Viewing L2TP over IPSec Connection Information
The show vpn-sessiondb command includes protocol filters that you can use to view detailed information about L2TP over IPSec connections. The full command from global configuration mode is show vpn-sessoindb detailed remote filter protocol l2tpOverIpsec.
The following example shows the details of a single L2TP over IPSec connection:
|
Session Type: |
Remote Detailed |
|
|
Username |
b_smith |
|
|
Index |
1 |
|
|
Assigned IP |
90.208.1.200 |
Public IP |
|
Protocol |
L2TPOverIPSec |
Encryption |
|
Hashing |
SHA1 |
|
|
Bytes Tx |
418464 |
Bytes Rx |
|
Client Type |
Client Ver |
|
|
Group Policy |
||
|
Tunnel Group |
DefaultRAGroup |
|
|
Login Time |
13:24:48 UTC Thu Mar |
30 2006 |
|
Duration |
1h:09m:18s |
|
|
Filter Name |
#ACSACL#-IP-ACL4Clients-440fa5aa |
|
|
NAC Result |
N/A |
|
|
Posture Token: |
424440 H Viewing L2TP over IPSec Connection Information IKE Sessions: 1 IPSec Sessions: 1 L2TPOverIPSec Sessions: 1 IKE: Session ID UDP Src Port IKE Neg Mode Encryption Rekey Int (T) D/H Group Main 3DES UDP Dst Port Auth Mode Hashing Rekey Left(T) preSharedKeys SHA1 24643 Seconds IPSec: Session ID Local Addr Remote Addr Encryption Encapsulation Rekey Int (T) Rekey Int (D) Idle Time Out Bytes Tx Pkts Tx 80.208.1.2/255.255.255.255/17/1701 70.208.1.212/255.255.255.255/17/1701 3DES Transport 3600 Seconds 95000 K-Bytes 30 Minutes 419064 4201 Hashing Rekey Left(T) Rekey Left(D) Idle TO Left Bytes Rx Pkts Rx SHA1 2856 Seconds 95000 K-Bytes 30 Minutes 425040 4227 L2TPOverIPSec: Session ID Username Assigned IP Encryption Idle Time Out Bytes Tx Pkts Tx l2tp 90.208.1.200 none 30 Minutes 301386 4198 Auth Mode Idle TO Left Bytes Rx Pkts Rx 30 Minutes 306480 4224 The following example shows the details of a single L2TP over IPSec over NAT connection: hostname# show vpn-sessiondb detail remote filter protocol L2TPOverIPSecOverNAtT Session Type: Remote Detailed Username Index Assigned IP Protocol Hashing Bytes Tx Client Type Group Policy Tunnel Group Login Time Duration Filter Name NAC Result Posture Token v_gonzalez 90.208.1.202 Public IP L2TPOverIPSecOverNatT Encryption MD5 1009 Bytes Rx Client Ver DfltGrpPolicy l2tpcert 14:35:15 UTC Thu Mar 30 2006 0h:00m:07s 70.208.1.2 3DES 2241 IKE Sessions: 1 IPSecOverNatT Sessions: 1 L2TPOverIPSecOverNatT Sessions: 1 IKE: Viewing L2TP over IPSec Connection Information H Session ID UDP Src Port IKE Neg Mode Encryption Rekey Int (T) D/H Group 4500 Main 3DES 3 00 Seconds 2 UDP Dst Port Auth Mode Hashing Rekey Left(T) 4500 rsaCertificate MD5 294 Seconds IPSecOverNatT: Session ID Local Addr Remote Addr Encryption Encapsulation Rekey Int (T) Idle Time Out Bytes Tx Pkts Tx 80.208.1.2/255.255.255.255/17/1701 70.208.1.2/255.255.255.255/17/0 3DES Transport 300 Seconds 1 Minutes 1209 20 Hashing Rekey Left(T) Idle TO Left Bytes Rx Pkts Rx 293 Seconds 1 Minutes 2793 32 L2TPOverIPSecOverNatT: Session ID Username Assigned IP Encryption Idle Time Out Bytes Tx Pkts Tx v_gonzalez 90.208.1.202 none 1 Minutes Auth Mode Idle TO Left Bytes Rx Pkts Rx 1 Minutes 2224 |
|
Continue reading here: Permitting Intra Interface Traffic
Was this article helpful?