User Guide
Chapter 5. Administrative Information Base
o Connection Manager - Show Information — [Gateway|Configure Advanced
Settings], [Configure:], [r]
Read-only state information for a number of functional components of the
OmniAccess 3500 NLG platform.
− SA – IKE — [Gateway|Configure Advanced Settings|SA — IKE], [Gateway:->
SA IKE Information], [r]
List of the IKE Security Associations that currently exist between the
OmniAccess 3500 NLG gateway and remotely connected OmniAccess 3500
NLG cards. Each row in the table corresponds to one OmniAccess 3500 NLG
card and shows the following information items:
Child SAs — Number of existing IPsec Security Associations that were
established under control of this IKE Security Association.
Creation Time — Time of establishment of the IKE Security Association,
in the format: <yyyymmddhhmmss>.
Local IP — IP address (outer header) of the local endpoint of the IKE
Security Association (on the OmniAccess 3500 NLG gateway).
Remote IP — IP address (outer header) of the remote endpoint of the
IKE Security Association (on the OmniAccess 3500 NLG card).
Local Identity — Certificate ID for the local endpoint of the IKE Security
Association.
Remote Identity — Certificate ID for the remote endpoint of the IKE
Security Association.
Encryption Algorithm — Algorithm used for the encryption of packets
exchanged over the IKE Security Association.
Hash Algorithm — Algorithm used for the exchange of credentials over
the IKE Security Association.
− SA – IPsec — [Gateway|Configure Advanced Settings|SA - IPsec], [Gateway:-
> SA IPsec Information], [r]
List of the IPsec Security Associations that currently exist between the
OmniAccess 3500 NLG gateway and remotely connected OmniAccess 3500
NLG cards. Each row in the table corresponds to one OmniAccess 3500 NLG
card (i.e., one IPsec tunnel, consisting of two IPsec security associations)
and shows the following information items:
Local IP — IP address (outer header) of the local endpoint of the IPsec
tunnel (on the OmniAccess 3500 NLG gateway).
Remote IP — IP address (outer header) of the remote endpoint of the
IPsec tunnel (on the OmniAccess 3500 NLG card).
ESP SPI-In — Security Parameter Index (SPI) found in incoming IPsec
packets with ESP protection (not available with AH protection).
ESP SPI-Out — Security Parameter Index inserted in outgoing IPsec
packets with ESP protection (not available with AH protection).
91