PDA

View Full Version : H3 3.4 LAN to LAN IPSec - Active SAs:4 or 2 ?



sm_ccie
03-03-2020, 10:17 PM
Guys anybody can confirm if the Active SAs: 4 output in WB is correct ? I can't get 4.

My labs show Active SAs:2

sh cry sess
Crypto session current status

Interface: Ethernet0/0
Session status: UP-ACTIVE
Peer: 201.99.70.2 port 4500
Session ID: 0
IKEv1 SA: local 201.99.24.2/4500 remote 201.99.70.2/4500 Active
IPSEC FLOW: permit ip 10.0.0.0/255.0.0.0 10.7.0.0/255.255.255.0
Active SAs: 2, origin: dynamic crypto map