Ipsec identifying active-peers

Dear All,


I would like to ask how to identify the active-peers? While in the ipsec sa has spi in the console and the webfig as weel, the isakmp has not. While the log has isakmp sa established with spi identifiers, unfortunately I cannot close one based on that log.
My problem that I have more established isakmp sa without and with active phase2 and I can not find the maching ipsec sa-s. Is there any way to explore which ike sa owns which ipsec sa-s?


thank you