
589 bytes
608 bytes
8 hours
7 pkts
36 pkts
The example below shows the use of the
show ip security connection detail
command to view
the details for a specified IPsec tunnel.
veos#show ip security connection detail
source address 1.0.0.1, dest address 1.0.0.2
Inbound SPI 0x672F6CC3:
request id 1, mode transport replay-window 32, seq 0x0
stats errors:
replay-window 0, replay 0, integrity_failed 0
lifetime config:
softlimit 18446744073709551615 bytes, hardlimit 18446744073709551615
bytes
softlimit 18446744073709551615 pkts, hardlimit 18446744073709551615
pkts
expire add 0 secs, hard 0 secs
lifetime current:
589 bytes, 7 pkts
add time Wed Aug 17 17:50:28 2016, use time Wed Aug 17 17:50:31
2016
Outbound SPI 0xc5f3c373:
request id 1, mode transport replay-window 32, seq 0x0
stats errors:
replay-window 0, replay 0, integrity_failed 0
lifetime config:
softlimit 18446744073709551615 bytes, hardlimit 18446744073709551615
bytes
softlimit 18446744073709551615 pkts, hardlimit 18446744073709551615
pkts
expire add 0 secs, hard 0 secs
lifetime current:
608 bytes, 7 pkts
add time Wed Aug 17 17:50:28 2016, use time Wed Aug 17 17:50:31
2016
The example below shows the use of the
show ip sec applied-profile
command to view all profiles
currently in use by established tunnels.
veos#show ip sec applied-profile
Profile Name
Interface
Arista
Tunnel0
vEOS Routers and CSR
Use this configuration process to set up GRE-over-IPsec tunnels on CSR peer routers. Procedures are provided
for configuration using IKE version 1, or IKE version 2. Make sure to use the correct procedure based on the
selected version of IKE.
CSR Configuration
The configuration of VTI IPsec tunnels on CSR peer router instances is almost identical to the configuration of
GRE-over-IPsec tunnels on CSR peer router instances. The only difference in the configurations is tunnel mode.
For VTI IPsec tunnels, tunnel mode must be set to ipsec instead of gre (for GRE-over-IPsec tunnels, tunnel
mode must be set to gre.)
113
IPsec Support
Summary of Contents for vEOS
Page 6: ......
Page 12: ......
Page 60: ......
Page 72: ......
Page 77: ...7 Select the default network 8 Complete the launch process 77 Server Requirements ...
Page 94: ...Figure 17 Linux SRIOV PCI Passthrough based Deployment vEOS Router Configuration Guide 94 ...
Page 124: ......
Page 128: ......