Cisco Cisco Packet Data Gateway (PDG) Guia De Resolução De Problemas
show crypto
show crypto ipsec security-associations statistics ▀
Cisco ASR 5000 Series Statistics and Counters Reference ▄
OL-22990-02
Field
Description
negotiated hard lifetime
(kb/sec)
(kb/sec)
The hard lifetime negotiated by the system and the security gateway for outbound SAs. The lifetime is
measured in terms kilobytes (kb) and/or seconds (sec).
The hard lifetime that dictates the maximum duration for the SA before its termination.
measured in terms kilobytes (kb) and/or seconds (sec).
The hard lifetime that dictates the maximum duration for the SA before its termination.
remaining hard lifetime
(kb/sec)
(kb/sec)
The amount of kilobytes and/or seconds remaining to the hard lifetime from what was initially
negotiated.
negotiated.
Encoded
The number of packets and bytes that have been encoded for the SA.
Encode Errors
The number of errors that have occurred while encoding packets.
inbound esp sas
spi
The inbound (from the system to the security gateway) security parameter index (SPI) used for the
Encapsulating Security Payload protocol.
Encapsulating Security Payload protocol.
transform
The protocols configured for the transform set used by the crypto map for inbound tunnels.
negotiated soft lifetime
(kb/sec)
(kb/sec)
The soft lifetime negotiated by the system and the security gateway for inbound SAs. The lifetime is
measured in terms kilobytes (kb) and/or seconds (sec).
The soft lifetime is used to warn that the SA is about to expire allowing the systems to negotiate a new
lifetime prior to the expiration of the hard lifetime.
measured in terms kilobytes (kb) and/or seconds (sec).
The soft lifetime is used to warn that the SA is about to expire allowing the systems to negotiate a new
lifetime prior to the expiration of the hard lifetime.
remaining soft lifetime
(kb/sec)
(kb/sec)
The amount of kilobytes and/or seconds remaining to the soft lifetime from what was initially
negotiated.
negotiated.
negotiated hard lifetime
(kb/sec)
(kb/sec)
The hard lifetime negotiated by the system and the security gateway for inbound SAs. The lifetime is
measured in terms kilobytes (kb) and/or seconds (sec).
The hard lifetime that dictates the maximum duration for the SA before its termination.
measured in terms kilobytes (kb) and/or seconds (sec).
The hard lifetime that dictates the maximum duration for the SA before its termination.
remaining hard lifetime
(kb/sec)
(kb/sec)
The amount of kilobytes and/or seconds remaining to the hard lifetime from what was initially
negotiated.
negotiated.
Decoded
The number of packets and bytes that have been decoded for the SA.
Decode Errors
The number of errors that have occurred while decoding packets.
Authentication Errors
The number of errors that occurred during the system/security gateway authentication process.
Replay Errors
The number of replay errors that occurred for the SA.
Too Short Errors
The number of too short errors that occurred for the SA.
ISAKMP sessions
established for this
tunnel
established for this
tunnel
The total number of sessions successfully connected by this SA.
ISAKMP sessions failed
for this tunnel
for this tunnel
The total number of sessions that failed to be connected by this SA.
ISAKMP for this tunnel
NOTE: These items are displayed for the life of the ISAKMP SA.
Phase1 Completed as
Responder
Responder
Indicates the state of the Phase 1 IPSec negotiation stage and role of the system (either responder or
initiator).
initiator).
Statistics
Displays statistics for the ISAKMP SA.
IN
The number of packets/bytes received.
OUT
The number of packets/bytes transmitted.