Hoot and Holler over V3PN Configuration Example
Verify
27
OL-6573-01
3 DES: Yes
AES CBC: Yes (128,192,256)
AES CNTR: No
Maximum buffer length: 4096
Maximum DH index: 0500
Maximum SA index: 0500
Maximum Flow index: 1000
Maximum RSA key size: 2048
crypto engine name: Cisco VPN Software Implementation
crypto engine type: software
serial number: 77C943AD
crypto engine state: installed
crypto engine in slot: N/A
Verify Remote Location Connectivity
This section provides instructions for verifying that your configuration works properly.
Certain
show
commands are supported by the Output Interpreter Tool (registered customers only),
which allows you to view an analysis of
show
command output.
In general, the
show
commands that are used to verify remote location connectivity are the same as the
commands used for the Headquarters router. See the
“Verify Headquarters Connectivity” section on
for summaries of the
show
commands that are common to both Headquarters and branch
verification. The following commands are used for the remote locations only:
•
show policy-map interface virtual-access 4 output
—Shows how traffic has been queued on the
DSL interface (Branch 1). Note that different queues have different packet counts because traffic is
assigned on the basis of DCSP and IP precedence values.
•
show policy-map interface serial 0/0/0 output
—Shows how traffic has been queued on the serial
interface (Branch 2). Note that different queues have different packet counts because traffic is
assigned on the basis of DCSP and IP precedence values.
Representative output for each of these commands is presented in the verification summaries that follow.
Note
Relevant display output is highlighted in
bold
text.
Example output is split into two sections:
•
Verifying Branch 1 Router, page 27
•
Verifying Branch 2 Router, page 34
Verifying Branch 1 Router
The following is an output example for the
show crypto isakmp sa
command, performed using the
configuration on the Branch 1 router (DSL):
Branch-1#
show crypto isakmp sa
dst src state conn-id slot
10.32.152.26 10.32.153.34
QM_IDLE
4 0