Solved

Cisco PIX 7.1(1) clearing / dropping / killing / logout a specific isakmp point to point tunnel

Posted on 2006-06-15
3
375 Views
Last Modified: 2013-11-16
Hi:  When you do a

show isakmp sa

you get something back like

73  IKE Peer: 111.222.111.222
    Type    : L2L             Role    : initiator
    Rekey   : no              State   : MM_ACTIVE

There is a clear isakmp sa command but it will clear ALL isakmp sessions.  Is there any way to clear just the one (#73) session in this case?

Thanks in advance
0
Comment
Question by:ort11
  • 2
3 Comments
 
LVL 5

Accepted Solution

by:
renill earned 250 total points
ID: 16919357
clear ipsec sa

To clear IPSec SAs entirely or based on specified parameters, use the clear ipsec sa command in global configuration and privileged EXEC modes. You can also use an alternate form: clear crypto ipsec sa.

clear ipsec sa [counters | entry peer-addr protocol spi | peer peer-addr | map map-name]
Syntax Description
counters  (Optional) Clears all counters.
entry (Optional) Clears IPSec SAs for a specified IPSec peer, protocol and SPI.
map map-name (Optional) Clears IPSec SAs for the specified crypto map.
peer (Optional) Clears IPSec SAs for a specified peer.
peer-addr Specifies the IP address of an IPSec peer.
protocol Specifies an IPSec protocol: esp or ah.
spi Specifies an IPSec SPI.

clear ipsec sa peer-addr 111.222.111.222

check this out..
0
 
LVL 1

Author Comment

by:ort11
ID: 16942356
Cool, will check this out and get back.
0
 
LVL 1

Author Comment

by:ort11
ID: 16961279
clear ipsec sa peer 111.222.111.222

seems to work fine.  have to leave out the -addr

thanks
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now