Cisco 2800 Series Manual page 168

Hide thumbs Also See for 2800 Series:
Table of Contents

Advertisement

Verify
The following is an output example for the show crypto ipsec sa command, performed using the
configuration on the Branch 1 router:
Branch-1# show crypto ipsec sa
interface: Tunnel0
Crypto map tag: INT_CM, local addr. 10.32.153.34
protected vrf:
local
remote ident (addr/mask/prot/port): (10.32.152.26/255.255.255.255/47/0)
current_peer: 10.32.152.26:500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 78341, #pkts encrypt: 78341, #pkts digest: 78341
#pkts decaps: 118387, #pkts decrypt: 118387, #pkts verify: 118387
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0
#pkts not decompressed: 0, #pkts decompress failed: 0
#send errors 11, #recv errors 0
local crypto endpt.: 10.32.153.34, remote crypto endpt.: 10.32.152.26
path mtu 1420, media mtu 1420
current outbound spi: D5823DEF
inbound esp sas:
spi: 0x69111392(1762726802)
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0xD5823DEF(3582082543)
outbound ah sas:
outbound pcp sas:
interface: Virtual-Template1
Crypto map tag: INT_CM, local addr. 10.32.153.34
protected vrf:
local
remote ident (addr/mask/prot/port): (10.32.152.26/255.255.255.255/47/0)
current_peer: 10.32.152.26:500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 78380, #pkts encrypt: 78380, #pkts digest: 78380
OL-6573-01
28
ident (addr/mask/prot/port): (10.32.153.34/255.255.255.255/47/0)
transform: esp-3des esp-sha-hmac ,
in use settings ={Tunnel, }
slot: 0, conn id: 5151, flow_id: 31, crypto map: INT_CM
crypto engine type: Hardware, engine_id: 2
sa timing: remaining key lifetime (k/sec): (508937407/10703)
ike_cookies: 795753FB 41D07F6D DE2C7D5A FB6197B3
IV size: 8 bytes
replay detection support: Y
transform: esp-3des esp-sha-hmac ,
in use settings ={Tunnel, }
slot: 0, conn id: 5152, flow_id: 32, crypto map: INT_CM
crypto engine type: Hardware, engine_id: 2
sa timing: remaining key lifetime (k/sec): (508938275/10702)
ike_cookies: 795753FB 41D07F6D DE2C7D5A FB6197B3
IV size: 8 bytes
replay detection support: Y
ident (addr/mask/prot/port): (10.32.153.34/255.255.255.255/47/0)
Hoot and Holler over V3PN Configuration Example

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents