[c-nsp] ASA EZVPN config

Ahmad Cheikh-Moussa acm at netuse.de
Sat Apr 28 06:10:54 EDT 2007


Hi!

> When I add vpnclient management clear to my vpnclient config, then everything
> works. Is this a new feature ?
One another question. The output of the show crypto isakmp sa has changed.
With 6.x, if a tunnel is established, the state were QM_Idle.
Now with 7.x it is AM_Active. On an IOS Router it is still QM_Idle.

Now I'am little bit confused.
Can someone explain me, why this has changed ?
What is the difference between QM_Idle and AM_Active ?
Until now I thought, if a tunnel is in active mode, then I have 
a problem with it.

sh crypto isakmp sa

   Active SA: 1
    Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1

1   IKE Peer: 1.1.1.2
    Type    : user            Role    : initiator
    Rekey   : no              State   : AM_ACTIVE

Regards,
 Ahmad




-- 
Ahmad Cheikh-Moussa 
NetUSE AG
Dr.-Hell-Straße, 24107 Kiel, Germany
Telefon: +49 431 2390 400 --  Telefax: +49 431 2390 499
Service: Service at NetUSE.DE --  http://NetUSE.DE/

Vorstand: Andreas Seeger (Vorsitz), Dr. Roland Kaltefleiter, Dr. Jörg Posewang
Aufsichtsrat: Detlev Hübner (Vorsitz)
Sitz der AG: Kiel, HRB 5358 USt.ID: DE156073942

Diese E-Mail enthält vertrauliche oder rechtlich geschützte Informationen.
Das unbefugte Kopieren dieser E-Mail oder die unbefugte Weitergabe der
enthaltenen Informationen ist nicht gestattet.

The information contained in this message is confidential or protected by
law. Any unauthorised copying of this message or unauthorised distribution
of the information contained herein is prohibited.



More information about the cisco-nsp mailing list