Quick Question About IPsec SA Details
-
I'm wondering if it's possible to find more detailed information about IPsec SAs.
I am troubleshooting an issue with a Cisco ASA on the other side, where the suspicion is the SAs are getting out of sync.
The ASAs are able to provide the following information for each IPsec tunnel:
Rekey Int (T): 28800 Seconds Rekey Left(T): 4682 Seconds
I'm wondering if there is a way to pull the similar information on the pfSense side.
Thanks!
-
Any info possible to see for that is shown in
setkey -D
or
setkey -DP
-
Perfect.
Looks like "Diff" should be the inverse of "Rekey Left".
Thanks!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.