210-260 · Question #41
Which command verifies phase 1 of an IPsec VPN on a Cisco router?
The correct answer is C. show crypto isakmp sa. When a problem exist with the connectivity, even phase 1 of VPN does not come up. On the ASA, if connectivity fails, the SA output is similar to this example, which indicates possibly an incorrect crypto peer configuration and/or incorrect ISAKMP proposal configuration…
Question
Which command verifies phase 1 of an IPsec VPN on a Cisco router?
Options
- Ashow crypto map
- Bshow crypto ipsec sa
- Cshow crypto isakmp sa
- Dshow crypto engine connection active
How the community answered
(28 responses)- A7% (2)
- B4% (1)
- C86% (24)
- D4% (1)
Explanation
When a problem exist with the connectivity, even phase 1 of VPN does not come up. On the ASA, if connectivity fails, the SA output is similar to this example, which indicates possibly an incorrect crypto peer configuration and/or incorrect ISAKMP proposal configuration: Router#show crypto isakmp sa 1 IKE Peer: XX.XX.XX.XX Type : L2L Role : initiator Rekey : no State : MM_WAIT_MSG2 generation-firewalls/81824-common-ipsec-trouble.html
Topics
Community Discussion
No community discussion yet for this question.