You can run the display ipsec sa command to check whether the SA configurations for outgoing protocol packets on the local end are identical with those for incoming protocol packets on the peer end. The display ipsec sa command output displays the following information:
- SA name
- Security proposal applied to the SA
- Number of times the SA is applied
- SA configurations for incoming Authentication Header (AH)
- SA configurations for outgoing AH
- SA configurations for incoming Encapsulating Security Payload (ESP)
- SA configurations for outgoing ESP