Diagnostic Commands
Chapter 5. Troubleshooting
58
View SAs
The
show ipSec sa
command displays the active SAs on the HA4000 gateway. In
addition to verifying that a specific SA is active on the HA4000, this command also
displays its SPI and lifetime.
Syntax
show ipSec sa
Response
Table 5-4 describes the fields displayed in the
show ipSec sa
command
response.
Example
admin>
show ipSec sa
Index 0
SPI 1000 (0x000003e8)
Src 192.169.50.6
Dst 192.169.51.6
Created WED MAY 01 00:00:02 2004
LIFETIMES (seconds): renegotiate 0, expire 0
View the Security Policy Database
The
show ipSec spd
command displays a summary of the contents of the
security policy database (SPD). Each entry in the database represents a policy.
Syntax
show ipSec spd [all]
Table 5-4 HA4000 Security Association Fields
Field
Description
SPI
Security parameter index uniquely identifies an SA at its
destination.
Src
Source address, displayed in dotted decimal notation.
Dst
Destination address, displayed in dotted decimal notation.
Created
Date and time that the SA was created.
Lifetimes in seconds
The
expire
lifetime is user-defined. When this timer
expires, the SA is deleted. When HA4000 gateways are
deployed in a pair, both HA4000 gateways use the shortest
of the two lifetime expiration values.
The
renegotiate
lifetime indicates the amount of time
before an SA is renegotiated; this is determined by the
HA4000. If the
expire
lifetime timer expires before the SA is
renegotiated, the SA is deleted.