Monitoring A Vpn - HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

Virtual Private Networks

Monitoring a VPN

SPI—use to
clear the
session
Crypto map
used to
create the
connection
8-70
Monitoring a VPN
You can monitor the VPN tunnels supported on your router. Enter this enable
mode command to view all active SAs:
Syntax: show crypto [ike | ipsec] sa
Enter the ike keyword to view IKE SAs, which are open only temporarily to
allow peers to negotiate a VPN connection securely.
Enter the ipsec keyword to view IPSec SAs, which are the VPN tunnels over
which secured data travels. The router establishes a separate SA for each
connection between a peer on the local network and a remote peer. (See
Figure 8-14.)
IPSec Security Associations: Total IPSec SAs: 2
Peer IP Address: 10.2.2.1
Mode-config Address: 192.168.100.1
Direction: Inbound
SPI: 0x9AF31804 (2599622660)
Encapsulation: ESP
RX Bytes: 0
Selectors: Src:192.168.100.1/255.255.255.255 Port:ANY Proto:ALL IP
Dst:10.1.30.0/255.255.255.0
Hard Lifetime: 28760
Soft Lifetime: 0
Crypto Map: VPN 10
Peer IP Address: 192.168.5.23
Mode-config Address: 192.168.100.1
Direction: Outbound
SPI: 0xB4E0AE5F (3034623583)
Encapsulation: ESP
TX Bytes: 0
Selectors: Src:10.1.30.0/255.255.255.0
Dst:192.168.100.1/255.255.255.255
Hard Lifetime: 28760
Soft Lifetime: 28670
Crypto Map: VPN 10
Figure 8-14. Viewing an IPSec SA
Port:ANY
Proto:ALL IP
Port:ANY
Proto:ALL IP
Port:ANY
Proto:ALL IP

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents