ruijie#show crypto ipsec sa Interface: Async 1//Local encrypted interface Crypto map tag:3gtest, local addr 30.160.230.11 //Local IP address used for negotiation with the peer mediamtu 1500 ================================== itemtype:static, seqno:1, id=32 local ident (addr/mask/prot/port): (192.168.1.0/0.0.0.255/0/0)) //Source IP address of the interesting traffic remote ident (addr/mask/prot/port): (192.168.2.0/0.0.0.255/0/0)) //Destination IP address of the interesting traffic PERMIT #pkts encaps: 336, #pkts encrypt: 336,#pkts digest 0 //Number of encapsulated packets, encrypted packets, and digest packets sent by the local port #pkts decaps: 58, #pkts decrypt: 58, #pkts verify 0 //Number of decapsulated packets, decrypted packets, and verification packets received by the specified port #send errors 0, #recv errors 0 //Number of error packets that are sent and received
Inbound esp sas: spi:0x39aea73c (967747388) //Incoming SPInumber of SA transform:esp-sm1 //Conversion set in use in use settings={Tunnel,} //Tunnel mode crypto map 3gtest 1//Name of the applied map sa timing: remaining key lifetime (k/sec): (4606685/3364) //Lifetime of the SA:remaining traffic and time IV size: 16 bytes Replay detection support:N Outbound esp sas: spi:0x437d9610 (1132303888) //Outgoing SPI number of the SA transform:esp-sm1 //Conversion set in use in use settings={Tunnel,} //Tunnel mode crypto map 3gtest 1 sa timing: remaining key lifetime (k/sec): (4606685/3364) //Lifetime of the SA:remaining traffic and time IV size: 16 bytes Replay detection support:N
|