show ipsec-log
To view IPSec connection logs, use the
show ipsec-log
command.
show ipsec-log
Syntax Description
This command has no arguments or keywords.
Command Modes
IPSec mode
Command History
Modification
Release
Command added.
1.1(1)
Usage Guidelines
Use the
set log-level
command to change the amount of information displayed by these logs.
Example
This example shows how to display the contents of the IPSec log file:
FP9300-A #
scope security
FP9300-A /security #
scope ipsec
FP9300-A /security/ipsec #
show ipsec-log
Feb 10 23:40:02 15[CFG] <test-connection|69>
using trusted ca certificate "C=US, ST=CA,
L=SJC, O=Cisco, OU=STBU, CN=CA, [email protected]"
Feb 10 23:40:02 15[CFG] <test-connection|69>
reached self-signed root ca with a path
length of 0
Feb 10 23:40:02 15[CFG] <test-connection|69>
crl correctly signed by "C=US, ST=CA, O=CA1,
OU=ca1, CN=InterCA1, [email protected]"
Feb 10 23:40:02 15[CFG] <test-connection|69>
crl is valid: until Mar 12 22:30:51 2017
Feb 10 23:40:02 15[CFG] <test-connection|69>
using cached crl
Feb 10 23:40:02 15[CFG] <test-connection|69> certificate status is good
Feb 10 23:40:02 15[CFG] <test-connection|69>
using trusted ca certificate "C=US, ST=CA,
L=SJC, O=Cisco, OU=STBU, CN=CA, [email protected]"
Feb 10 23:40:02 15[CFG] <test-connection|69> checking certificate status of "C=US, ST=CA,
O=CA1, OU=ca1, CN=InterCA1, [email protected]"
Feb 10 23:40:02 15[CFG] <test-connection|69>
fetching crl from
'file:///opt/certstore/ssp2-tp.crl' ...
Feb 10 23:40:02 15[CFG] <test-connection|69> issuer of fetched CRL 'C=US, ST=CA, O=CA1,
OU=ca1, CN=InterCA1, [email protected]' does not match CRL issuer
'56:71:f1:d9:b1:62:fd:c3:2b:4d:cb:6b:01:85:ea:75:e5:0e:99:0d'
Feb 10 23:40:02 15[CFG] <test-connection|69>
fetching crl from
'http://192.168.0.81/interca_inuse.crl.pem' ...
Feb 10 23:40:02 15[CFG] <test-connection|69>
using trusted certificate "C=US, ST=CA,
L=SJC, O=Cisco, OU=STBU, CN=CA, [email protected]"
Feb 10 23:40:02 15[CFG] <test-connection|69>
crl correctly signed by "C=US, ST=CA, L=SJC,
O=Cisco, OU=STBU, CN=CA, [email protected]"
Feb 10 23:40:02 15[CFG] <test-connection|69>
crl is valid: until Mar 12 22:30:49 2017
Feb 10 23:40:02 15[CFG] <test-connection|69> certificate status is good
Feb 10 23:40:02 15[CFG] <test-connection|69>
reached self-signed root ca with a path
length of 1
Feb 10 23:40:02 15[IKE] <test-connection|69> authentication of 'C=US, ST=CA, O=Cisco,
OU=STBU, CN=SSP, [email protected]' with RSA signature successful
Feb 10 23:40:02 15[IKE] <test-connection|69> IKE_SA test-connection[69] established between
192.168.0.174[C=US, ST=CA, O=Cisco, OU=STBU, CN=SSP]
Cisco Firepower 4100/9300 FXOS Command Reference
298
S Commands
show ipsec-log
Содержание Firepower 4100 Series
Страница 4: ...Cisco Firepower 4100 9300 FXOS Command Reference 2 About the FXOS CLI Command Reference Guide ...
Страница 25: ...P A R T I A R Commands A C Commands on page 25 D R Commands on page 81 ...
Страница 26: ......
Страница 122: ...Cisco Firepower 4100 9300 FXOS Command Reference 120 A R Commands return ...
Страница 123: ...P A R T II S Commands scope Commands on page 123 set Commands on page 157 sh Commands on page 235 ...
Страница 124: ......
Страница 236: ...Cisco Firepower 4100 9300 FXOS Command Reference 234 S Commands set vlan ...
Страница 379: ...P A R T III T W Commands T W Commands on page 379 ...
Страница 380: ......
Страница 390: ...Cisco Firepower 4100 9300 FXOS Command Reference 388 T W Commands where ...
Страница 391: ...P A R T IV connect shell Commands connect shell Commands on page 391 ...
Страница 392: ......
Страница 420: ...Cisco Firepower 4100 9300 FXOS Command Reference 418 connect shell Commands connect module Command List ...