[ND-JNDL-FW]dis ike sa
Connection-ID Remote Flag DOI
------------------------------------------------------------------
7241 112.5.134.8 RD IPsec
Flags:
RD--READY RL--REPLACED FD-FADING RK-REKEY
[ND-JNDL-FW]dis ipsec sa
-------------------------------
Interface: GigabitEthernet1/0/4
-------------------------------
-----------------------------
IPsec policy: jn
Sequence number: 10
Mode: ISAKMP
-----------------------------
Tunnel id: 0
Encapsulation mode: tunnel
Perfect Forward Secrecy: dh-group1
Inside VPN:
Extended Sequence Numbers enable: N
Traffic Flow Confidentiality enable: N
Path MTU: 1420
Tunnel:
local address: 192.168.1.3
remote address: 112.5.134.8
Flow:
sour addr: 192.168.17.0/255.255.255.0 port: 0 protocol: ip
dest addr: 192.168.10.0/255.255.255.0 port: 0 protocol: ip
[Inbound ESP SAs]
SPI: 2202432271 (0x8346730f)
Connection ID: 21474836483
Transform set: ESP-ENCRYPT-AES-CBC-128 ESP-AUTH-SHA1
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843200/3367
Max received sequence-number: 0
Anti-replay check enable: Y
Anti-replay window size: 64
UDP encapsulation used for NAT traversal: Y
Status: Active
[Outbound ESP SAs]
SPI: 922318686 (0x36f9775e)
Connection ID: 12884901890
Transform set: ESP-ENCRYPT-AES-CBC-128 ESP-AUTH-SHA1
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843200/3367
Max sent sequence-number: 0
UDP encapsulation used for NAT traversal: Y
Status: Active
(0)
最佳答案
检查下ipsec的流量是走的相应接口么?
是不是会负载均衡负载到其他接口了
(0)
怎么查看流量转发到其他接口?
tracert看看,
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
tracert看看,