Install guide
Software Version 2.9.1 91
Software Version 2.9.1
C613-10486-00 REV C
show ipsec policy counter
Syntax SHow IPSec POLIcy[=name] COUnter
Description This command displays the counters for IPsec policies. The output of this
command includes two new fields (Figure 19, Table 14).
Figure 19: Example output from the show ipsec policy counter command
Setup/Remove Counters:
setupStarted 1 setupSaSetupFailImm 0
setupSaSetupStarted 1 setupSaSetupFailed 0
setupDone 1 setupFailed 0
removeStarted 0 removeSaSetupStarted 0
removeDone 0
Outbound Packet Processing Counters:
outDeny 0 outPermit 0
outNoBundle 1 outNoBundleFail 0
outMakeSetupStrctFail 0 outSetupBundleFail 0
outBundleSoftExpire 0 outBundleExpire 0
outProcessStart 4373 outProcessFailImm 0
outBundleStateBad 0 outProcessFail 0
outProcessDone 4373 outBundleNotFound 0
outNoBundleSqos 0
.
.
.
Table 14: New parameters in the output of the show ipsec policy counter command
Parameter Meaning
outNoBundleSqos Number of outbound packets discarded because the bundle
was not found after SQoS processed the packet, and IPsec
was unable to process the packet using another bundle.
This can indicate that IPsec has removed a bundle suddenly,
such as when the bundle reaches its expirykbytes limit.
outBundleNotFound Number of outbound packets where the bundle was not
found after SQoS processed the packet. This can indicate
that IPsec has removed a bundle suddenly, such as when the
bundle reaches its expirykbytes limit.