- ホーム
- マルチクラウドネットワーク
- Customer Edge diagnostics
- Command reference
- Network commands
- IPsec
IPsec
CEはF5リージョナルエッジへのIPsecトンネルを構築します。これらがダウンしている場合、ローカルでどれだけ正常に見えていても、サイトはグローバルネットワークから隔離されます。
ipsec-status
Section titled “ipsec-status”{"command":["ipsec-status"]}Security Associations (2 up, 0 connecting):ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io]ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: INSTALLED, TUNNEL, reqid 65542, ESP in UDP SPIs: ffff1700_i ffffce10_over.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: 10.0.1.4/32 === <public-ip>/32ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io]ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: INSTALLED, TUNNEL, reqid 65541, ESP in UDP SPIs: ffff1160_i ffff1e70_over.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: 10.0.1.4/32 === <public-ip>/32最初の行が答えです:Security Associations (2 up, 0 connecting)。connecting に表示されているものは、接続を試みているが失敗しているトンネルです。
各SAは接続先のリージョナルエッジの名前を示しています — ny8-nyc、dc12-ash はF5 POPコードです — したがって、これによってサイトがどのエッジに接続されているかも確認できます。
経過時間付きの ESTABLISHED、続いて INSTALLED, TUNNEL が表示されているのは正常なペアです:前者はIKEセッション、後者が実際にトラフィックを転送するチャイルドSAです。チャイルドSAがインストールされていない状態でIKEセッションだけが確立されているのは、注目すべき障害パターンです。
ipsec-statusall
Section titled “ipsec-statusall”同じ情報に加え、SA単位のバイト数およびパケットカウンター、リキータイマー、ネゴシエートされたアルゴリズムを表示します。
{"command":["ipsec-statusall"]}Status of IKE charon daemon (strongSwan 5.9.13, Linux 5.14.0-687.20.1.el9_8.x86_64, x86_64): uptime: 78 minutes, since Aug 03 15:12:39 2026 malloc: sbrk 3428352, mmap 0, used 2019536, free 1408816 worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 20 loaded plugins: charon aes des rc2 sha2 sha1 mgf1 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs12 pgp dnskey sshkey pem openssl pkcs8 fips-prf gmp curve25519 xcbc cmac hmac kdf gcm drbg attr kernel-pb kernel-netlink resolve socket-default stroke vici updown xauth-generic error-notify countersListening IP addresses: 10.0.2.4 10.0.3.4 100.64.255.1 10.0.1.4 169.254.100.1 169.254.10.13 169.254.254.103Connections:ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: 10.0.1.4[4500]...<public-ip>[4500] IKEv1/2, dpddelay=3sver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: local: [ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io] uses any authenticationver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: cert: "O=Volterra, OU=ves-system, CN=ike"ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: remote: [ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io] uses any authenticationver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io: child: dynamic === 0.0.0.0/0 TUNNEL, dpdaction=startver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: 10.0.1.4[4500]...<public-ip>[4500] IKEv1/2, dpddelay=3sver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: local: [ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io] uses any authenticationver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: cert: "O=Volterra, OU=ves-system, CN=ike"ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: remote: [ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io] uses any authenticationver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io: child: dynamic === 0.0.0.0/0 TUNNEL, dpdaction=startSecurity Associations (2 up, 0 connecting):ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io]ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: IKEv2 SPIs: 82b18316b81c76c1_i* 4a79a978d19b3304_r, any reauthentication in 2 hoursver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io[8]: IKE proposal: AES_GCM_16_128/PRF_HMAC_SHA2_256/MODP_3072ver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: INSTALLED, TUNNEL, reqid 65542, ESP in UDP SPIs: ffff1700_i ffffce10_over.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: AES_GCM_16_128, 0 bytes_i, 0 bytes_o, rekeying disabledver.ny8-nyc.ves-io.<uuid>.tenant.int.ves.io{9}: 10.0.1.4/32 === <public-ip>/32ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: ESTABLISHED 70 minutes ago, 10.0.1.4[ver.mcn-ce-ha-eastus01.<tenant>.<uuid>.tenant.int.ves.io]...<public-ip>[ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io]ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: IKEv2 SPIs: 7ec7d8a8178881fb_i* e683f63a81425ff5_r, any reauthentication in 2 hoursver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io[7]: IKE proposal: AES_GCM_16_128/PRF_HMAC_SHA2_256/MODP_3072ver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: INSTALLED, TUNNEL, reqid 65541, ESP in UDP SPIs: ffff1160_i ffff1e70_over.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: AES_GCM_16_128, 0 bytes_i, 0 bytes_o, rekeying disabledver.dc12-ash.ves-io.<uuid>.tenant.int.ves.io{8}: 10.0.1.4/32 === <public-ip>/32「トンネルが稼働中」と「トンネルがトラフィックを転送中」を区別するために使用します。何時間も確立されているにもかかわらずバイト数がほぼゼロのトンネルは、稼働しているが使われていない状態であり、これは通常、問題がトンネルではなくルーティングにあることを意味します。