<DIV>Thank you Paul.</DIV>
<DIV>on 2009-09-08,"Paul Wouters" <paul@xelerance.com> wrote :<BR>>On Mon, 7 Sep 2009, weiruyao wrote:<BR>><BR>>> If not ,is there another way to show me the status of the IPSec SA.Can<BR>>> setkey do the task?<BR>><BR>>remove setkey. Its an old tool that should not be used at all. Instead<BR>>use:<BR>><BR>>ip xfrm policy<BR>>ip xfrm state<BR>><BR>>Paul</DIV>
<DIV>I have tried.The ip xfrm command can't get the detail status such as the number of packets encrypted since the ipsec sa established,idle time,first used time,added time,etc.</DIV>
<DIV>Any other methods to be get these things?</DIV>
<DIV>Thank you in advance.<BR></DIV><br><br><span title="neteasefooter"/><hr/>
<a href="http://www.yeah.net/?from=footer">没有广告的终身免费邮箱,www.yeah.net</a>
</span>