Ruijie Community

Title: Description of show crypto ipsec sa [Print this page]

Author: admin    Time: 2017-5-4 20:23
Title: Description of show crypto ipsec sa
Description of show crypto ipsec sa

Author: admin    Time: 2017-5-4 20:23
ruijie#show crypto ipsec sa
Interface: Async 1//Local encrypted interface
Crypto map tag:3gtest, local addr 30.160.230.11  //Local IP address used for negotiation with the peer
mediamtu 1500
==================================
itemtype:static, seqno:1, id=32
local ident (addr/mask/prot/port): (192.168.1.0/0.0.0.255/0/0))   //Source IP address of the interesting traffic
remote ident (addr/mask/prot/port): (192.168.2.0/0.0.0.255/0/0))  //Destination IP address of the interesting traffic
PERMIT
#pkts encaps: 336, #pkts encrypt: 336,#pkts digest 0 //Number of encapsulated packets, encrypted packets, and digest packets sent by the local port
#pkts decaps: 58, #pkts decrypt: 58, #pkts verify 0  //Number of decapsulated packets, decrypted packets, and verification packets received by the specified port
#send errors 0, #recv errors 0 //Number of error packets that are sent and received

Inbound esp sas:
spi:0x39aea73c (967747388) //Incoming SPInumber of SA
transform:esp-sm1        //Conversion set in use
in use settings={Tunnel,} //Tunnel mode
crypto map 3gtest 1//Name of the applied map
sa timing: remaining key lifetime (k/sec): (4606685/3364)  //Lifetime of the SA:remaining traffic and time
IV size: 16 bytes
Replay detection support:N
Outbound esp sas:
spi:0x437d9610 (1132303888) //Outgoing SPI number of the SA
transform:esp-sm1        //Conversion set in use
in use settings={Tunnel,} //Tunnel mode
crypto map 3gtest 1
sa timing: remaining key lifetime (k/sec): (4606685/3364)  //Lifetime of the SA:remaining traffic and time
IV size: 16 bytes
Replay detection support:N






Welcome to Ruijie Community (https://community.ruijienetworks.com/) Powered by Discuz! X3.2