660
Re-register in
Period of time after which the GM re-registers with a KS.
N/A
indicates that the GM does not re-register with a KS.
Succeeded registrations Number of successful registrations.
Attempted registrations Number of registration attempts.
Last rekey from
KS from which the GM receives the last rekey message.
N/A
indicates that the GM does not receive any rekey messages.
Last rekey seq num
Sequence number of the last received rekey message.
N/A
indicates that the GM does not receive any rekey messages.
Multicast rekeys received
Number of multicast rekeys received. This field is displayed only
when the GDOI GM group is a multicast group.
Unicast rekeys received
Number of unicast rekeys received. This field is displayed only
when the GDOI GM group is a unicast group.
Rekey ACKs sent
Number of rekey ACK messages sent. This field is displayed only
when the GDOI GM group is a unicast group.
Allowable rekey cipher
Rekey encryption algorithms that the GM allows.
Any
indicates
that the GM allows all encryption algorithms.
Allowable rekey hash
Rekey hash algorithms that the GM allows.
Any
indicates that the
GM allows all hash algorithms.
Allowable transform
Rekey transform modes that the GM allows.
Any
indicates that
the GM allows all transform modes.
Rekeys cumulative Rekey statistics.
Total received Total number of rekeys that the GM has received.
Rekeys after latest registration
Number of rekeys that the GM has received after the last
successful registration.
Last rekey received for
Period of time for which the key has existed after the last rekey
operation.
N/A
indicates that no rekey message is received. This
field is displayed only in multicast mode.
Total rekey ACKs sent
Number of rekey ACK messages sent. This field is displayed only
in unicast mode.
ACL downloaded from KS 90.1.1.1 ACL information downloaded from the KS at 90.1.1.1.
rule 0 deny udp source-port eq 848
destination-port eq 848
UDP packets whose source and destination port numbers are
both 848 do not need to be protected by IPsec.
rule 1 deny ospf OSPF protocol packets do not need to be protected by IPsec.
rule 2 permit icmp All ICMP packets need to be protected by IPsec.
KEK KEK information.
Rekey transport type Transport type of rekey messages:
Multicast
or
Unicast
.
Remaining key lifetime KEK lifetime in seconds.
Encrypt algorithm KEK encryption algorithm.
Key size KEK key length.
Signature algorithm KEK signature algorithm.
Signature hash algorithm KEK signature hash algorithm.
Signature key length KEK signature key length in bits.