H3C MSR Series Command Reference Manual page 543

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

<Sysname> display ipsec sa brief
-----------------------------------------------------------------------
Interface/Global
-----------------------------------------------------------------------
GE1/0/1
GE1/0/1
GE1/0/1
Global
Table 79 Command output
Field
Interface/Global
Dst Address
SPI
Protocol
Status
# Display the number of IPsec SAs.
<Sysname> display ipsec sa count
Total IPsec SAs count: 4
# Display detailed information about all IPsec SAs.
<Sysname> display ipsec sa
-------------------------------
Interface: GigabitEthernet1/0/1
-------------------------------
-----------------------------
IPsec policy: r2
Sequence number: 1
Mode: ISAKMP
-----------------------------
Tunnel id: 3
Encapsulation mode: tunnel
Perfect Forward Secrecy:
Inside VPN:
Extended Sequence Numbers enable: Y
Traffic Flow Confidentiality enable: N
Path MTU: 1443
Tunnel:
local
address: 2.2.2.2
remote address: 1.1.1.2
Flow:
sour addr: 192.168.2.0/255.255.255.0
Dst Address
SPI
10.1.1.1
400
255.255.255.255
4294967295
100::1/64
500
--
600
Description
Interface where the IPsec SA belongs to or global IPsec SA (created by using an
IPsec profile).
Remote end IP address of the IPsec tunnel.
For the IPsec SAs created by using IPsec profiles, this field displays two hyphens
(--).
IPsec SA SPI.
Security protocol used by IPsec.
Status of the IPsec SA: Active or Standby.
In a VSRP scenario, this field displays either Active or Standby.
In standalone mode, this field always displays Active.
520
Protocol
Status
ESP
Active
ESP
Active
AH
Active
ESP
Active
port: 0
protocol: ip

Advertisement

Table of Contents
loading

Table of Contents