[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Show the status of a VPN in Cisco firewall/router?

Posted on 2004-11-18
5
Medium Priority
?
9,609 Views
Last Modified: 2009-12-16
Hi all,

I have an ipsec site-to-site VPN established between a Cisco 2600 router and a PIX 506 firewall.  I want to be able to telnet into each device and show the status of this VPN tunnel.  Specifically, I want to know if the VPN tunnel is up or not.  

What command(s) will accomplish this, and how do I interpret the results?

Thanks!
0
Comment
Question by:visioneer
  • 3
  • 2
5 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 12620070
Use
PIX# show cry is sa
Router# show cry is sa

Look for the IP address of the peer and a QM_IDLE state. As long as you see QM_IDLE the tunnel is established and happy
0
 
LVL 5

Author Comment

by:visioneer
ID: 12620100
What commands am I doing to look for this?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 2000 total points
ID: 12620388
"show crypto is sa"
0
 
LVL 5

Author Comment

by:visioneer
ID: 12620436
Okay, so the state is MM_NO_STATE.  I assume that means my VPN is broken?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12621080
MM_NO_STATE means the ISAKMP config on one side is not right
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question