[H3C-FW]display ike sa verbose
-----------------------------------------------
Connection ID: 339
Outside VPN:
Inside VPN:
Profile: to-fgt_IPv4_1
Transmitting entity: Responder
Initiator cookie: cee4fa69bb0a4237
Responder cookie: 67b034f31e39caca
-----------------------------------------------
Local IP: 101.100.1.21
Local ID type: IPV4_ADDR
Local ID: 101.100.1.21
Remote IP: 202.100.1.17
Remote ID type: IPV4_ADDR
Remote ID: 202.100.1.17
Authentication-method: PRE-SHARED-KEY
Authentication-algorithm: SHA256
Encryption-algorithm: AES-CBC-256
Life duration(sec): 86400
Remaining key duration(sec): 85628
Exchange-mode: Main
Diffie-Hellman group: Group 5
NAT traversal: Not detected
Extend authentication: Disabled
Assigned IP address:
Vendor ID index:0xffffffff
Vendor ID sequence number:0x0
[H3C-FW]
[H3C-FW]display ipsec sa
-------------------------------
Interface: GigabitEthernet1/0/1
-------------------------------
-----------------------------
IPsec policy: to-fgt
Sequence number: 1
Mode: ISAKMP
-----------------------------
Tunnel id: 0
Encapsulation mode: tunnel
Perfect Forward Secrecy: dh-group14
Inside VPN:
Extended Sequence Numbers enable: N
Traffic Flow Confidentiality enable: N
Path MTU: 1424
Tunnel:
local address: 101.100.1.21
remote address: 202.100.1.17
Flow:
sour addr: 192.168.21.0/255.255.255.0 port: 0 protocol: ip
dest addr: 192.168.17.0/255.255.255.0 port: 0 protocol: ip
[Inbound ESP SAs]
SPI: 150042999 (0x08f17977)
Connection ID: 30064771077
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/43200
SA remaining duration (kilobytes/sec): 1843145/42380
Max received sequence-number: 854
Anti-replay check enable: Y
Anti-replay window size: 64
UDP encapsulation used for NAT traversal: N
Status: Active
[Outbound ESP SAs]
SPI: 852320529 (0x32cd6111)
Connection ID: 777389080580
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/43200
SA remaining duration (kilobytes/sec): 1843147/42380
Max sent sequence-number: 839
UDP encapsulation used for NAT traversal: N
Status: Active
[H3C-FW]