New IPsec Troubleshooting Features
There are two new IPsec troubleshooting features you can use in the IOS:
IPsec VPN Monitoring: IOS 12.3(4)T
Invalid Security Parameter Index Recovery: IOS 12.3(2)T
The following three sections will discuss both of these features.
IPsec VPN Monitoring Feature
IPsec VPN monitoring is a feature new in IOS 12.3(4)T. This feature allows you to monitor VPN sessions to provide for enhanced troubleshooting. These enhancements include:
Adding a description to IKE peers so that it becomes easier to identify the peer other than using their IP address or FQDN.
Clearing a crypto session: before IOS 12.3(4)T, you had to clear both the Phase 1 and 2 connections to a peer individually to tear down the crypto session; in IOS ...