The 'vpn tu' command provides an interactive menu to view and manage IPsec SAs, including Phase 1 and Phase 2 SAs. It allows administrators to see encryption domains, peer addresses, and SA lifetimes, making it the appropriate tool to verify that traffic is being encrypted and decrypted correctly.
Why this answer
The 'vpn tu' command is specifically designed for VPN troubleshooting on Check Point gateways. It provides a menu to list IPsec SAs, including encryption and authentication algorithms, and can also be used to reset SAs. It is the most direct way to verify that traffic is being encrypted and decrypted correctly.