show ikev2 session
Displays Internet Key Exchange version 2 (IKEv2) session information that includes
rekeys and other negotiated information.
Parameters
Modes
User EXEC mode
Usage Guidelines
This command may be entered in all configuration modes.
The
show ikev2 session
command displays the following information:
| Output field | Description | |||
|---|---|---|---|---|
| IKE count | The total number of IKEv2 security associations (SAs). | |||
| Child Sa Count | The total number of IPsec security associations (SAs). | |||
| tnl-id | The tunnel interface ID for the IKEv2 SA. | |||
| local | The local address of the tunnel. | |||
| remote | The remote address of the tunnel. | |||
| status | The IKEv2 SA state. | |||
| vrf(i) | The base or internal VRF for the IKEv2 tunnel. | |||
| vrf(f) | The front-end (customer end) VRF for the IKEv2 tunnel. | |||
| Encr | The encryption algorithm used by this session after IKEv2 negotiations. | |||
| Hash | The hashing algorithm used by this session after IKEv2 negotiations. | |||
| DH Grp | The Diffie-Hellman (DH) group used by this session after IKEv2 negotiations. | |||
| Auth | The authentication method used by this session after IKEv2 negotiations. | |||
| PRF | The pseudorandom function (PRF) used by this session after IKEv2 negotiations. | |||
| Local spi | The local security parameter index (SPI) for the session. | |||
| Remote spi | The remote SPI for the session. | |||
| Life/Active Time | The configured IKEv2 rekey time and the time left until the next rekey. | |||
| Rekey count Local | The total number of session key changes for the IKEv2 SA that were initiated by the local device. | |||
| Rekey count Remote | The total number of session key changes for the IKEv2 SA that were initiated by the remote device. | |||
| Status Description | The IKEv2 SA state. | |||
| Initiator id | The initiator identity for the IKEv2 SA. | |||
| Responder id | The responder identity for the IKEv2 SA. | |||
| no Exchange in progress | Indicates that this session is not in an exchange state. | |||
| next request message id | The next message ID for the session. | |||
| Keepalive timer | The interval between IKEv2 messages that are sent to detect if a peer is still alive. | |||
| Total keepalive sent | The total number of "keepalive" messages sent for the session. | |||
| Total keepalive received | The total number of "keepalive" messages received for the session. | |||
| Total Bytes sent | The total number of bytes sent in the session. | |||
| Total Bytes Received | The total number of bytes received in the session. | |||
| Time past since last msg | The elapsed time since the last message. | |||
| NAT-T | Network Address Translation (NAT) configuration status. | |||
| Child Sa | IPsec SA details. | |||
| id | The numeric identifier for an IPsec SA. | |||
| Local selector | The local traffic selector. | |||
| Remote selector | The remote traffic selector. | |||
| ESP SPI IN/OUT | The IPsec SPI for ingress and the SPI for egress. | |||
| Encryption | The encryption algorithm used by the session. | |||
| ICV Size | The size of the integrity check value (ICV) for the encryption algorithm. | |||
| Esp_hmac | The hashed message authentication code (HMAC) algorithm used by the session. | |||
| Authentication | The authentication algorithm used by the session. | |||
| DH Group | The Diffie-Hellman (DH) group used by the authentication algorithm. | |||
| Mode | The Encapsulating Security Protocol (ESP) mode for the session. | |||
| Rekey count Local | The total number of changes to the IPsec SA session key initiated by the local device. | |||
| Rekey count Remote | The total number of changes to the IPsec SA session key initiated by the remote device. | |||
Examples
The following example displays IKEv2 session information.
device# show ikev2 session
IKE count:1, Child Sa Count:2
tnl-id local remote status vrf(i) vrf(f)
------------------------------------------------------------------------------
tnl 18 10.18.3.4 10.18.3.5 active default-vrf default-vrf
------------------------------------------------------------------------------
Encr: aes-cbc-256, Hash: sha384, DH Grp:384_ECP/Group 20, Auth: pre_shared
PRF: sha384
Is Initiator: Yes
Local spi : 0xe115847e85ad667b Remote spi: 0x7bb5ee3b6074a4b4
Life/Active Time: 2592000/534 sec
Rekey count Local: 0 Rekey count Remote: 2
Child Sa:
id 1
Local selector 0.0.0.0/0 - 255.255.255.255
Remote selector 0.0.0.0/0 - 255.255.255.255
ESP SPI IN/OUT: 0xb278/0x7935
Encryption: aes-gcm-256, ICV Size: 16 octects, Esp_hmac: Null
Authetication: null DH Group:none , Mode: tunnel
Rekey count Local: 0 Rekey count Remote: 2
The following example displays detailed IKEv2 session information.
device# show ikev2 session detail
IKE count:4, Child Sa Count:8
tnl-id local remote status vrf(i) vrf(f)
------------------------------------------------------------------------------
tnl 18 10.18.3.4 10.18.3.5 active default-vrf default-vrf
------------------------------------------------------------------------------
Encr: aes-cbc-256, Hash: sha384, DH Grp:384_ECP/Group 20, Auth: pre_shared
PRF: sha384
Local spi : 0xe115847e85ad667b Remote spi: 0x7bb5ee3b6074a4b4
Life/Active Time: 2592000/614 sec
Rekey count Local: 0 Rekey count Remote: 2
Status Description: active
Initiator id: address 18.3.3.4 Responder id: address 18.3.3.5
no Exchange in progress
next request message id=4
Keepalive timer: 300 seconds, retry 0
Total keepalive sent: 2
Total keepalive received: 0
Total Bytes sent : 524 Total Bytes Received : 672
Time past since last msg: 14
NAT-T is not detected
Child Sa:
id 1
Local selector 0.0.0.0/0 - 255.255.255.255
Remote selector 0.0.0.0/0 - 255.255.255.255
ESP SPI IN/OUT: 0xb278/0x7935
Encryption: aes-gcm-256, ICV Size: 16 octects, Esp_hmac: Null
Authetication: null DH Group:none , Mode: tunnel
Rekey count Local: 0 Rekey count Remote: 2
History
| Release version | Command history |
|---|---|
| 08.0.50 | This command was introduced. |