Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

Show crypto ipsec sa

Hi all. I have applied a crypto map to an interface that is shut. But when i do sh crypto ipsec sa, i can see the entry for this interface as well. Although all counters are zero but i am confused why is it showing at all ?

If i only want to see active interfaces which are actually passing the traffic how can i see them ? is there anyway to exclude interfaces that are not active ?

1 REPLY

Re: Show crypto ipsec sa

There are a number of parameters avaialble in the 'show crypto ipsec sa' command to filter the output:

show crypto ipsec sa ?

address IPSEC SA table in (dest) address order

detail show counter detail

identity IPSEC SADB identity tree

interface Show info for specific interface

ipv6 Show IPv6 crypto IPsec SA info

map IPSEC SA table for a specific crypto map

peer Show peer sas

vrf VRF Routing/Forwarding instance

| Output modifiers

Also you can do something like

show crypto ipsec sa | include interface|tag|ident|encr|decr

Regards

Farrukh

388
Views
0
Helpful
1
Replies
CreatePlease to create content