IKEv1 phase-2 SAs increasing

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IKEv1 phase-2 SAs increasing

L4 Transporter

Hello,

 

We are trying to clear and initiate IPsec connection using the following commands: 

clear vpn ike-sa gateway <value>
clear vpn ipsec-sa tunnel <value>
test vpn ike-sa gateway <value>
test vpn ipsec-sa tunnel <value>
 
However, the SA’s are not clearing , instead they are increasing. Any idea how to stop and clear them?
 
IKEv1 phase-2 SAs
Gateway Name TnID Tunnel GwID/IP Role Algorithm SPI(in) SPI(out) MsgID ST Xt
------------ ---- ------ ------- ---- --------- ------- -------- ----- -- --
ABC-IKE-GW 7 ABC-IKE-Tunnel:defg 1 Resp ESP/ DH2/tunl/SHA1 90091F68 6BD89E28 45C201A1 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Resp ESP/ DH2/tunl/SHA1 C5E7E2AA AAF9A197 6E9BB2BE 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Resp ESP/ DH2/tunl/SHA1 9EB26F76 AAF9A196 FE30C916 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Resp ESP/ DH2/tunl/SHA1 97F9ED21 AAF9A195 AA1E59F7 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Resp ESP/ DH2/tunl/SHA1 C7341C5C AAF9A194 5CDD1EBF 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Resp ESP/ DH2/tunl/SHA1 F369023B AAF9A192 E28DE38F 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Resp ESP/ DH2/tunl/SHA1 944E760D AAF9A191 7EF5B110 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Resp ESP/ DH2/tunl/SHA1 D241FB26 AAF9A190 31B577D9 9 1
ABC-North-East-IKE- 10 ABC-North-East-Tunn 2 Init ESP/ DH2/tunl/SHA1 BA253926 AAF9A18C 47391E4D 9 1
ABC-South-West-IKE-GW 13 ABC-South-West-Tunnel: 3 Resp ESP/ DH2/tunl/SHA1 ADA46287 37BD9032 307A1FF2 9 1
ABC-test-IKE-GW 16 ABC-test-Tunnel:test 4 Resp ESP/ DH2/tunl/SHA1 DD3B05E9 5FE62DF6 769AACB6 9 1
1 accepted solution

Accepted Solutions

L7 Applicator

Could it be that there constantly is traffic? So when you clear it the new SA's are already created when you enter the "show" command...

View solution in original post

1 REPLY 1

L7 Applicator

Could it be that there constantly is traffic? So when you clear it the new SA's are already created when you enter the "show" command...

  • 1 accepted solution
  • 1704 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!