show ikev2 profile

Displays configuration information about Internet Key Exchange version 2 (IKEv2) profiles.
Syntax
show ikev2 profile [ profile-name ]
Parameters
profile-name
Specifies the name of an IKEv2 profile.
Modes

User EXEC mode

Usage Guidelines

This command may be entered in all configuration modes.

When a profile is not specified, this command displays information about all IKEv2 profiles.

The show ikev2 profile command displays the following information:

Output field Description
IKEv2 Profile The IKEv2 profile name.
Auth Profile The authentication profile for this IKEv2 profile.
Match Criteria
Inside VRF The VRF name.
Local The local system ID that is compared with the received payload during negotiation. Permitted ID formats are:
  • address—An IPv4 address
  • fqdn—A fully qualified domain name, for example, router1.example.com
  • email—An email address, for example, test@test.com
  • key-id—A key ID
Remote Remote system ID that is compared with the received payload during negotiation. Permitted ID formats are:
  • address—An IPv4 address
  • fqdn—A fully qualified domain name, for example, router1.example.com
  • email—An email address, for example, test@test.com
  • key-id—A key ID
Local Identifier

Local system ID that is sent with the payload during negotiation. Permitted ID formats are:

  • address—An IPv4 address.
  • fqdn—A fully qualified domain name, for example, router1.example.com.
  • email—An email address, for example, test@test.com.
  • key-id—A key ID.

Remote Identifier

Remote system ID. Permitted ID formats are:

  • address—An IPv4 address.
  • fqdn—A fully qualified domain name, for example, router1.example.com.
  • email—An email address, for example, test@test.com.
  • key-id—A key ID.

Lifetime The IKEv2 SA lifetime (in minutes). This is also known as the rekey time.
Keepalive Check The interval, in seconds, between the IKEv2 messages sent to detect a dead peer.
Initial contact The initial contact configuration status. When a device reboots, peer devices may have security associations (SAs) that are no longer valid. When initial contact is enabled, an initial contact message is sent to ensure that old security associations (SAs) on the peer are deleted.
Ref Count Number of IPsec profiles that refer to this IKEv2 profile.
Examples

The following example displays configuration information for an IKEv2 profile named prof_mktg.

device# show ikev2 profile ipsec_tunnel_1

IKEv2 Profile       : ipsec_tunnel_1
Auth Profile        : ipsec_tunnel_1
Match Criteria      :
Inside VRF         : vrf1
  Local: 
   email ipsec_tunnel_1@example.com
  Remote: 
   email ipsec_tunnel_1@example.com
Local Identifier    : email ipsec_tunnel_1@example.com
Remote Identifier   : email ipsec_tunnel_1@example.com
Lifetime            : 2592000 sec
Keepalive Check     : 10 sec
Initial contact     : yes 
Ref Count           : 1
History
Release version Command history
08.0.50 This command was introduced.