Command map

show vpn ipsec dataplane sa

Show the Security Association Database the kernel holds.

Ze command

Registry path
show vpn ipsec dataplane sa
Usage
show vpn ipsec dataplane sa [spi <spi>]
Mode
Read-only
Wire method
ze-show:vpn-ipsec-dataplane-sa
Backends
any backend
Task support
optional: the MCP call is synchronous, which is the default
Subcommands
none: this command takes no subcommand
Pipes, always
json, ndjson, table, text, yaml, raw, no-more, save
Pipes, when the answer has rows
match, count, first, last, display, fill
Pipes, while streaming
log
Pipes, local process only
save

Description

Lists each installed ESP SA with its SPI,
addresses, mode, algorithms, replay window, byte and packet counters, and
timestamps. Give 'spi <spi>' to show all matching SAs. Without a selector the command
dumps every SA, which on a device with many tunnels is one row per SA.

Arguments

NameTypeRequiredValuesSummaryDescription
spiuintnoany value of this typeShow all SAs with this SPI.The value is decimal. Ze keeps only the SAs whose SPI equals it, and the inbound SA and the outbound SA of one tunnel carry different SPIs, so one value names one direction. The value 0 is refused.

Mapping status

No vendor equivalent has been curated yet for this Ze command.

Juniper Junos MX

No equivalent is listed for this vendor yet.

Cisco IOS XR

No equivalent is listed for this vendor yet.

Nokia SR OS

No equivalent is listed for this vendor yet.

VyOS

No equivalent is listed for this vendor yet.