display ipsec sa ipsec sa information: =============================== Interface: GigabitEthernet0/0/4 =============================== ----------------------------- IPSec policy name: "p_2_p1" Sequence number : 1 Acl group : 3999 Acl rule : 5 Mode : ISAKMP ----------------------------- Connection ID : 56 Encapsulation mode: Tunnel Holding time : 0d 0h 2m 25s Tunnel local : 192.168.22.100:500 Tunnel remote : 192.168.22.200:500 Flow source : 10.9.30.0/255.255.255.0 0/0-65535 Flow destination : 10.9.20.0/255.255.255.0 0/0-65535 [Outbound ESP SAs] SPI: 3386531653 (0xc9da5f45) Proposal: ESP-ENCRYPT-AES-256 ESP-AUTH-SHA2-256-128 SA remaining key duration (kilobytes/sec): 1843200/3456 Outpacket count : 0 Outpacket encap count : 0 Outpacket drop count : 0 Slice Failure: 0 Max sent sequence-number: 0 UDP encapsulation used for NAT traversal: N [Inbound ESP SAs] SPI: 9769066 (0x95106a) Proposal: ESP-ENCRYPT-AES-256 ESP-AUTH-SHA2-256-128 SA remaining key duration (kilobytes/sec): 1843200/3456 Inpacket count : 5 Inpacket decap count : 0 Inpacket drop count : 0 Authentication Failure: 0 Replay Failure: 0 Decrypt Check Failure: 0 Max received sequence-number: 0 UDP encapsulation used for NAT traversal: N Anti-replay : Enable Anti-replay window size: 1024