Show crypto ipsec sa

Unanswered Question
Jun 7th, 2009
User Badges:

Hi all. I have applied a crypto map to an interface that is shut. But when i do sh crypto ipsec sa, i can see the entry for this interface as well. Although all counters are zero but i am confused why is it showing at all ?

If i only want to see active interfaces which are actually passing the traffic how can i see them ? is there anyway to exclude interfaces that are not active ?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Farrukh Haroon Tue, 06/09/2009 - 00:52
User Badges:
  • Red, 2250 points or more

There are a number of parameters avaialble in the 'show crypto ipsec sa' command to filter the output:

show crypto ipsec sa ?

address IPSEC SA table in (dest) address order

detail show counter detail

identity IPSEC SADB identity tree

interface Show info for specific interface

ipv6 Show IPv6 crypto IPsec SA info

map IPSEC SA table for a specific crypto map

peer Show peer sas

vrf VRF Routing/Forwarding instance

| Output modifiers

Also you can do something like

show crypto ipsec sa | include interface|tag|ident|encr|decr




This Discussion