IP Security - Virtual Private Network
Left running head:
Chapter name (automatic)
850
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
Alcatel-Lucent
T
O VIEW IPSEC SECURITY ASSOCIATION
EXAMPLE
ALU# show crypto ipsec sa
GigabitEthernet3/1
Crypto Map: ALU Match m1
Peer 60.60.60.2
********INBOUND********
ESP Algo:crypt:DES-CBC len:64 auth:SHA1-HMAC len:160
TUNNEL MODE Replay Detection Enabled: Yes
ESP spi:0xc3fb59c time-left:28793secs/0kb esp-sa-id:12
Decaps:7 Decrypt:7 Auth:7 Errors:0
********OUTBOUND********
ESP Algo:crypt:DES-CBC len:64 auth:SHA1-HMAC len:160
TUNNEL MODE Replay Detection Enabled: Yes
ESP spi:0x541a7498 time-left:28793secs/0kb esp-sa-id:16
Encaps:7 Encrypt:7 Auth:7 Errors:0
Command (in SUM/CM) Description
show crypto ipsec sa
[interface <name>|map
<name>|peer <ip-address>]
This command displays IPsec SA details,
the encryption and authentication algorithms
used in negotiating SAs.
It also displays dynamic information like
SPI's and SA-ID's, information/statistics
about all the VPN tunnels that are active and
in use.