Stanislav Kozlov писал(а):
sh cry ip sa
sh cry ip sa det
[skip]
PERMIT, flags={origin_is_acl,}
#pkts encaps: 94305, #pkts encrypt: 94305, #pkts digest: 94305
#pkts decaps: 109661, #pkts decrypt: 109661, #pkts verify: 109661
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0
#pkts not decompressed: 0, #pkts decompress failed: 0
#pkts no sa (send) 41, #pkts invalid sa (rcv) 0
#pkts encaps failed (send) 0, #pkts decaps failed (rcv) 0
#pkts invalid prot (recv) 0, #pkts verify failed: 0
#pkts invalid identity (recv) 0, #pkts invalid len (rcv) 0
#pkts replay rollover (send): 0, #pkts replay rollover (rcv) 0
##pkts replay failed (rcv): 0
#pkts internal err (send): 0, #pkts internal err (recv) 0
local crypto endpt.: A.A.A.A, remote crypto endpt.: B.B.B.B
path mtu 1500, ip mtu 1500, ip mtu idb FastEthernet0/1
current outbound spi: 0x4B000010(1258291216)
inbound esp sas:
spi: 0x1B8189A6(461474214)
transform: esp-3des esp-md5-hmac ,
in use settings ={Tunnel, }
conn id: 3001, flow_id: FPGA:1, crypto map: DI-804HV
sa timing: remaining key lifetime (k/sec): (4425570/28720)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0x4B000010(1258291216)
transform: esp-3des esp-md5-hmac ,
in use settings ={Tunnel, }
conn id: 3002, flow_id: FPGA:2, crypto map: DI-804HV
sa timing: remaining key lifetime (k/sec): (4425569/28720)
IV size: 8 bytes
replay detection support: Y
Status: ACTIVE
outbound ah sas:
outbound pcp sas:
#sh ver
Cisco IOS Software, 1841 Software (C1841-ADVIPSERVICESK9-M), Version 12.4(8), RELEASE SOFTWARE (fc1)
Есть идеи?