Check Tunnel Status
Use the following command to verify the tunnel status on your ISR.
show crypto session detail
and the output must show the tunnel status as UP-ACTIVE.
Substitute the IP address of the Secure Access data center nearest your location for \[sse_dc_ip\]
.
ISR#show crypto session detail
Crypto session current status
Code: C - IKE Configuration mode, D - Dead Peer Detection
K - Keepalives, N - NAT-traversal, T - cTCP encapsulation
X - IKE Extended Authentication, F - IKE Fragmentation
R - IKE Auto Reconnect, U - IKE Dynamic Route Update
Interface: Tunnel1
Profile: sse
Uptime: 14:53:47
Session status: UP-ACTIVE
Peer: \[sse_dc_ip\] port 4500 fvrf: (none) ivrf: (none)
Phase1_id: \[sse_dc_ip\]
Desc: (none)
Session ID: 1
IKEv2 SA: local 10.10.10.201/4500 remote \[sse_dc_ip\]/4500 Active
Capabilities:DFNXU connid:4 lifetime:09:06:13
IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0
Active SAs: 2, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) 4608000/2499
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 4608000/2499