Archive for December, 2006

Cisco VPN Refresh Commands

Friday, December 1st, 2006

Some handy commands when it comes to refreshing a site to site vpn that has stopped working.

show isakmp sa - Displays the current status of ISAKMP SAs

show crypto ipsec sa - Displays the current status of IPSec SAs-useful for ensuring traffic is being encrypted

clear crypto isakmp sa – Clears ISAKMP SAs

clear crypto ipsec sa – Clears IPSec SAs

debug crypto isakmp – Displays ISAKMP (IKE) communications between the PIX Firewall and IPSec peers

debug crypto ipsec - Displays IPSec communications between the PIX Firewall and IPSec peers