This chapter will focus on how to troubleshoot IPsec sessions on Cisco PIX and ASA security appliances. The layout of this chapter is similar to that found in Chapter 19, "Troubleshooting Router Connections." I've broken the chapter into two areas on troubleshooting: ISAKMP/IKE Phase 1 and ISAKMP/IKE Phase 2 issues. With these two areas, I'll show you how ISAKMP/IKE Phase 1 and 2 connections are built, and what to look for when there is a problem with either of these phases.
This chapter by no means covers all possible problems you'll experience with IPsec sessions on Cisco security appliances. However, I hope to provide you with the basic background knowledge so that troubleshooting IPsec sessions on the appliances is a simpler process.
Part I: VPNs
Overview of VPNs
VPN Technologies
IPsec
PPTP and L2TP
SSL VPNs
Part II: Concentrators
Concentrator Product Information
Concentrator Remote Access Connections with IPsec
Concentrator Remote Access Connections with PPTP, L2TP, and WebVPN
Concentrator Site-to-Site Connections
Concentrator Management
Verifying and Troubleshooting Concentrator Connections
Part III: Clients
Cisco VPN Software Client
Windows Software Client
3002 Hardware Client
Part IV: IOS Routers
Router Product Information
Router ISAKMP/IKE Phase 1 Connectivity
Router Site-to-Site Connections
Router Remote Access Connections
Troubleshooting Router Connections
Part V: PIX Firewalls
PIX and ASA Product Information
PIX and ASA Site-to-Site Connections
PIX and ASA Remote Access Connections
Troubleshooting PIX and ASA Connections
Part VI: Case Study
Case Study
Index