Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

show security ipsec tunnel-distribution

 

Syntax

Release Information

Command introduced in Junos OS Release 17.4R1 for SRX4600 devices.

Command introduced in Junos OS Release 18.2R2 for SRX5400, SRX5600, and SRX5800 devices.

Description

Display the number of IPsec VPN tunnels that are anchored in each thread. An IPsec tunnel session is assigned an anchor thread, based on the load during the tunnel session installation. When a new tunnel session is created, the least loaded thread is chosen to anchor the new tunnel. When the tunnel is deleted, the anchor mapping is removed from the control plane.

Tunnel distribution across different Services Processing Unit (SPU) or equivalent is based on the number of tunnels and not on throughput in each tunnel. Tunnels anchored in a SPU are not transferred to a different SPU or equivalent during SPU failure.

The distribution profile shows any assigned IPSec distribution profile without any distribution profiles assigned to a vpn object. This tab shows default_profiile, else the associated profile is displayed.

Options

noneDisplay thread information about all active tunnels.
brief(Optional) Display thread information about all active tunnels. (Default)
summary(Optional) Display the number of tunnels anchored to each thread.

Required Privilege Level

view

List of Sample Output

show security ipsec tunnel-distribution

show security ipsec tunnel-distribution summary

show security ipsec tunnel-distribution fpc 0 pic 0

show security ipsec tunnel-distribution fpc 0 pic 1

show security ipsec tunnel-distribution summary fpc 0 pic 0

show security ipsec tunnel-distribution summary fpc 0 pic 1

Output Fields

Table 1 lists the output fields for the show security ipsec tunnel-distribution command. Output fields are listed in the approximate order in which they appear.

Table 1: show security ipsec tunnel-distribution Output Fields

Field Name

Field Description

Level of Output

Tunnel-ID

VPN tunnel identifier.

brief

Thread-ID

Thread identifier.

All levels

Number of Tunnels

The number of tunnels anchored to the thread.

summary

Sample Output

show security ipsec tunnel-distribution

user@host> show security ipsec tunnel-distribution

show security ipsec tunnel-distribution summary

user@host> show security ipsec tunnel-distribution summary

show security ipsec tunnel-distribution fpc 0 pic 0

user@host> show security ipsec tunnel-distribution fpc 0 pic 0

show security ipsec tunnel-distribution fpc 0 pic 1

user@host> show security ipsec tunnel-distribution fpc 0 pic 1

show security ipsec tunnel-distribution summary fpc 0 pic 0

user@host> show security ipsec tunnel-distribution summary fpc 0 pic 0

show security ipsec tunnel-distribution summary fpc 0 pic 1

user@host> show security ipsec tunnel-distribution summary fpc 0 pic 1