[Openswan Users] IKE status

Mike Horn lists at caddisconsulting.com
Tue Dec 5 16:00:12 EST 2006


Hi,

Is there an easy way to get the list of IPsec peers and their IKE status?
Right now I'm using the "ipsec auto --status" command and grep'ing for
ISAKMP, but that gets painful with large number of peers and rekeys.

I was hoping for something along the lines of Cisco's "show crypto isakmp
sa" command (output below).  Which shows all peers and their current ISAKMP
state.  Is there a command in Openswan that provides similar output?

Router# show crypto isakmp sa

f_vrf/i_vrf    dst             src           state        conn-id    slot
      /vpn2    172.21.114.123  10.1.1.1      QM_IDLE           13       0
      /vpn2    172.25.13.1     10.1.1.1      QM_IDLE           13       0

Thanks,

-mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20061205/3c19cd35/attachment.html 


More information about the Users mailing list