Site-to-site VPN monitoring between Site1 (198.51.100.2) and Site2 (203.0.113.2).
Site1 (198.51.100.2) monitors for Site2 traffic.
ubnt@Site1-EdgeRouter:~$ sudo tcpdump -i eth0 -n '(src 203.0.113.2 or dst 203.0.113.2) and (udp port 500 or udp port 4500)'
Site2 (203.0.113.2) monitors for Site1 traffic.
ubnt@Site2-EdgeRouter:~$ sudo tcpdump -i eth0 -n '(src 198.51.100.2 or dst 198.51.100.2) and (udp port 500 or udp port 4500)'
https://help.ui.com/hc/en-us/articles/204962304-EdgeRouter-Capturing-Packets