cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
722
Views
4
Helpful
1
Replies

about GETVPN

Kiran Doijode
Level 1
Level 1

Hi everyone,

How many SA's can a getvpn handle ?

1 Reply 1

Jason Gervia
Cisco Employee
Cisco Employee

Kiran,


This is platform specific.  The 'show cry eli' command should be able to tell you that information for your specific platform:

Example:

Hardware Encryption : ACTIVE
Number of hardware crypto engines = 1

CryptoEngine NETGX details: state = Active
Capability      : IPPCP, DES, 3DES, AES, IPv6, GDOI, FAILCLOSE

IPSec-Session :     0 active,  2400 max, 0 failed

Keep in mind that due to re-keying, you'll only be able to get about 1/2 your limit (because you will have both the old IPSEC SA and the new IPSEC SA for a short period of time, until the old SA expires).

--Jason