Installation Guide

Table Of Contents
IKEv2 Option Description
NOTE
Range of interval: 10 - 1440
Proposal <proposal-name> The IPsec proposal to be used with this IPsec prole. Multiple proposals can be specied.
Replay-protection (Optional) Disable anti-replay checking for a particular IPsec Prole. By default it is disabled.
NOTE
The setting of this command must match the setting of ESN-enable under the IPsec proposal.
MLX Series IKEv2 Show Commands
IKEv2 show commands include congured proposals, policy, prole, security associations, sessions, certicates, counters, security
associations, statistics, proposals, and database for security policies.
IKEv2 Option Description
Show ikev2 proposal [name] Show congured IKEv2 proposals.
Show ikev2 policy [policy-name] Show IKEv2 policy.
Show ikev2 prole [prole-name] Show IKEv2 prole.
Show ikev2 sa [spi-index | fvrf
<vrf-name> | local <address> |
remote <address>] [detail]
Show IKEv2 security associations.
Show ikev2 {session [local-spi-
id]} [detail]
Show IKEv2 sessions.
Show ikev2 certicate Show certicates used by IKEv2.
Show ikev2 statistics Show ikev2 counters.
Show ipsec prole [prole-name] Show congured IPSEC proles.
Show ipsec proposal [proposal-
name]
Show congured IPSEC proposals.
Show ipsec sa [address
<address> | identity <id> | interface
<name> | peer address] [detail]
Show IPSEC security associations.
show ipsec statistics [tunnel
<tunnel-id>]
Show Ipsec SA statistics.
Show ipsec Policy Displays the database for the IPsec security policies.
Examples of Show Commands
show ikev2 proposal:
device# show ikev2 proposal
Name : ikev2-default-proposal
Encryption : AES-CBC-256
Integrity : sha384
PRF : sha384
DH Group : 384_ECP/Group 20
show ikev2 policy:
device# show ikev2 policy
Name : ike_policy_red
vrf : Default
MLX Series router modules
Extreme Routing MLX Series Hardware Installation Guide
52 53-1004203-04