# show crypto isakmp sa
Active SA: 2 Rekey SA: 0 Total IKE SA: 2 1 IKE Peer: <Tunnen1EndpointIP> Type : L2L Role : initiator Rekey : no State : MM_ACTIVE
# debug crypto isakmp
# no debug crypto isakmp
# show crypto ipsec sa
interface: outside
Crypto map tag: <CryptoMapNane>, seq num: 2, local addr: <RouterLocalIPAddr>
access-list integ-ppe-loopback extended permit ip any vpc_subnet subnet_mask
local ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0)
remote ident (addr/mask/prot/port): (<VPCCIDRRange>/<VPCSubnetMask>/0/0)
current_peer: integ-ppe1
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#send errors: 0, #recv errors: 0
local crypto endpt.: <RouterLocalIPAddr>, remote crypto endpt.: <CloudhubVPN_IP>
path mtu 1500, ipsec overhead 74, media mtu 1500
current outbound spi: <OutboundSA_SPI>
current inbound spi : <InboundSA_SPI>
inbound esp sas:
spi: <InboundSA_SPI> (123456789)
transform: esp-aes esp-sha-hmac no compression
in use settings ={L2L, Tunnel, PFS Group 2, }
slot: 0, conn_id: 4710400, crypto-map: <VPN_CryptoMap>
sa timing: remaining key lifetime (kB/sec): (4374000/3593)
IV size: 16 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
outbound esp sas:
spi: 0x6D9F8D3B (1234567890)
transform: esp-aes esp-sha-hmac no compression
in use settings ={L2L, Tunnel, PFS Group 2, }
slot: 0, conn_id: 4710400, crypto-map: <VPN_CryptoMap>
sa timing: remaining key lifetime (kB/sec): (4374000/3593)
IV size: 16 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
# debug crypto ipsec
# no debug crypto ipsec
# show run crypto
crypto ipsec transform-set <transform-set-name> esp-aes esp-sha-hmac crypto map <VPN_CryptoMap> 1 match address access-list-name crypto map <VPN_CryptoMap> 1 set pfs crypto map <VPN_CryptoMap> 1 set peer <CloudhubVPN_IP_1> <CloudhubVPN_IP_2> crypto map <VPN_CryptoMap> 1 set transform-set <transform-set-name> crypto map <VPN_CryptoMap> 1 set security-association lifetime seconds 3600
# show run access-list <access-list-name>
access-list <access-list-name> extended permit ip any <VPCCIDRRange> <VPCSubnetMask>
001114461

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.