• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

command for ip xfrm state

Scheduled Pinned Locked Moved IPsec
3 Posts 2 Posters 879 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mercy_angel
    last edited by Dec 24, 2020, 3:14 PM

    i am using mikrotik tunnel with pfsense router, and find some in-state-sequence-errors value on the mikrotik, and i now want to compare,So whenever this counter increases, there is at least one "miskeyed" SA.
    This is command for mikrotik

    /ip ipsec installed-sa print
    

    , but i need it for pfsense, i tried something like this

    ip xfrm state
    

    but command not found..

    K 1 Reply Last reply Dec 24, 2020, 6:28 PM Reply Quote 0
    • K
      Konstanti @mercy_angel
      last edited by Dec 24, 2020, 6:28 PM

      @mercy_angel
      ipsec statusall
      or
      swanctl --list-sas
      or
      setkey -D

      ip xfrm state - it's a Linux command

      M 1 Reply Last reply Dec 24, 2020, 9:06 PM Reply Quote 1
      • M
        mercy_angel @Konstanti
        last edited by Dec 24, 2020, 9:06 PM

        @konstanti said in command for ip xfrm state:

        ipsec statusall
        or
        swanctl --list-sas
        or
        setkey -D

        Thanks a lot!

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received