Cisco Cisco Packet Data Gateway (PDG)

Seite von 5133
show crypto   
▀   
 
 
▄  Statistics and Counters Reference, StarOS Release 16  
3716 
   
show crypto isakmp security-associations 
Table 262. 
show crypto isakmp security-associations
 Command Output Descriptions 
Field
 
Description
 
Local IPSec GW 
The IP address of the local IPSec gateway. 
Remote IPSec 
GW 
The IP address of the remote IPSec gateway. 
State 
This displays the state of the SA. 
The two letters at the beginning of the state define the IKE mode as follows: 
 
MM - Main Mode 
 
QM - Quick Mode 
 
AM - Aggressive Mode 
The letter in parentheses ( ) at the end of the state, describe where the state message was 
initiated as follows: 
 
I - Initiator 
 
R - Responder 
Lifetime 
The lifetime (time) the security association is active and amount of time remaining. 
 
show crypto managers 
Table 263. 
show crypto managers
 Command Output Descriptions 
Field
 
Description
 
Total IKEv2 Invalid-MsgId 
Notify Sent 
An invalid KE Payload was received and the receiver sent back a NOTIFY 
payload to indicate this. 
This is the number of times a NOTIFY payload was sent to indicate this error 
condition. 
Total IKEv2 Invalid-MsgId 
Notify Received 
A NOTFIY Payload was received indicating that the KE which had been 
previously sent to the peer was deemed invalid by the peer. 
Total IKEv2 Invalid-KE 
Notify Sent 
An IKE packet was received for which the message-id is invalid. A NOTIFY 
payload was sent to the peer to indicate that the received message-id was invalid. 
This maintains the count of the number of times that such a NOTIFY payload 
was sen.t