ikev2 policy

Creates an Internet Key Exchange version 2 (IKEv2) policy and enters IKEv2 policy configuration mode.
Syntax
ikev2 policy name
no ikev2 policy name
Command Default

The default IKEv2 policy is def-ike-policy.

Parameters
name
Specifies the name of an IKEv2 policy.
Modes

Global configuration mode

Usage Guidelines

There is a default IKEv2 policy (def-ike-policy) that is used to protect IKEv2 SA negotiations. The default policy does not require configuration and has the following settings:

  • proposal: def-ike-prop
  • local_address: Not set; matches all local addresses
  • vrf: Not set; matches the default-VRF

Use the ikev2 policy command to configure any additional IKEv2 policies that you need.

The no form of the command removes any IKEv2 policy configuration other than the default IKEv2 policy.

The default IKEv2 policy cannot be removed.

Only one IKEv2 policy can be selected for a local endpoint (single IPv4 address). Configuring multiple IKEv2 policies for the same IP address is invalid.

When multiple matching policies are identified during IKEv2 negotiations, the most recently created matching policy is used.

Examples

The following example creates an IKEv2 policy named test_policy1.

device# configure terminal
device(config)# ikev2 policy test_policy1
device(config-ike-policy-test_policy1)#
History
Release version Command history
08.0.50 This command was introduced.