Viewing L2TP over IPSec Connection Information

The show vpn-sessiondb command includes protocol filters that you can use to view detailed information about L2TP over IPSec connections. The full command from global configuration mode is show vpn-sessoindb detailed remote filter protocol l2tpOverIpsec.

The following example shows the details of a single L2TP over IPSec connection:

hostname# show vpn-sessiondb detail remote filter protocol L2TPOverIPSec

Session Type:

Remote Detailed

Username

b_smith

Index

1

Assigned IP

90.208.1.200

Public IP

Protocol

L2TPOverIPSec

Encryption

Hashing

SHA1

Bytes Tx

418464

Bytes Rx

Client Type

Client Ver

Group Policy

DfltGrpPolicy

Tunnel Group

DefaultRAGroup

Login Time

13:24:48 UTC Thu Mar

30 2006

Duration

1h:09m:18s

Filter Name

#ACSACL#-IP-ACL4Clients-440fa5aa

NAC Result

N/A

Posture Token:

424440

H Viewing L2TP over IPSec Connection Information

IKE Sessions: 1 IPSec Sessions: 1 L2TPOverIPSec Sessions: 1

IKE:

Session ID UDP Src Port IKE Neg Mode Encryption Rekey Int (T) D/H Group

Main

3DES

28800 Seconds 2

UDP Dst Port Auth Mode Hashing Rekey Left(T)

preSharedKeys SHA1

24643 Seconds

IPSec:

Session ID Local Addr Remote Addr Encryption Encapsulation Rekey Int (T) Rekey Int (D) Idle Time Out Bytes Tx Pkts Tx

80.208.1.2/255.255.255.255/17/1701 70.208.1.212/255.255.255.255/17/1701

3DES

Transport 3600 Seconds 95000 K-Bytes 30 Minutes 419064 4201

Hashing

Rekey Left(T) Rekey Left(D) Idle TO Left Bytes Rx Pkts Rx

SHA1

2856 Seconds 95000 K-Bytes 30 Minutes 425040 4227

L2TPOverIPSec: Session ID Username Assigned IP Encryption Idle Time Out Bytes Tx Pkts Tx

l2tp

90.208.1.200 none

30 Minutes

301386

4198

Auth Mode Idle TO Left Bytes Rx Pkts Rx

30 Minutes

306480

4224

The following example shows the details of a single L2TP over IPSec over NAT connection:

hostname# show vpn-sessiondb detail remote filter protocol L2TPOverIPSecOverNAtT

Session Type: Remote Detailed

Username Index

Assigned IP Protocol Hashing Bytes Tx Client Type Group Policy Tunnel Group Login Time Duration Filter Name NAC Result Posture Token v_gonzalez

90.208.1.202 Public IP

L2TPOverIPSecOverNatT Encryption MD5

1009 Bytes Rx

Client Ver

DfltGrpPolicy l2tpcert

14:35:15 UTC Thu Mar 30 2006 0h:00m:07s

70.208.1.2 3DES

2241

IKE Sessions: 1 IPSecOverNatT Sessions: 1 L2TPOverIPSecOverNatT Sessions: 1

IKE:

Viewing L2TP over IPSec Connection Information H

Session ID UDP Src Port IKE Neg Mode Encryption Rekey Int (T) D/H Group

4500 Main 3DES

3 00 Seconds 2

UDP Dst Port Auth Mode Hashing Rekey Left(T)

4500

rsaCertificate MD5

294 Seconds

IPSecOverNatT: Session ID Local Addr Remote Addr Encryption Encapsulation Rekey Int (T) Idle Time Out Bytes Tx Pkts Tx

80.208.1.2/255.255.255.255/17/1701 70.208.1.2/255.255.255.255/17/0

3DES

Transport 300 Seconds 1 Minutes 1209 20

Hashing

Rekey Left(T) Idle TO Left Bytes Rx Pkts Rx

293 Seconds 1 Minutes 2793 32

L2TPOverIPSecOverNatT:

Session ID Username Assigned IP Encryption Idle Time Out Bytes Tx Pkts Tx

v_gonzalez

90.208.1.202

none

1 Minutes

Auth Mode Idle TO Left Bytes Rx Pkts Rx

1 Minutes

2224

Continue reading here: Permitting Intra Interface Traffic

Was this article helpful?

0 0