nerdexam
Cisco

210-260 · Question #41

Which command verifies phase 1 of an IPsec VPN on a Cisco router?

The correct answer is C. show crypto isakmp sa. When a problem exist with the connectivity, even phase 1 of VPN does not come up. On the ASA, if connectivity fails, the SA output is similar to this example, which indicates possibly an incorrect crypto peer configuration and/or incorrect ISAKMP proposal configuration…

VPN

Question

Which command verifies phase 1 of an IPsec VPN on a Cisco router?

Options

  • Ashow crypto map
  • Bshow crypto ipsec sa
  • Cshow crypto isakmp sa
  • Dshow crypto engine connection active

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    86% (24)
  • D
    4% (1)

Explanation

When a problem exist with the connectivity, even phase 1 of VPN does not come up. On the ASA, if connectivity fails, the SA output is similar to this example, which indicates possibly an incorrect crypto peer configuration and/or incorrect ISAKMP proposal configuration: Router#show crypto isakmp sa 1 IKE Peer: XX.XX.XX.XX Type : L2L Role : initiator Rekey : no State : MM_WAIT_MSG2 generation-firewalls/81824-common-ipsec-trouble.html

Topics

#IPsec VPN#IKE Phase 1#ISAKMP#show commands

Community Discussion

No community discussion yet for this question.

Full 210-260 Practice