show ikev2 statistics
Displays statistical information about Internet Key Exchange version 2 (IKEv2).
Modes
User EXEC mode
Usage Guidelines
This command may be entered in all configuration modes.
The
show ikev2 statistics command displays the following information:
| Output field | Description | |
|---|---|---|
| Total IKEv2 SA Count active | The total number of IKEv2 security associations (SAs) in an active state. | |
| Incoming IKEv2 Requests | The number of IKEv2 SAs (accepted and rejected) initiated by the peer device. | |
| Outgoing IKEv2 Requests | The number of IKEv2 SAs initiated by the local device. | |
| Accepted | The total number of outgoing IKEv2 SAs that were accepted. | |
| Rejected | The total number of outgoing IKEv2 SAs that were rejected. | |
| Rejected due to no cookie | The total number of outgoing IKEv2 SAs that were rejected due to no cookie. | |
| IKEv2 Packet Statistics | ||
| Total Packets Received | The total number of packets received. | |
| Total Packets Transmitted | The total number of packets transmitted. | |
| Total Packets Retransmitted | The total number of packets retransmitted. | |
| Total Failed Transmission | The total number of packets where transmission failed. | |
| Total Pending Packets | The total number of packets to be transmitted. | |
| Total Buffer Failed | The total number of packets where transmission failed due to a buffer issue. | |
| Total Keepalive Received | The total number of IKEv2 keepalive messages received. | |
| Total Keepalive Transmitted | The total number of IKEv2 keepalive messages transmitted. | |
| IKEv2 Error Statistics | ||
| Unsupported Payload | The total number of IKEv2 packets received with an unsupported payload. | |
| Invalid IKE SPI | The total number of IKEv2 packets received with an invalid security parameter index (SPI). | |
| Invalid Version | The total number of IKEv2 packets received with an invalid version. | |
| Invalid Syntax | The total number of IKEv2 packets received with invalid syntax. | |
| Negotiation Timeout | The total number of IKEv2 sessions deleted due to dead peer detection (DPD) or negotiation timeouts. | |
| No Policy | The total number of IKEv2 sessions deleted or rejected due to a policy issue. | |
| No Protection Suite | The total number of IKEv2 sessions deleted or rejected due to a protection suite issue. | |
| Policy Error | The total number of IKEv2 sessions deleted or rejected due to policy error. | |
| IKE Packet Error | The total number of IKEv2 or IPsec packets received with a packet error. | |
| Discard Policy | The total number of IKEv2 or IPsec sessions deleted or rejected due to a policy error or mismatch. | |
| Proposal Mismatch | The total number of IKEv2 or IPsec packets sent or received with a proposal mismatch. | |
| Invalid Selectors | The total number of IKEv2 or IPsec packets sent or received with invalid selectors. | |
| Internal Error | The total number of IKEv2 or IPsec packets sent or received with an internal error. | |
| SA Overflow | The total number of times the maximum SA count was reached. | |
| IKE SA Overflow | The number of times the maximum IKEv2 SA count was reached. | |
| IPSEC SA Overflow | The number of times the maximum IPsec SA count was reached. | |
| Authentication Failed | The total number of IKEv2 or IPsec packets sent or received when authentication failed. | |
| Others | The total number of IKEv2 or IPsec packets sent or received with other error types. | |
| Number of HW-SPI Add write | The number of times the creation of an IPsec SPI was written to the hardware. | |
| Number of HW-SPI Delete | The number of times the deletion of an IPsec SPI was written to the hardware. | |
Examples
The following example displays IKEv2 statistics.
device# show ikev2 statistics
Total IKEv2 SA Count active: 0
Incoming IKEv2 Requests: Accepted: 0 Rejected: 0
Outgoing IKEv2 Requests: 0
Accepted: 0 Rejected: 0 Rejected due to no cookie: 0
IKEv2 Packet Statistics:
Total Packets Received : 0
Total Packets Transmitted : 2
Total Packets Retransmitted: 0
Total Failed Transmission : 0
Total Pending Packets : 0
Total Buffer Failed : 0
Total Keepalive Received : 0
Total Keepalive Transmitted: 0
IKEv2 Error Statistics:
Unsupported Payload : 0 Invalid IKE SPI : 0
Invalid Version : 0 Invalid Syntax : 0
Negotiation Timeout : 0 No Policy : 0
No Protection Suite : 0 Policy Error : 0
IKE Packet Error : 1 Discard Policy : 0
Proposal Mismatch : 0 Invalid Selectors: 0
Internal Error : 0 SA Overflow : 0
IKE SA Overflow : 0 IPSEC SA Overflow: 0
Authentication Failed : 0 Others : 0
Number of HW-SPI Add write : 0 Number of HW-SPI Delete write: 0
History
| Release version | Command history |
|---|---|
| 08.0.50 | This command was introduced. |