478
ACL Downloaded From KS 100.1.1.100:
rule 0 permit ip source 10.1.1.0 0.0.0.255 destination 10.1.2.0 0.0.0.255
rule 1 permit ip source 10.1.2.0 0.0.0.255 destination 10.1.1.0 0.0.0.255
rule 2 permit ip source 10.1.1.0 0.0.0.255 destination 10.1.3.0 0.0.0.255
rule 3 permit ip source 10.1.3.0 0.0.0.255 destination 10.1.1.0 0.0.0.255
KEK Policy:
Rekey transport type : Multicast
Lifetime (sec) : 243
Encrypt algorithm : AES
Key size : 128
Sig hash algorithm : SHA1
Sig key length (bit) : 2048
TEK Policy:
Interface Ethernet1/1:
IPsec SA:
SPI: 0x640321A(104870426)
Transform: ESP-ENCRYPT-AES-128 ESP-AUTH-SHA1
SA timing:
remaining key lifetime (sec): 123
Anti-replay detection: Disabled
Packets between subnet 10.1.1.0/24 and subnet 10.1.2.0/24 are encrypted/de-encrypted by GM 1
and GM 2.
# Display GM information on KS 1.
<KS1> display gdoi ks members
Group Name: ks1
Group member ID : 1.1.1.1
Group member version : 1.0
Group ID : 12345
Rekeys sent : 0
Rekey retries : 0
Rekey ACKs received : 0
Rekey ACKs missed : 0
Group member ID : 2.2.2.2
Group member version : 1.0
Group ID : 12345
Rekeys sent : 0
Rekey retries : 0
Rekey ACKs received : 0
Rekey ACKs missed : 0
Group member ID : 3.3.3.3
Group member version : 1.0
Group ID : 12345
Rekeys sent : 0
Rekey retries : 0