_______________________________________________________________________________________________________
_____________________________________________________________________________________________________
© Virtual Access 2017
GW3300 Series User Manual
Issue: 1.7
Page 263 of 372
27.6
IPSec diagnostics using the web interface
27.6.1
IPSec status
In the top menu, click Status -> IPSec. The IPSec Connections page appears.
Figure 130: The IPSec connections page
In the Name column, the syntax contains the IPSec Name defined in package dmvpn and
the remote IP address of the hub, or the spoke separated by an underscore; for
example, dmvpn_213.233.148.2.
27.7
IPSec diagnostics using UCI
27.7.1
IPSec configuration
To view IPSec configuration via UCI, enter:
root@VA_router:~# uci export strongswan
To restart strongSwan, enter:
root@VA_router:~# etc/init.d/strongswan restart
27.7.2
IPSec status
27.7.3
To view IPSec status, enter:
root@VA_router:~# ipsec statusall
Security Associations (1 up, 0 connecting):
dmvpn_89_101_154_151[1]: ESTABLISHED 2 hours ago,
10.68.234.133[10.68.234.133]...89.101.154.151[89.101.154.151]
dmvpn_89_101_154_151{1}: REKEYING, TRANSPORT, expires in 55 seconds
dmvpn_89_101_154_151{1}: 10.68.234.133/32[gre] === 192.168./32[gre]
dmvpn_89_101_154_151{1}: INSTALLED, TRANSPORT, ESP in UDP SPIs: cca7b970_i
d874dc90_o
dmvpn_89_101_154_151{1}: 10.68.234.133/32[gre] === 89.101.154.151/32[gre]
To view a list of IPSec commands, enter:
root@VA_router:~# ipsec –help