match-identity

Configures match options for an Internet Key Exchange version 2 (IKEv2) profile based on local or remote identity parameters.
Syntax
match-identity local { address { ip-address | ipv6-address } | dn dn-name | email email-address | fqdn fqdn-name | key-id key-id }
match-identity remote { address { ip-address | ipv6-address } | dn dn-name | email email-address | fqdn fqdn-name | key-id key-id }
no match-identity local { address { ip-address | ipv6-address } | dn dn-name | email email-address | fqdn fqdn-name | key-id key-id }
no match-identity remote { address { ip-address | ipv6-address } | dn dn-name | email email-address | fqdn fqdn-name | key-id key-id }
Command Default

A match identity is not configured.

Parameters
local
Specifies matching based on local identity.
address ip-address
Specifies matching based on a specific IPv4 address.
address ipv6-address
Specifies matching based on a specific IPv6 address.
dn fqdn-name
Specifies matching based on a specific Distinguished Name (DN).
email email-address
Specifies matching based on a specific email address.
fqdn fqdn-name
Specifies matching based on a specific fully qualified domain name (FQDN).
key-id key-id
Specifies matching based on a specific key ID.
remote
Specifies matching based on remote identity.
Modes

IKEv2 profile configuration mode

Usage Guidelines

An IKEv2 profile must contain an identity to match. When a match identity is not configured, the profile is considered incomplete and is not used. An IKEv2 profile can have more than one match identity. When multiple match statements of the same type are configured, a match occurs when any statement is matched.

The no form of the command removes the specified match identity configuration.

Examples

The following example shows how to configure two match identities for an IKEv2 profile named prof-mktg, which is matched when the local IP address is 10.3.3.3. or the remote IP address is 10.2.2.1.

device# configure terminal
device(config)# ikev2 profile prof-mktg            
device(config-ike-profile-prof-mktg)# match-identity local address 10.3.3.3
device(config-ike-profile-prof-mktg)# match-identity remote address 10.2.2.1
device(config-ike-profile-prof-mktg)# exit
History
Release version Command history
08.0.50 This command was introduced.
08.0.70 Support was added for IPv6.