357
regular-expression
: Specifies a regular expression, a case-sensitive string of 1 to 256 characters.
Description
Use the
display ike sa
command to display information about the current IKE SAs.
If you do not specify any parameters or keywords, the command displays brief information about the
current IKE SAs.
Related commands:
ike proposal
and
ike peer
.
Examples
# Display brief information about the current IKE SAs.
<Sysname> display ike sa
total phase-1 SAs: 1
connection-id peer flag phase doi
----------------------------------------------------------
1 202.38.0.2 RD|ST 1 IPSEC
2 202.38.0.2 RD|ST 2 IPSEC
flag meaning
RD--READY ST--STAYALIVE RL--REPLACED FD—FADING TO—TIMEOUT
Table 58
Output description
Field Description
total phase-1 SAs
Total number of SAs for phase 1
connection-id
Identifier of the ISAKMP SA
peer
Remote IP address of the SA
flag
Status of the SA:
•
RD (READY): The SA has been established.
•
ST (STAYALIVE): This end is the initiator of the tunnel negotiation.
•
RL (REPLACED): The tunnel has been replaced by a new one and will be deleted
later.
•
FD (FADING): The soft lifetime is over but the tunnel is still in use. The tunnel will
be deleted when the hard lifetime is over.
•
TO (TIMEOUT): The SA has received no keepalive packets after the last keepalive
timeout. If no keepalive packets are received before the next keepalive timeout,
the SA will be deleted.
phase
The phase the SA belongs to:
•
Phase 1: The phase for establishing the ISAKMP SA.
•
Phase 2: The phase for negotiating the security service. IPsec SAs are established
in this phase.
doi
Interpretation domain the SA belongs to
# Display detailed information about the current IKE SAs.
<Sysname> display ike sa verbose
---------------------------------------------
connection id: 2
transmitting entity: initiator
---------------------------------------------
local ip: 4.4.4.4