show ikev2 sa

Displays configuration information about current Internet Key Exchange version 2 (IKEv2) security associations (SAs).
Syntax
show ikev2 sa [ detail ]
show ikev2 sa fvrf vrf-name
show ikev2 sa interface tunnel-port [ detail ]
show ikev2 sa ipv4
show ikev2 sa ipv6
show ikev2 sa local { ip-address | ipv6-address } [ detail ]
show ikev2 sa remote { ip-address | ipv6-address } [ detail ]
Parameters
detail
Specifies the display of detailed information.
fvrf vrf-name
Specifies the name of a forwarding VRF.
interface tunnel-port
Specifies a tunnel port number.
ipv4
Specifies IPv4 connections.
ipv6
Specifies IPv6 connections.
local ip-address
Specifies a local interface.
ip-address
Specifies an IPv4 address.
ipv6-address
Specifies an IPv6 address.
remote
Specifies a remote interface.
Modes

User EXEC mode

Usage Guidelines

This command may be entered in all configuration modes.

When the detail option is omitted, only the basic SA information is displayed.

The show ikev2 sa command displays the following information:

Output field Description
Total SA The total number of IKEv2 SAs, that is; SAs that are in active, constructing, and dying states.
Active SA The number of IKEv2 SAs in an active state.
Constructing SA The number of IKEv2 SAs in a constructing state.
Dying SA The number of IKEv2 SAs in an dying state.
tnl-id The tunnel interface ID for the IKEv2 SA.
local The local address of the tunnel.
remote The remote address of the tunnel.
status The IKEv2 SA state.
vrf(i) The base or internal VRF for the IKEv2 tunnel.
vrf(f) The front-end (customer end) VRF for the IKEv2 tunnel.
Role The role of the device (initiator, responder).
Local SPI The local security parameter index (SPI) for the IKEv2 SA.
Remote SPI The remote SPI for the IKEv2 SA.
Profile The IKEv2 profile for the session.
Policy The IKEv2 policy for the session.
Auth Proposal The IKEv2 authentication proposal for the session.
Examples

The following example displays information about the current SA configuration, in which there are four active SAs.

device# show ikev2 sa

Total SA : 4
Active SA: 4    : Constructing SA:0     : Dying SA:0
---------------------------------------------------------------------------
tnl-id   local           remote          status   vrf(i)        vrf(f)
---------------------------------------------------------------------------
tnl 18   10.18.3.4/500   10.18.3.5/500   active   default-vrf   default-vrf
tnl 22   10.22.3.4/500   10.22.3.5/500   active   default-vrf   default-vrf
tnl 19   10.19.3.4/500   10.19.3.5/500   active   default-vrf   default-vrf
tnl 20   10.20.3.4/500   10.20.3.5/500   active   default-vrf   default-vrf
   

The following example displays detailed IKEv2 SA information.

device# show ikev2 sa detail

Total SA : 1
Active SA: 1   : Constructing SA:0     : Dying SA:0    
--------------------------------------------------------------------------------
tnl-id  Local           Remote          Status       Vrf(i)      Vrf(f)
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
tnl 1  10.1.41.1      10.4.41.1         Active       vrf1        vrf2       
--------------------------------------------------------------------------------
Role                : Initiator
Local SPI           : 0x6fb19219160c7d71     Remote SPI: 0xde1b24e5764f311e
Profile             : p1 
Policy              : ipsec_tunnel_1
Auth Proposal       : p1
      

The following example displays IKEv2 SA information, including information about IPv6 connections.

device# show ikev2 sa
Total SA : 7
Active SA: 7    : Constructing SA:0     : Dying SA:0    
-----------------------------------------------------------------------------------------------------------------------
tnl-id  Local            Remote            Status       Vrf(i)      Vrf(f)
-----------------------------------------------------------------------------------------------------------------------
tnl 8   2220::1          5002::2           Active       default-vrf default-vrf
tnl 7   1110::1          5002::2           Active       default-vrf default-vrf
tnl 1   1000::1          1004::2           Active       default-vrf default-vrf
tnl 4   120.1.1.1        110.1.1.1         Active       default-vrf default-vrf
tnl 11  1000::1          1003::2           Active       default-vrf default-vrf
tnl 9   3330::1          5002::2           Active       default-vrf default-vrf
tnl 3   100.1.1.1        104.1.1.2         Active       default-vrf default-vrf
      
History
Release version Command history
08.0.50 This command was introduced.
08.0.70 Support was added for IPv6.