crypto isakmp sa
dst src state conn-id slot
20.20.20.2 20.20.20.10 QM_IDLE 1 0
Cisco1751#
show crypto engine connections active
ID Interface IP-Address State Algorithm Encrypt Decrypt
1 Ethernet0/0 20.20.20.2 set HMAC_SHA+3DES_56_C 0 0
200 Ethernet0/0 20.20.20.2 set HMAC_SHA+3DES_56_C 0 0
201 Ethernet0/0 20.20.20.2 set HMAC_SHA+3DES_56_C 134 0
202 Ethernet0/0 20.20.20.2 set HMAC_SHA+3DES_56_C 0 770
203 Ethernet0/0 20.20.20.2 set HMAC_SHA+3DES_56_C 0 0
TROUBLESHOOTING THE CONFIGURATION
Certain
show
commands are supported by the
Output Interpreter Tool
(
registered
customers only), which analyzes
show
command output.
Note:
Before issuing
debug
commands, see
Important Information about Debug Commands
.
•
debug crypto isakmp
—Displays errors during Phase 1.
•
debug crypto ipsec
—Displays errors during Phase 2.
•
debug crypto engine
—Displays information from the crypto engine.
•
debug ip your routing protocol
—Displays information about routing transactions of the routing protocol.
•
clear crypto connection connection-id [slot | rsm | vip]
—Terminates an encrypted session currently in progress.
Encrypted sessions normally terminate when the session times out. Use the
show crypto cisco connections
command to see the connection-id value.
•
clear crypto isakmp
—Clears the Phase 1 security associations.
•
clear crypto sa
—Clears the Phase 2 security associations.
Kommentare zu diesen Handbüchern