263
Table 40 Command output
Field Description
Src Address
Local IP address. For SAs generated through GDOI policies or SAs generated
through policies that are applied to IPv6 routing protocols, "—" is displayed for
this field.
Dst Address
Remote IP address. For SAs generated through GDOI policies or SAs
generated through policies that are applied to IPv6 routing protocols, "—" is
displayed for this field.
SPI Security
parameter
index.
Protocol
Security protocol used by IPsec.
Algorithm
Authentication algorithm and encryption algorithm used by the security
protocol, where E indicates the encryption algorithm and A indicates the
authentication algorithm. A value of NULL means that type of algorithm is not
specified.
# Display detailed information about all IPsec SAs.
<Sysname> display ipsec sa
===============================
Interface: GigabitEthernet3/0/1
path MTU: 1500
===============================
-----------------------------
IPsec policy name: "r2"
sequence number: 1
acl version: ACL4
mode: isakmp
-----------------------------
PFS: N, DH group: none
tunnel:
local address: 2.2.2.2
remote address: 1.1.1.2
flow:
sour addr: 192.168.2.0/255.255.255.0 port: 0 protocol: IP
dest addr: 192.168.1.0/255.255.255.0 port: 0 protocol: IP
[inbound ESP SAs]
spi: 0xd47b1ac1(3564837569)
transform: ESP-ENCRYPT-DES ESP-AUTH-MD5
in use setting: Tunnel
connection id: 1
sa duration (kilobytes/sec): 4294967295/604800
sa remaining duration (kilobytes/sec): 1843200/2686
anti-replay detection: Enabled
anti-replay window size(counter based): 32
udp encapsulation used for nat traversal: N
status: active