523
Max sent sequence-number Max sequence number in the sent packets.
Anti-replay check enable Whether anti-replay checking is enabled.
UDP encapsulation used for NAT
traversal
Whether NAT traversal is used by the IPsec SA.
Status
Status of the IPsec SA:
Active
or
Standby
.
In a VSRP scenario, this field displays either
Active
or
Standby
.
In standalone mode, this field always displays
Active
.
No duration limit for this SA The manual IPsec SAs do not have lifetime.
Related commands
ipsec sa global-duration
reset ipsec sa
display ipsec statistics
Use display ipsec statistics to display IPsec packet statistics.
Syntax
display ipsec statistics [ tunnel-id tunnel-id ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
tunnel-id tunnel-id: Specifies an IPsec tunnel by its ID. The value range for the tunnel-id argument is
0 to 4294967295. You can use the display ipsec tunnel brief command to view the IDs of
established IPsec tunnels.
Usage guidelines
If you do not specify any parameters, this command displays statistics for all IPsec packets.
Examples
# Display statistics for all IPsec packets.
<Sysname> display ipsec statistics
IPsec packet statistics:
Received/sent packets: 47/64
Received/sent bytes: 3948/5208
Dropped packets (received/sent): 0/45
Dropped packets statistics
No available SA: 0
Wrong SA: 0
Invalid length: 0
Authentication failure: 0