Field
sour addr
dest addr
port
protocol
SPI
Transform set
SA duration (kilobytes/sec)
SA remaining duration (kilobytes/sec)
Max received sequence-number
Max sent sequence-number
Anti-replay check enable
UDP encapsulation used for NAT traversal
Status
No duration limit for this SA
Related commands
ipsec sa global-duration
•
•
reset ipsec sa
display ipsec statistics
Use display ipsec statistics to display IPsec packet statistics.
Syntax
display ipsec statistics [ tunnel-id tunnel-id ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
tunnel-id tunnel-id: Specifies an IPsec tunnel by its ID. The value range is 0 to 4294967295. You can use
the display ipsec tunnel brief command to view the IDs of established IPsec tunnels.
Usage guidelines
If you do not specify any parameters, this command displays statistics for all IPsec packets.
Description
Source IP address of the data flow.
Destination IP address,
Port number.
Protocol type.
SPI of the IPsec SA.
Security protocol and algorithms used by the IPsec transform set.
IPsec SA lifetime, in kilobytes or seconds.
Remaining IPsec SA lifetime, in kilobytes or seconds.
Max sequence number in the received packets.
Max sequence number in the sent packets.
Whether any-replay checking is enabled.
Whether NAT traversal is used by the IPsec SA.
IPsec SA stateful failover status: active or backup.
The manual IPsec SAs do not have lifetime.
240