Not sure what kind of device's output this is. But to see the phase2 SA status, you can do either:
get vpn ipsec tunnel name [phase1_name]
or
diag vpn tunnel list name [phase1_name]
Both basically have the same info like network selectors, status, other key parameters after negotiation, etc., like below:
fg40f-utm (root) # get vpn ipsec tun name SFOviaCentu
gateway
name: 'DEMO-VPN'
local-gateway: x.x.x.x:0 (static)
remote-gateway: y.y.y.y:0 (static)
status: up
mode: ike-v2
interface: 'ppp3' (50) vrf:0
rx packets: 82 bytes: 9115 errors: 0
tx packets: 156 bytes: 20914 errors: 0
dpd: on-idle/negotiated status:ok idle: 30000ms retry: 3 count: 0
selectors
name: 'DEMO-VPN1'
auto-negotiate: disable
mode: tunnel
src: 0:0.0.0.0/0.0.0.0:0
dst: 0:0.0.0.0/0.0.0.0:0
SA
lifetime/rekey: 43200/38306
mtu: 1422
tx-esp-seq: 9d
replay: enabled
qat: 0
inbound
spi: 1970346c
enc: aes-cb 4f2b84d0b26a641b919430d101a1980ff9571d6affe6179c8d066cd1ec6d9a13
auth: sha256 6e4abef734db713a5ff15bd26b58b28623468c2af2ff7bd8bde952f100b8359c
outbound
spi: 089313d0
enc: aes-cb fd1d6006bdf368ce5ceed56e815ced17637ef97b1cd39efce7b3abe9128d35ac
auth: sha256 234c68a2efc64a180c41b5db104616defd71bab21fbc6f6ec3e95e768a1fc379
NPU acceleration: none
But if a specific phase2(network-selector pair) is not up, it would show without SA info like below because SA is not established:
....
selectors
name: 'DEMO-PH2-4'
auto-negotiate: disable
mode: tunnel
src: 0:172.17.0.0/255.255.0.0:0
dst: 0:10.10.10.10:0
selectors (<--SA info starts here instead if tunnel is up)
....
Toshi
| User | Count |
|---|---|
| 2806 | |
| 1425 | |
| 812 | |
| 757 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.