Re: ASA site-to-site VPN problem

From: Bogdan Sass <bogdan.sass_at_catc.ro>
Date: Mon, 01 Jun 2009 11:08:19 +0300

Farrukh Haroon wrote:
> Also you should ignore the packet-tracer output and check the 'show
> cyrpto ipsec sa' output on both sides.
>
> Are the encr/decr counters incrementing adequately?
] Yes, but there is no way of telling what kind of traffic is hitting
the counters (as I was saying, some of the traffic makes it through, and
some doesn't).

-- 
Bogdan Sass
CCAI,CCSP,JNCIA-ER,CCIE #22221 (RS)
Information Systems Security Professional
"Curiosity was framed - ignorance killed the cat"
Blogs and organic groups at http://www.ccie.net
Received on Mon Jun 01 2009 - 11:08:19 ART

This archive was generated by hypermail 2.2.0 : Wed Jul 01 2009 - 20:02:36 ART