match-identity
match-identity
local
{
address
{
ip-address
|
ipv6-address
}
|
dn
dn-name
|
email
email-address
|
fqdn
fqdn-name
|
key-id
key-id
}
match-identity
remote
{
address
{
ip-address
|
ipv6-address
}
|
dn
dn-name
|
email
email-address
|
fqdn
fqdn-name
|
key-id
key-id
}
no match-identity
local
{
address
{
ip-address
|
ipv6-address
}
|
dn
dn-name
|
email
email-address
|
fqdn
fqdn-name
|
key-id
key-id
}
no match-identity
remote
{
address
{
ip-address
|
ipv6-address
}
|
dn
dn-name
|
email
email-address
|
fqdn
fqdn-name
|
key-id
key-id
}
A match identity is not configured.
IKEv2 profile configuration mode
An IKEv2 profile must contain an identity to match. When a match identity is not configured, the profile is considered incomplete and is not used. An IKEv2 profile can have more than one match identity. When multiple match statements of the same type are configured, a match occurs when any statement is matched.
The
no form of the command removes the specified match identity configuration.
The following example shows how to configure two match identities for an IKEv2 profile named prof-mktg, which is matched when the local IP address is 10.3.3.3. or the remote IP address is 10.2.2.1.
device# configure terminal device(config)# ikev2 profile prof-mktg device(config-ike-profile-prof-mktg)# match-identity local address 10.3.3.3 device(config-ike-profile-prof-mktg)# match-identity remote address 10.2.2.1 device(config-ike-profile-prof-mktg)# exit
| Release version | Command history |
|---|---|
| 08.0.50 | This command was introduced. |
| 08.0.70 | Support was added for IPv6. |