Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


show security group-vpn member ipsec inactive-tunnels



Show inactive Group VPNs. Group VPNv2 is supported on SRX300, SRX320, SRX340, SRX345, SRX550HM, SRX1500, SRX4100, SRX4200, and SRX4600 Series Firewalls and vSRX Virtual Firewall instances.



Display information for all groups.


(Optional) Display summary output.


(Optional) Display detailed output.

group-id group-id

(Optional) Display information for the specified group identifier.

Required Privilege Level


Output Fields

Table 1 lists the output fields for the show security group-vpn member ipsec inactive-tunnels command. Output fields are listed in the approximate order in which they appear.

Table 1: show security group-vpn member ipsec inactive-tunnels Output Fields

Field Name

Field Description


Server on which group member is registered.


UDP port number.


Group identifier.


Logical system.


Reason that the tunnel is inactive:

  • The tunnel was cleared through the CLI.

  • The hard lifetime has expired.

  • There are too many TEKs.

  • There was a configuration change.

  • There was an SA installation error.

  • The TEK is stale.

  • The tunnel was deleted from the server.


Logical system name.

Group VPN Name

Name of the Group VPN.

Local Gateway

IP address of the local IKE gateway.

GDOI Server

IP address of the group server.

Group Id

Group identifier.

Recovery Probe

Status of the recovery probe, either enabled or disabled (default).


Fragmentation of IPsec traffic on the group member—clear (default), copy, or set.


Statistics for GDOI groupkey-pull and groupkey-push exchanges, server failovers, deletes received, number of times the maximum number of keys and policies were exceeded, and the number of unsupported algorithms received.

Down Reason

Reason that the tunnel is inactive:

  • The tunnel was cleared through the CLI.

  • The hard lifetime has expired.

  • There are too many TEKs.

  • There was a configuration change.

  • There was an SA installation error.

  • The TEK is stale.

  • The tunnel was deleted from the server.

  • The tunnel is not initiated.

Sample Output

show security group-vpn member ipsec inactive-tunnels

show security group-vpn member ipsec inactive-tunnels detail

Release Information

Command introduced in Junos OS Release 15.1X49-D30.