Command introduced before JUNOS Release 7.4.
(Encryption interface on M Series and T Series routers only) Display information about the IPSec security associations applied to the local or transit traffic stream.
none — Display standard information about all IPSec security associations.
brief | detail — (Optional) Display the specified level of output.
sa-name — (Optional) Display the specified IPSec security association.
view
Table 236 lists the output fields for the show ipsec security-associations command. Output fields are listed in the approximate order in which they appear.
Table 236: show ipsec security-associations Output Fields
show ipsec security-associations sa-name
user@host> show ipsec security-associations
sa-cosmic brief Security association: sa-cosmic, Interface family: Up Local gateway: 21.21.1.1, Remote gateway: 21.21.2.1 Local identity: ipv4_subnet(any:0,[0..7]=0.0.0.0/0) Remote identity: ipv4_subnet(any:0,[0..7]=0.0.0.0/0) Direction SPI AUX-SPI Mode Type Protocol inbound 2908734119 0 tunnel dynamic AH outbound 3494029335 0 tunnel dynamic AH
show ipsec security-associations sa-name detail
user@host> show ipsec security-associations
sa-cosmic detail Security association: sa-cosmic, Interface family: Up Local gateway: 21.21.1.1, Remote gateway: 21.21.2.1 Local identity: ipv4_subnet(any:0,[0..7]=0.0.0.0/0) Remote identity: ipv4_subnet(any:0,[0..7]=0.0.0.0/0) Direction: inbound, SPI: 2908734119, AUX-SPI: 0, State: Installed Mode: tunnel, Type: dynamic Protocol: AH, Authentication: hmac-md5-96, Encryption: None Soft lifetime: Expired Hard lifetime: Expires in 120 seconds Anti-replay service: Disabled Direction: outbound, SPI: 3494029335, AUX-SPI: 0, State: Installed Mode: tunnel, Type: dynamic Protocol: AH, Authentication: hmac-md5-96, Encryption: None Soft lifetime: Expired Hard lifetime: Expires in 120 seconds Anti-replay service: Disabled