show crypto ipsec sa ipv6
Display the IPsec security associations (SAs) used on OSPFv3 interfaces.
E-Series TeraScale, Z-Series, S4810
Syntax
show crypto ipsec sa ipv6 [interface interface]
Parameters
interface 
interface
(OPTIONAL) Displays information about the SAs used on a specified 
OSPFv3 interface, where 
interface 
is one of the following values:
• For a 1-Gigabit Ethernet interface, enter GigabitEthernet 
slot
/
port
.
• For a Port Channel interface, enter port-channel 
number
. 
Valid port-channel numbers (on an E-Series TeraScale): 1 to 
255.
• For a 10-Gigabit Ethernet interface, enter TenGigabitEthernet 
slot
/
port
.
• For a 40–Gigabit Ethernet interface, enter fortyGigE 
slot
/
port
.
• For a VLAN interface, enter vlan 
vlan-id
. Valid VLAN IDs: 1 to 
4094.
Defaults No default behavior or values.
Command Modes
EXEC
EXEC Privilege
Command History
Version 9.1.(0.0) Introduced on the S4810 and Z9000.
Version 8.4.2.0 Introduced on the E-Series TeraScale.
Usage 
Information
The show crypto ipsec sa ipv6 command output displays security associations set up for 
OSPFv3 links in IPsec authentication and encryption policies on the router.
Related 
Commands
show crypto 
ipsec policy
Display the configuration of IPsec authentication and encryption 
policies.
Example
FTOS#show crypto ipsec policy
FTOS#show crypto ipsec sa ipv6
Interface: TenGigabitEthernet 0/0
 Link Local address: fe80::201:e8ff:fe40:4d10
 IPSecv6 policy name: OSPFv3-1-500
 
 inbound ah sas
  spi : 500 (0x1f4)
   transform : ah-md5-hmac
   in use settings : {Transport, }
   replay detection support : N
   STATUS : ACTIVE
1123