Hi
I config my PIX as HUB-SPOKEN mode. Sometimes one VPN peer in trouble and I delete the IPSEC SA at branch side and it will continue working. Sometimes I delete ISAKMP SA at branch side, but the HUB side there is still the ISAKMP SA about the peer. I can'T find the command about delete the ISAKMP SA by only one. the Command "clear isakmp sa" will delete all ISAKMP SA! So how can I delete only one ISAKMP SA in group og SAs?
And, when you finished configurations about the PIX, how to troubleshooting when the VPN tunnel was broken? Do you guys have something like howto or guide such things?
thanks
oh
I config my PIX as HUB-SPOKEN mode. Sometimes one VPN peer in trouble and I delete the IPSEC SA at branch side and it will continue working. Sometimes I delete ISAKMP SA at branch side, but the HUB side there is still the ISAKMP SA about the peer. I can'T find the command about delete the ISAKMP SA by only one. the Command "clear isakmp sa" will delete all ISAKMP SA! So how can I delete only one ISAKMP SA in group og SAs?
And, when you finished configurations about the PIX, how to troubleshooting when the VPN tunnel was broken? Do you guys have something like howto or guide such things?
thanks
oh