Palo Alto: aktive VPN Tunnel zeigen

user@PAC1(active)> show vpn flow

total tunnels configured:                                     18
filter - type IPSec, state any

total IPSec tunnel configured:                                18
total IPSec tunnel shown:                                     18

id    name                          state   monitor local-ip                      peer-ip                       tunnel-i/f
--    ----                          -----   ------- --------                      -------                       ----------
21    T029_TDM_AL:PXYID1            active  off     185.9.110.39                  0.0.0.0                       tunnel.29
22    T244_LTE1:PXYID1              active  up      185.9.110.39                  0.0.0.0                       tunnel.244
23    T004_PH_AR:PXYID1             active  up      185.9.110.39                  193.158.105.154               tunnel.4
24    T005_PH_KA:PXYID1             init    down    185.9.110.39                  62.156.183.234                tunnel.5
25    T214_PH_EB:PXYID1             init    down    185.9.110.39                  62.225.35.114                 tunnel.214
26    T206_PH_GR:PXYID1             init    down    185.9.110.39                  62.156.183.226                tunnel.206
27    T151_PH_HE:PXYID1             init    down    185.9.110.39                  62.153.210.18                 tunnel.151
28    T003_PH_IL:PXYID1             init    down    185.9.110.39                  195.243.128.170               tunnel.3

 

user@PAC1(active)> show vpn flow tunnel-id 23

tunnel  T004_PH_AR:PXYID1
 id:                     23
 type:                   IPSec
 gateway id:             14
 local ip:               185.9.110.39
 peer ip:                193.158.105.154
 inner interface:        tunnel.4
 outer interface:        ae1.306
 state:                  active
 session:                232563
 tunnel mtu:             1424
 lifetime remain:        506 sec
 lifesize remain:        N/A
 latest rekey:           3094 seconds ago
 monitor:                on
 monitor status:       up
 monitor dest:         10.200.4.100
 monitor interval:     3 seconds
 monitor threshold:    5 probe losses
 monitor packets sent: 21234
 monitor packets recv: 21224
 monitor packets seen: 0
 monitor packets reply:0
 en/decap context:       87
 local spi:              CAC3C692
 remote spi:             89E5F86C
 key type:               auto key
 protocol:               ESP
 auth algorithm:         SHA256
 enc  algorithm:         AES256
 anti replay check:      no
 copy tos:               no
 authentication errors:  0
 decryption errors:      0
 inner packet warnings:  0
 replay packets:         0
 packets received
 when lifetime expired:0
 when lifesize expired:0
 sending sequence:       346156
 receive sequence:       0
 encap packets:          4521411
 decap packets:          3972431
 encap bytes:            3095806584
 decap bytes:            1634034696
 key acquire requests:   21
 owner state:            0
 owner cpuid:            s1dp0
 ownership:              1