13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IPSec VPN maintenanceTip:●●Use <strong>the</strong> show crypto ipsec sa list list-id [rule rule-id] [detail] CLIcommand to display <strong>the</strong> IPsec SA configuration by list ID and rule ID.Tip:The detail option in <strong>the</strong> various show crypto ipsec sa CLI commands,provides detailed counters information on each IPSec SA. To pinpoint <strong>the</strong> source<strong>of</strong> a problem, it is useful to check for a counter whose value grows with time.Use <strong>the</strong> clear crypto sa counters command to clear <strong>the</strong> crypto SA counters.IPSec VPN interventionYou can use <strong>the</strong> following clear CLI commands to intervene in IPSec VPN configuration:●●Use <strong>the</strong> clear crypto sa command to clear all IPSec SAs (security associationstructures).Use <strong>the</strong> clear crypto isakmp command to flush a specific entry in <strong>the</strong> ISAKMPdatabase or <strong>the</strong> entire ISAKMP database.Note:Note:If you wish to clear both an ISAKMP connection and <strong>the</strong> IPSec SAs, <strong>the</strong>recommended order <strong>of</strong> operations is:First clear <strong>the</strong> IPSec SAs using <strong>the</strong> clear crypto sa all command,<strong>the</strong>n clear <strong>the</strong> ISAKMP SA using <strong>the</strong> clear crypto isakmp command.IPSec VPN loggingIPSec VPN logging allows you to view <strong>the</strong> start and finish <strong>of</strong> IKE phase 1 and IKE phase 2negotiations. Most importantly, it displays <strong>the</strong> configuration <strong>of</strong> both peers, so that you canpinpoint <strong>the</strong> problem in case <strong>of</strong> a mismatch between <strong>the</strong> IPSec VPN configuration <strong>of</strong> <strong>the</strong> peers.To view <strong>the</strong> IPSec VPN syslog:1. Use <strong>the</strong> set logging session enable command to enable syslog on <strong>the</strong> session.<strong>G350</strong>-001# set logging session enableDone!CLI-Notification: write: set logging session enableIssue 3 January 2005 219

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!