R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
182
Table 24 Command output
Field Descri
p
tion
Interface/Global Interface where the IPsec SA belongs to or global IPsec SA.
Dst Address Remote end IP address of the IPsec tunnel.
SPI IPsec SA SPI.
Protocol Security protocol used by IPsec.
Status
Stateful failover status of the IPsec SA: active or backup.
In standalone mode, this field displays .
# Display the number of IPsec SAs.
<Sysname> display ipsec sa count
Total IPsec SAs count: 4
# Display information about all IPsec SAs.
<Sysname> display ipsec sa
-------------------------------
Interface: Vlan-interface1
-------------------------------
-----------------------------
IPsec policy: map1
Sequence number: 10
Mode: manual
-----------------------------
Tunnel id: 0
Encapsulation mode: tunnel
Path MTU: 1427
Tunnel:
local address: 192.168.0.61
remote address: 192.168.0.64
Flow:
as defined in ACL 3101
[Inbound ESP SA]
SPI: 54321 (0x0000d431)
Transform set: ESP-ENCRYPT-AES-CBC-192 ESP-AUTH-SHA1
No duration limit for this SA
[Outbound ESP SA]
SPI: 12345 (0x00003039)
Transform set: ESP-ENCRYPT-AES-CBC-192 ESP-AUTH-SHA1
No duration limit for this SA
Table 25 Command output
Field Description
Interface Interface where the IPsec SA belongs.
IPsec policy Name of the used IPsec policy.