469
Field
Description
Path MTU
Path MTU of the IPsec SA.
Tunnel
Local and remote addresses of the IPsec tunnel.
This field is not displayed if the negotiation mode is GDOI.
local address
Local end IP address of the IPsec tunnel.
remote address
Remote end IP address of the IPsec tunnel.
Flow
Information about the data flow protected by the IPsec tunnel.
sour addr
Source IP address of the data flow.
dest addr
Destination IP address of the data flow.
port
Port number.
protocol
Protocol type:
•
ip
—IPv4.
•
ipv6
—IPv6.
Current outbound SPI
SPI that the outbound IPsec SA currently uses.
This field is displayed when the negotiation mode is GDOI.
SPI
SPI of the IPsec SA.
Connection ID
Identifier of the IPsec SA.
Transform set
Security protocol and algorithms used by the IPsec transform
set.
SA duration (kilobytes/sec)
IPsec SA lifetime, in kilobytes or seconds.
SA remaining duration (kilobytes/sec)
Remaining IPsec SA lifetime, in kilobytes or seconds.
Max received sequence-number
Max sequence number in the received packets.
Max sent sequence-number
Max sequence number in the sent packets.
Anti-replay check enable
Whether anti-replay checking is enabled.
UDP encapsulation used for NAT
traversal
Whether NAT traversal is used by the IPsec SA.
Status
Status of the IPsec SA:
Active
or
Standby
.
In a VSRP scenario, this field displays either
Active
or
Standby
.
In standalone mode, this field always displays
Active
.
No duration limit for this SA
The manual IPsec SAs do not have lifetime.
Related commands
ipsec sa global-duration
reset ipsec sa
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...