261
ike-peer name: peer1
PFS: N
transform-set name: prop1
IPsec sa local duration(time based): 3600 seconds
IPsec sa local duration(traffic based): 1843200 kilobytes
policy enable: True
tfc enable: False
===========================================
IPsec profile: "btoa"
Using interface: Tunnel1
===========================================
-----------------------------
IPsec profile name: "btoa"
mode: tunnel
-----------------------------
encapsulation mode: tunnel
security data flow :
ike-peer name: btoa
PFS: N
transform-set name: method1
IPsec sa local duration(time based): 3600 seconds
IPsec sa local duration(traffic based): 1843200 kilobytes
policy enable: True
tfc enable: False
Table 39 Command output
Field Description
Interface
Interface that references the IPsec profile.
encapsulation mode
Encapsulation mode for the IPsec profile:
•
dvpn
—DVPN tunnel mode.
•
tunnel
—IPsec tunnel mode.
security data flow
ACL referenced by the IPsec profile.
As an IPsec profile does not reference any ACL, no information
is displayed for this field.
ike-peer name
IKE peer referenced by the IPsec profile.
PFS
Whether perfect forward secrecy is enabled.
DH group
Used DH group. Its value can be 1, 2, 5, or 14.
transport-set name
IPsec transform set referenced by the IPsec profile.
IPsec sa local duration(time based)
Time-based SA lifetime at the local end.
IPsec sa local duration(traffic based)
Traffic-based SA lifetime at the local end.
policy enable
Whether the IPsec policy is enabled.
tfc enable
Whether TFC padding is enabled.