[Openswan Users] the status of the IPSec SA

weiruyao weiruyao at 163.com
Mon Sep 7 23:03:17 EDT 2009


Thank you Paul.
on 2009-09-08,"Paul Wouters" <paul at xelerance.com> wrote :
>On Mon, 7 Sep 2009, weiruyao wrote:
>
>> If not ,is there another way to show me the status of the IPSec SA.Can
>> setkey do the task?
>
>remove setkey. Its an old tool that should not be used at all. Instead
>use:
>
>ip xfrm policy
>ip xfrm state
>
>Paul
I have tried.The ip xfrm command can't get the detail status such as the number of packets encrypted since the ipsec sa established,idle time,first used time,added time,etc.
Any other methods to be get these things?
Thank you in advance.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20090908/fdb9ead6/attachment-0001.html 


More information about the Users mailing list