[strongSwan] How to verify the actual IKE proposal

Dion Kant dion at concero.nl
Fri Mar 7 11:52:32 CET 2014

Hello all,

On a running tunnel (IKEV1), I can easily verify the ESP proposal by
using ipsec statusall lable-xxx

ipsec statusall lable-xxx

000 "lable-xxx":   newest ISAKMP SA: #0; newest IPsec SA: #173651;
000 "lable-xxx":   ESP proposal: AES_CBC_256/HMAC_SHA1/MODP_1536

Is there also a means to verify the selected IKE cipher stuff ?

Regards, Dion

More information about the Users mailing list