266
Table 41 Command output
Field Description
Interface
Interface referencing the IPsec policy.
path MTU
Maximum IP packet length supported by the interface.
Protocol
Name of the protocol to which the IPsec policy is applied.
IPsec policy name
Name of IPsec policy used.
sequence number
Sequence number of the IPsec policy.
acl version
ACL version, IPv4 ACL and IPv6 ACL.
If no ACL is referenced, this field displays
None
.
For an IPsec SA established in GDOI mode, this field is not displayed.
mode
IPsec negotiation mode.
PFS
Whether the perfect forward secrecy feature is enabled.
DH group
Used DH group. Its value can be none, 1, 2, 5, or 14.
tunnel IPsec
tunnel.
local address
Local IP address of the IPsec tunnel.
remote address
Remote IP address of the IPsec tunnel.
flow Data
flow.
current outbound spi
Value of the SPI used in the outbound direction.
sour addr
Source IP address of the data flow.
dest addr
Destination IP address of the data flow.
port Port
number.
protocol Protocol
type.
inbound
Information of the inbound SA.
outbound
Information of the outbound SA.
spi Security
parameter
index.
transform
Security protocol and algorithms used by the IPsec transform set.
in use setting
IPsec SA attribute setting: transport or tunnel.
connection id
IPsec tunnel identifier.
sa duration
Lifetime of the IPsec SA.
sa remaining duration
Remaining lifetime of the SA.
anti-replay detection
Whether IPsec anti-replay detection is enabled.
anti-replay window size(time
based)
Anti-replay window size (time-based), in seconds.
This field is not displayed if IPsec anti-replay detection is not enabled.
anti-replay window (counter
based)
Anti-replay window size (traffic-based). Its value can be 32, 64, 128,
256, 512, or 1024.
This field is not displayed if IPsec anti-replay detection is not enabled.
udp encapsulation used for nat
traversal
Whether NAT traversal is enabled for the SA.