ikev2 policy
Global configuration mode
There is a default IKEv2 policy (def-ike-policy) that is used to protect IKEv2 SA negotiations. The default policy does not require configuration and has the following settings:
- proposal: def-ike-prop
- local_address: Not set; matches all local addresses
- vrf: Not set; matches the default-VRF
Use the
ikev2 policy command to configure any additional IKEv2 policies that you need.
The
no form of the command removes any IKEv2 policy configuration other than the default
IKEv2 policy.
The default IKEv2 policy cannot be removed.
Only one IKEv2 policy can be selected for a local endpoint (single IPv4 address). Configuring multiple IKEv2 policies for the same IP address is invalid.
When multiple matching policies are identified during IKEv2 negotiations, the most recently created matching policy is used.
| Release version | Command history |
|---|---|
| 08.0.50 | This command was introduced. |