468
Global IPsec SA
-------------------------------
-----------------------------
IPsec profile: profile
Mode: Manual
-----------------------------
Encapsulation mode: transport
[Inbound AH SAs]
SPI: 1234563 (0x0012d683)
Connection ID: 9
Transform set: AH-SHA1
No duration limit for this SA
[Outbound AH SAs]
SPI: 1234563 (0x002d683)
Connection ID: 10
Transform set: AH-SHA1
No duration limit for this SA
Table 70 Command output
Field
Description
Interface
Interface where the IPsec SA belongs.
IPsec policy
Name of the IPsec policy.
IPsec profile
Name of the IPsec profile.
Sequence number
Sequence number of the IPsec policy entry.
Mode
Negotiation mode used by the IPsec policy:
•
Manual
•
ISAKMP
•
Template
•
GDOI
Tunnel id
IPsec tunnel ID.
Encapsulation mode
Encapsulation mode, transport or tunnel.
Perfect Forward Secrecy
Perfect Forward Secrecy (PFS) used by the IPsec policy for
negotiation:
•
768-bit Diffie-Hellman group (
dh-group1
)
•
1024-bit Diffie-Hellman group (
dh-group2
)
•
1536-bit Diffie-Hellman group (
dh-group5
)
•
2048-bit Diffie-Hellman group (
dh-group14
)
•
2048-bit and 256_bit subgroup Diffie-Hellman group
(
dh-group24
)
•
256-bit ECP Diffie-Hellman group (
dh-group19
)
•
384-bit ECP Diffie-Hellman group (
dh-group20
)
Extended Sequence Number enable
Whether Extended Sequence Number (ESN) is enabled.
Traffic Flow Confidentiality enable
Whether Traffic Flow Confidentiality (TFC) padding is enabled.
Inside VRF
VPN instance to which the protected data flow belongs.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...