356
Step Command
Remarks
2.
Set the IKEv2 NAT keepalive
interval.
ikev2 nat-keepalive seconds
By default, the IKEv2 NAT
keepalive interval is 10 seconds.
Displaying and maintaining IKEv2
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display the IKEv2 proposal configuration.
display ikev2 proposal
[
name
|
default
]
Display the IKEv2 policy configuration.
display ikev2 policy
[
policy-name
|
default
]
Display the IKEv2 profile configuration.
display ikev2 profile
[
profile-name
]
Display the IKEv2 SA information.
display ikev2 sa
[
count
| [ {
local
|
remote
}
{
ipv4-address
|
ipv6
ipv6-address
} [
vpn-instance
vpn-instance-name
] ] [
verbose
[
tunnel
tunnel-id
]
] ]
Display IKEv2 statistics.
display ikev2 statistics
Delete IKEv2 SAs and the child SAs negotiated
through the IKEv2 SAs.
reset ikev2 sa
[ [ {
local
|
remote
} {
ipv4-address
|
ipv6
ipv6-address
} [
vpn-instance
vpn-instance-name
] ] |
tunnel
tunnel-id
] [
fast
]
Clear IKEv2 statistics.
reset ikev2 statistics
Troubleshooting IKEv2
IKEv2 negotiation failed because no matching IKEv2
proposals were found
Symptom
The IKEv2 SA is in IN-NEGO status.
<Sysname> display ikev2 sa
Tunnel ID Local Remote Status
---------------------------------------------------------------------------
5 123.234.234.124/500 123.234.234.123/500 IN-NEGO
Status:
IN-NEGO: Negotiating, EST: Establish, DEL:Deleting
Analysis
Certain IKEv2 proposal settings are incorrect.
Solution
1.
Examine the IKEv2 proposal configuration to see whether the two ends have matching IKEv2
proposals.
2.
Modify the IKEv2 proposal configuration to make sure the two ends have matching IKEv2
proposals.
Summary of Contents for FlexFabric 5940 SERIES
Page 251: ...238 ...