Hi Marco, > Kindly I would like to ask if there is any know reason > why ipsec statusall sometimes doesn't print the number > of packets for the child_sa.
The number of packets is printed if a last use time can be determined via the respective policy. Check the log for errors regarding querying the inbound policy (you could increase the log level for knl to see a bit more about the interaction with the kernel). Regards, Tobias
