(Adaptive services interface only) Display IPSec
statistics for the specified service set. If no service set is specified,
the statistics for all service sets are displayed.
Options
none — Display standard
IPSec statistics for all service sets.
brief | detail — (Optional)
Display the specified level of output.
remote-gw remote-peer-address — (Optional) Display IPSec statistics for
an individual IPSec tunnel and an individual remote host.
service-set service-set-name — (Optional) Display information about a
particular service set.
Table 244 lists
the output fields for the show services ipsec-vpn ipsec statistics command. Output fields are listed in the approximate order in which
they appear.
Table 244: show services
ipsec-vpn ipsec statistics Output Fields
Field Name
Field Description
Level of Output
PIC
The physical interface on which
the IPSec tunnel is configured.
All levels
Service set
Name of the service set for which
the IPSec tunnel is defined.
All levels
Local gateway
Gateway address of the local system.
All levels
Remote gateway
Gateway address of the remote system.
All levels
Tunnel index
Numeric identifier of the specific
IPSec tunnel for the security association.
All levels
ESP statistics
Encapsulation Security Payload
(ESP) statistics:
Encrypted bytes—Total number of bytes encrypted
by the local system across the IPSec tunnel.
Decrypted bytes—Total number of bytes decrypted
by the local system across the IPSec tunnel.
Encrypted packets—Total number of packets
encrypted by the local system across the IPSec tunnel.
Decrypted packets—Total number of packets
decrypted by the local system across the IPSec tunnel
All levels
AH Statistics
Authentication Header statistics:
Input bytes—Total number of bytes received
by the local system across the IPSec tunnel.
Output bytes—Total number of bytes transmitted
by the local system across the IPSec tunnel.
Input packets—Total number of packets received
by the local system across the IPSec tunnel.
Output packets—Total number of packets
transmitted by the local system across the IPSec tunnel.
All levels
Errors
AH authentication failures—Total number
of authentication header (AH) failures. An AH failure occurs when
there is a mismatch of the authentication header in a packet transmitted
across an IPSec tunnel.
Replay errors—Total number of replay errors.
A replay error is generated when a duplicate packet is received within
the replay window.
ESP authentication failures—Total number
of Encapsulation Security Payload (ESP) failures. An ESP failure occurs
when there is an authentication mismatch in ESP packets.
Decryption errors—Total number of decryption
errors.
Bad headers—Total number of invalid headers
detected.
Bad trailers—Total number of invalid trailers
detected.
All levels
Sample Output
show services ipsec-vpn ipsec statistics detail
user@host> show services ipsec-vpn ipsec statistics
detail