show ikev2 session

Displays Internet Key Exchange version 2 (IKEv2) session information that includes rekeys and other negotiated information.
Syntax
show ikev2 session [ local-spi-id | detail ]
Parameters
local-spi-id
Specifies the security parameter index (SPI) for the IKEv2 session.
detail
Specifies the display of detailed information about IKEv2 sessions.
Modes

User EXEC mode

Usage Guidelines

This command may be entered in all configuration modes.

The show ikev2 session command displays the following information:

Output field Description
IKE count The total number of IKEv2 security associations (SAs).
Child Sa Count The total number of IPsec security associations (SAs).
tnl-id The tunnel interface ID for the IKEv2 SA.
local The local address of the tunnel.
remote The remote address of the tunnel.
status The IKEv2 SA state.
vrf(i) The base or internal VRF for the IKEv2 tunnel.
vrf(f) The front-end (customer end) VRF for the IKEv2 tunnel.
Encr The encryption algorithm used by this session after IKEv2 negotiations.
Hash The hashing algorithm used by this session after IKEv2 negotiations.
DH Grp The Diffie-Hellman (DH) group used by this session after IKEv2 negotiations.
Auth The authentication method used by this session after IKEv2 negotiations.
PRF The pseudorandom function (PRF) used by this session after IKEv2 negotiations.
Local spi The local security parameter index (SPI) for the session.
Remote spi The remote SPI for the session.
Life/Active Time The configured IKEv2 rekey time and the time left until the next rekey.
Rekey count Local The total number of session key changes for the IKEv2 SA that were initiated by the local device.
Rekey count Remote The total number of session key changes for the IKEv2 SA that were initiated by the remote device.
Status Description The IKEv2 SA state.
Initiator id The initiator identity for the IKEv2 SA.
Responder id The responder identity for the IKEv2 SA.
no Exchange in progress Indicates that this session is not in an exchange state.
next request message id The next message ID for the session.
Keepalive timer The interval between IKEv2 messages that are sent to detect if a peer is still alive.
Total keepalive sent The total number of "keepalive" messages sent for the session.
Total keepalive received The total number of "keepalive" messages received for the session.
Total Bytes sent The total number of bytes sent in the session.
Total Bytes Received The total number of bytes received in the session.
Time past since last msg The elapsed time since the last message.
NAT-T Network Address Translation (NAT) configuration status.
Child Sa IPsec SA details.
id The numeric identifier for an IPsec SA.
Local selector The local traffic selector.
Remote selector The remote traffic selector.
ESP SPI IN/OUT The IPsec SPI for ingress and the SPI for egress.
Encryption The encryption algorithm used by the session.
ICV Size The size of the integrity check value (ICV) for the encryption algorithm.
Esp_hmac The hashed message authentication code (HMAC) algorithm used by the session.
Authentication The authentication algorithm used by the session.
DH Group The Diffie-Hellman (DH) group used by the authentication algorithm.
Mode The Encapsulating Security Protocol (ESP) mode for the session.
Rekey count Local The total number of changes to the IPsec SA session key initiated by the local device.
Rekey count Remote The total number of changes to the IPsec SA session key initiated by the remote device.
Examples

The following example displays IKEv2 session information.

device# show ikev2 session

IKE count:1, Child Sa Count:2
tnl-id     local        remote       status     vrf(i)        vrf(f)
------------------------------------------------------------------------------
tnl 18     10.18.3.4    10.18.3.5    active     default-vrf   default-vrf
------------------------------------------------------------------------------
    Encr: aes-cbc-256, Hash: sha384, DH Grp:384_ECP/Group 20, Auth: pre_shared
    PRF: sha384
    Is Initiator: Yes
    Local spi  : 0xe115847e85ad667b       Remote spi: 0x7bb5ee3b6074a4b4
    Life/Active Time: 2592000/534 sec
    Rekey count Local: 0       Rekey count Remote: 2
Child Sa:
 id 1
       Local selector  0.0.0.0/0 - 255.255.255.255
       Remote selector 0.0.0.0/0 - 255.255.255.255
       ESP SPI IN/OUT: 0xb278/0x7935
       Encryption: aes-gcm-256, ICV Size: 16 octects, Esp_hmac: Null
       Authetication: null  DH Group:none , Mode: tunnel
       Rekey count Local: 0       Rekey count Remote: 2

The following example displays detailed IKEv2 session information.

device# show ikev2 session detail

IKE count:4, Child Sa Count:8
tnl-id     local        remote       status     vrf(i)        vrf(f)
------------------------------------------------------------------------------
tnl 18     10.18.3.4    10.18.3.5    active     default-vrf   default-vrf
------------------------------------------------------------------------------
    Encr: aes-cbc-256, Hash: sha384, DH Grp:384_ECP/Group 20, Auth: pre_shared
    PRF: sha384
    Local spi  : 0xe115847e85ad667b       Remote spi: 0x7bb5ee3b6074a4b4
    Life/Active Time: 2592000/614 sec
    Rekey count Local: 0       Rekey count Remote: 2
    Status Description: active
    Initiator id: address 18.3.3.4    Responder id: address 18.3.3.5
    no Exchange in progress
    next request message id=4
    Keepalive timer: 300 seconds, retry 0
        Total keepalive sent: 2
        Total keepalive received: 0
        Total Bytes sent    : 524   Total Bytes Received   : 672
    Time past since last msg: 14
    NAT-T is not detected
Child Sa:
 id 1
       Local selector  0.0.0.0/0 - 255.255.255.255
       Remote selector 0.0.0.0/0 - 255.255.255.255
       ESP SPI IN/OUT: 0xb278/0x7935
       Encryption: aes-gcm-256, ICV Size: 16 octects, Esp_hmac: Null
       Authetication: null  DH Group:none , Mode: tunnel
       Rekey count Local: 0       Rekey count Remote: 2
History
Release version Command history
08.0.50 This command was introduced.