match address-local

Configures matching an Internet Key Exchange version 2 (IKEv2) policy based on a local IPv4 or IPv6 address.
Syntax
match address-local { ip-address ip-mask | ipv6-address ipv6mask }
no match address-local { ip-address mask | ipv6-address mask }
Command Default

The IKEv2 policy matches all local IPv4 or IPv6 addresses.

Parameters
ip-address ip-mask
Specifies a local IPv4 address and mask.
ip-address ipv6-mask
Specifies a local IPv6 address and mask.
Modes

IKEv2 policy configuration mode

Usage Guidelines

The no form of the command restores the default value of the policy matching all local IPv4 or IPv6 addresses.

Examples

The following example configures an IKEv2 policy named pol-mktg to use an IKEv2 proposal named prop-mktg and match the local IPv4 address 10.3.3.3 255.255.255.0.

device# configure terminal
device(config)# ikev2 policy pol-mktg            
device(config-ike-policy-pol-mktg)# proposal prop-mktg
device(config-ike-policy-pol-mktg)# match address-local 10.3.3.3 255.255.255.0
device(config-ike-policy-pol-mktg# exit

The following example configures an IKEv2 policy named al2 to use an IKEv2 proposal and match the local IPv6 address 2001:100::1/64.

device# configure terminal
device(config)# ikev2 policy al2            
device(config-ike-policy-al2)# proposal al2
device(config-ike-policy-al2)# match address-local 2001:100::1/64
History
Release version Command history
08.0.50 This command was introduced.
08.0.70 Support was added for IPv6.