[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 423
  • Last Modified:

Show vpn active

i am working with a Cisco 501, how can i show the active vpn ?
Can i 'reset' just one ?

Thank you,
1 Solution
>>>>i am working with a Cisco 501, how can i show the active vpn ?

If you are using the CLI, just do a "show crypto isa sa" on the PIX. If you are using a PDM (GUI), just go to the
Monitoring TAB under VPN statistics>IKE SA's.

>>>>Can i 'reset' just one ?

It depends what you want to reset. There's two things you can reset, Phase 1 and Phase 2. If you want to reset
the IPSEC SA which is phase 2 then you can do so. This won't disconnect the VPN user, it would just renegotiate
phase 2.  But if you want to reset phase 1 which is equivalent to disconnecting a particular VPN connection, then unfortunately you can't. When you clear phase 1, all of the existing VPN connection will be disconnected.

To clear phase 2: (Reset a specific VPN connection)

clear crypto ipsec sa peer x.x.x.x --> where x.x.x.x is the public IP address of the VPN user

To clear phase 1: (Disconnects all existing VPN connection)

clear crypto isa sa


Featured Post

New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now