command for ip xfrm state
-
i am using mikrotik tunnel with pfsense router, and find some in-state-sequence-errors value on the mikrotik, and i now want to compare,So whenever this counter increases, there is at least one "miskeyed" SA.
This is command for mikrotik/ip ipsec installed-sa print
, but i need it for pfsense, i tried something like this
ip xfrm state
but command not found..
-
@mercy_angel
ipsec statusall
or
swanctl --list-sas
or
setkey -Dip xfrm state - it's a Linux command
-
@konstanti said in command for ip xfrm state:
ipsec statusall
or
swanctl --list-sas
or
setkey -DThanks a lot!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.