1-24
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the ASA to Integrate with Cisco TrustSec
Monitoring the ASA Integrated with Cisco TrustSec
Peer IP Local IP Conn Status Duration (dd:hr:mm:sec)
-----------------------------------------------------------------------------
2.2.2.1 2.2.2.2 On 0:00:02:14
3.3.3.1 3.3.3.2 On 0:00:02:14
------------------------------------------------------------------------------------------
Peer IP Local IP Conn Status Duration
(dd:hr:mm:sec)
------------------------------------------------------------------------------------------
1234::A8BB:CCFF:FE00:1101 1234::A8BB:CCFF:FE00:2202 On 0:00:02:14
This example displays a detailed information about each SXP connections enabled on the ASA:
hostname# show cts sxp connections
SXP : Enabled
Highest version : 2
Default password : Set
Default local IP : Not Set
Reconcile period : 120 secs
Retry open period : 10 secs
Retry open timer : Not Running
Total number of SXP connections : 2
----------------------------------------------
Peer IP : 2.2.2.1
Local IP : 2.2.2.2
Conn status : Delete Hold Down
Local mode : Listener
Ins number : 3
TCP conn password : Set
Delete hold down timer : Running
Reconciliation timer : Not Running
Duration since last state change: 0:00:00:16 (dd:hr:mm:sec)
----------------------------------------------
Peer IP : 3.3.3.1
Local IP : 3.3.3.2
Conn status : On
Local mode : Listener
Ins number : 2
TCP conn password : Default
Delete hold down timer : Not Running
Reconciliation timer : Not Running
Duration since last state change: 0:00:05:49 (dd:hr:mm:sec)
This example displays data for all SXP connections:
hostname# show connection security-group
100 in use, 90 most used
TCP inside (security-group mktg(3)) 10.1.1.1:2000 outside (security-group 111)
172.23.59.53:21, idle 0:00:00, bytes 10, flags ...
TCP inside (security-group mktg(3)) 10.1.1.1:2010 outside (security-group 222)
172.23.59.53:21, idle 0:00:00, bytes 10, flags ...
...
This example displays the SXP connection matching specific SGT values for source and destination:
hostname# show connection security-group tag 3 security-group tag 111
1 in use
TCP inside (security-group mktg(3)) 10.1.1.1:2000 outside (security-group 111)
172.23.59.53:21, idle 0:00:00, bytes 10, flags ...