show ikev2 sa
show ikev2 sa
[
detail
]
show ikev2 sa
fvrf
vrf-name
show ikev2 sa
interface
tunnel-port
[
detail
]
show ikev2 sa
ipv4
show ikev2 sa
ipv6
show ikev2 sa
local
{
ip-address
|
ipv6-address
}
[
detail
]
show ikev2 sa
remote
{
ip-address
|
ipv6-address
}
[
detail
]
User EXEC mode
This command may be entered in all configuration modes.
When the
detail option is omitted, only the basic SA information is displayed.
The
show ikev2 sa command displays the following information:
| Output field | Description |
|---|---|
| Total SA | The total number of IKEv2 SAs, that is; SAs that are in active, constructing, and dying states. |
| Active SA | The number of IKEv2 SAs in an active state. |
| Constructing SA | The number of IKEv2 SAs in a constructing state. |
| Dying SA | The number of IKEv2 SAs in an dying state. |
| tnl-id | The tunnel interface ID for the IKEv2 SA. |
| local | The local address of the tunnel. |
| remote | The remote address of the tunnel. |
| status | The IKEv2 SA state. |
| vrf(i) | The base or internal VRF for the IKEv2 tunnel. |
| vrf(f) | The front-end (customer end) VRF for the IKEv2 tunnel. |
| Role | The role of the device (initiator, responder). |
| Local SPI | The local security parameter index (SPI) for the IKEv2 SA. |
| Remote SPI | The remote SPI for the IKEv2 SA. |
| Profile | The IKEv2 profile for the session. |
| Policy | The IKEv2 policy for the session. |
| Auth Proposal | The IKEv2 authentication proposal for the session. |
The following example displays information about the current SA configuration, in which there are four active SAs.
device# show ikev2 sa Total SA : 4 Active SA: 4 : Constructing SA:0 : Dying SA:0 --------------------------------------------------------------------------- tnl-id local remote status vrf(i) vrf(f) --------------------------------------------------------------------------- tnl 18 10.18.3.4/500 10.18.3.5/500 active default-vrf default-vrf tnl 22 10.22.3.4/500 10.22.3.5/500 active default-vrf default-vrf tnl 19 10.19.3.4/500 10.19.3.5/500 active default-vrf default-vrf tnl 20 10.20.3.4/500 10.20.3.5/500 active default-vrf default-vrf
The following example displays detailed IKEv2 SA information.
device# show ikev2 sa detail
Total SA : 1
Active SA: 1 : Constructing SA:0 : Dying SA:0
--------------------------------------------------------------------------------
tnl-id Local Remote Status Vrf(i) Vrf(f)
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
tnl 1 10.1.41.1 10.4.41.1 Active vrf1 vrf2
--------------------------------------------------------------------------------
Role : Initiator
Local SPI : 0x6fb19219160c7d71 Remote SPI: 0xde1b24e5764f311e
Profile : p1
Policy : ipsec_tunnel_1
Auth Proposal : p1
The following example displays IKEv2 SA information, including information about IPv6 connections.
device# show ikev2 sa
Total SA : 7
Active SA: 7 : Constructing SA:0 : Dying SA:0
-----------------------------------------------------------------------------------------------------------------------
tnl-id Local Remote Status Vrf(i) Vrf(f)
-----------------------------------------------------------------------------------------------------------------------
tnl 8 2220::1 5002::2 Active default-vrf default-vrf
tnl 7 1110::1 5002::2 Active default-vrf default-vrf
tnl 1 1000::1 1004::2 Active default-vrf default-vrf
tnl 4 120.1.1.1 110.1.1.1 Active default-vrf default-vrf
tnl 11 1000::1 1003::2 Active default-vrf default-vrf
tnl 9 3330::1 5002::2 Active default-vrf default-vrf
tnl 3 100.1.1.1 104.1.1.2 Active default-vrf default-vrf
| Release version | Command history |
|---|---|
| 08.0.50 | This command was introduced. |
| 08.0.70 | Support was added for IPv6. |