Debugging Ipsec - Patton electronics SmartNode Series Software Configuration Manual

Software for smartnode series
Hide thumbs Also See for SmartNode Series:
Table of Contents

Advertisement

22 • VPN configuration
Example: Display IPsec Transformation Profiles
SN(cfg)#show profile ipsec-transform
IPSEC transform profiles:
Name: AES_128
ESP Encryption: AES-CBC, Key length: 128
Example: Display IPsec Policy Profiles
SN(cfg)#show profile ipsec-policy-manual
Manually keyed IPSEC policy profiles:
Name: ToBerne, Peer: 200.200.200.1, Mode: tunnel, transform-profile: AES_128
ESP SPI Inbound: 1111, Outbound: 2222
ESP Encryption Key Inbound: 1234567890ABCDEF1234567890ABCDEF
ESP Encryption Key Outbound: FEDCBA0987654321FEDCBA0987654321

Debugging IPsec

A debug monitor and an additional show command are at your disposal to debug IPsec problems.
Procedure: To debug IPsec connections
Mode: Configure
Step
1
node (cfg)#debug ipsec
2
node (cfg)#show ipsec security-associ-
optional
ations
Example: IPsec Debug Output
SN(cfg)#debug ipsec
IPSEC monitor on
23:11:04
ipsec > Could not find security association for inbound ESP packet.
SPI:1201
Example: Display IPsec Security Associations
SN(cfg)#show ipsec security-associations
Active security associations:
Dir Type
Peer
270
Command
Policy
Mode
SPI AH
SPI ESP
SmartWare Software Configuration Guide
Enables IPsec debug monitor
Summarizes the configuration information of all
IPsec connections. If an IPsec connection does
not show up, then one or more parameters are
missing in the respective Policy Profile.
The information 'Bytes (processed)' supports
debugging because it indicates whether IPsec
packets depart from ('OUT') or arrive at ('IN') the
SmartNode.
Udp-Encapsulation
AH
ESP-Auth
Purpose
ESP-Enc
VPN configuration task list

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SmartNode Series and is the answer not in the manual?

This manual is also suitable for:

Smartware release 2.20

Table of Contents