Skip to main content
hjboven
New Member
March 26, 2018
Solved

Status of Site to Site IPsec with multiple Phase 2 Selectors

  • March 26, 2018
  • 1 reply
  • 10325 views

Hi,  We newly connected via IPsec VPN with multiple subnets on both sides. 

I used the VPN Wizzard to establish the VPN and the Tunnelstatus shows up 

But of course this is only an indication of the whole as multiple Phase 2 Selectors have been entered.

 

Most of it is working fine. But yes you guessed it 1 of the 9 Subnets on my side is unreachable.

Is there a way to see the status of the indvidual Phase 2 Selectors ??

    Best answer by emnoc

    Yes

     

    diag vpn tunne list

     

    scan thru the output for each proxy-id and look at the SPI and bytes-sent/recv

     

    if you have a SPI value , than I would 1 > check routing & fw.policy and 2>the cli cmd  diag debug flow is your friend.

     

    Check out 

    http://socpuppet.blogspot.com/2013/10/site-2-site-routed-vpn-trouble-shooting.html

     

    1 reply

    emnoc
    emnocAnswer
    New Member
    March 26, 2018

    Yes

     

    diag vpn tunne list

     

    scan thru the output for each proxy-id and look at the SPI and bytes-sent/recv

     

    if you have a SPI value , than I would 1 > check routing & fw.policy and 2>the cli cmd  diag debug flow is your friend.

     

    Check out 

    http://socpuppet.blogspot.com/2013/10/site-2-site-routed-vpn-trouble-shooting.html

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!