R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
224
Syntax
display ike sa [ verbose [ connection-id connection-id | remote-address [ ipv6 ] remote-address
[ vpn-instance vpn-name ] ] ]
Views
Any view
Predefined user roles
network-admin
network-operator
mdc-admin
mdc-operator
Parameters
verbose: Displays detailed information.
connection-id connection-id: Displays detailed information about IKE SAs by connection ID in the range
of 1 to 2000000000.
remote-address: Displays detailed information about IKE SAs with the specified remote address.
ipv6: Specifies an IPv6 address.
remote-address: Remote IP address.
vpn-instance vpn-name: Displays detailed information about IKE SAs in an MPLS L3VPN. The vpn-name
argument is a case-sensitive string of 1 to 31 characters. To display information about IKE SAs on the
public network, do not specify this parameter.
Usage guidelines
If you do not specify any parameter, the command displays a summary about all IKE SAs.
Examples
# Display information about the current IKE SAs.
<Sysname> display ike sa
Connection-ID Remote Flag DOI
----------------------------------------------------------
1 202.38.0.2 RD IPSEC
Flags:
RD--READY ST--STAYALIVE RL--REPLACED FD—FADING
Table 31 Command output
Field Descri
p
tion
Connection-ID Identifier of the IKE SA.
Remote Remote IP address of the SA.
Flags
Status of the SA:
RD (READY)—The SA has been established.
ST (STAYALIVE)—This end is the initiator of the tunnel negotiation.
RL (REPLACED)—The SA has been replaced by a new one and will be deleted later.
FD (FADING)—The SA is in use, but it is about to expire and will be deleted soon.