Display Ipsec Statistics - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Field
Max sent sequence-number
Anti-replay check enable
UDP encapsulation used for NAT
traversal
Status
No duration limit for this SA
Related commands
ipsec sa global-duration
reset ipsec sa

display ipsec statistics

Use display ipsec statistics to display IPsec packet statistics.
Syntax
display ipsec statistics [ tunnel-id tunnel-id ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
tunnel-id tunnel-id: Specifies an IPsec tunnel by its ID. The value range for the tunnel-id argument is
0 to 4294967295. You can use the display ipsec tunnel brief command to view the IDs of
established IPsec tunnels.
Usage guidelines
If you do not specify any parameters, this command displays statistics for all IPsec packets.
Examples
# Display statistics for all IPsec packets.
<Sysname> display ipsec statistics
IPsec packet statistics:
Received/sent packets: 47/64
Received/sent bytes: 3948/5208
Dropped packets (received/sent): 0/45
Dropped packets statistics
No available SA: 0
Wrong SA: 0
Invalid length: 0
Authentication failure: 0
Description
Max sequence number in the sent packets.
Whether anti-replay checking is enabled.
Whether NAT traversal is used by the IPsec SA.
Status of the IPsec SA: Active or Standby.
In a VSRP scenario, this field displays either Active or
Standby.
In standalone mode, this field always displays Active.
The manual IPsec SAs do not have lifetime.
523

Advertisement

Table of Contents
loading

Table of Contents