Objective
This reference provides commands and sample output for verifying PQC or PPK negotiation and SD-WAN IKEv2 sessions.
Sample output for ML-KEM-based PQC
Device# show crypto ikev2 sa detailed
IPv4 Crypto IKEv2 SA
Tunnel-id Local Remote fvrf/ivrf Status
1 50.50.50.2/12346 51.51.51.2/12346 none/none READY
Encr: AES-GCM, keysize: 256, PRF: SHA256, DH Grp:19
Auth sign: PSK, Auth verify: PSK
PQC Key Exchange: ML-KEM-768
Status Description: Negotiation done
Quantum-safe Encryption using PQC: ML-KEM-768
PEER TYPE: IOS-XE
Confirm READY, PQC Key Exchange, and Quantum-safe Encryption using PQC.
Sample output for dynamic PPK
Device# show crypto ikev2 sa detailed
IPv4 Crypto IKEv2 SA
Tunnel-id Local Remote fvrf/ivrf Status
3 10.1.30.30/12346 10.1.31.31/12346 none/none READY
Encr: AES-GCM, keysize: 256, PRF: SHA256, DH Grp:19
Auth sign: PSK, Auth verify: PSK, QR
Status Description: Negotiation done
Quantum-safe Encryption using Dynamic PPK
Local Sys Id: sks2 Remote Sys Id: sks1
PEER TYPE: IOS-XE
Confirm READY, QR, Dynamic PPK, and the local and remote key-source IDs.
Sample output for manual PPK
Device# show crypto ikev2 sa detailed
IPv4 Crypto IKEv2 SA
Tunnel-id Local Remote fvrf/ivrf Status
2 52.52.52.2/12346 53.53.53.2/12346 none/none READY
Encr: AES-GCM, keysize: 256, PRF: SHA256, DH Grp:19
Auth sign: PSK, Auth verify: PSK, QR
Status Description: Negotiation done
Quantum-safe Encryption using Manual PPK
PEER TYPE: IOS-XE
Confirm READY, QR, and Quantum-safe Encryption using Manual PPK.
Verify the SD-WAN IKEv2 session counters
Device# show crypto ikev2 sdwan stats
Total SDWAN IKEv2 sessions : 48
Total SDWAN IKEv2 active sessions : 48
Total SDWAN IKEv2 inactive sessions : 0
Total session create requests received : 48
Total session create requests succeeded : 48
Total session update requests received : 10
Total session update requests succeeded : 10
Total session updates - no change : 10
Total BFD down notifications received : 18
Total BFD down notifications skipped : 18
Total create IPSec SA success notify sent : 1123
Total delete IPSec SA notify sent : 546
Total delete IPSec SA notify drops : 10
Total remote behind SYMNAT detected : 10
Total remote behind SYMNAT notification sent : 10
Total remote behind SYMNAT processing done : 10
Error Statistics:
Sessions flapped due to DPD timeout : 18
Display the available SD-WAN IKEv2 session filters
Device# show crypto ikev2 sdwan session ?
detail Show detailed session information
flap-history Show session flap history
remote-sysip Filter by remote system-ip
tloc-pair Filter by tloc-pair
| Output modifiers
<cr> <cr>
List the SD-WAN IKEv2 sessions
Device# show crypto ikev2 sdwan session
TLOC Pair Local address:port
Remote address:port WAN If Tunnel If SA Flow ID
mpls.172.16.255.15#mpls.10.1.1.1 10.1.15.15:12346
192.161.1.1:12346 Gi1 Tu1 0x24000868
mpls.172.16.255.15#private1.10.1.1.1 10.1.15.15:12346
192.161.1.3:12346 Gi1 Tu1 0x240008AE
biz-internet.172.16.255.15#biz-internet.10.1.1.1 15.20.100.1:12346
192.161.1.4:12346 Lo200 Tu14095200 0x24000870
biz-internet.172.16.255.15#public-internet.10.1.1.1 15.20.100.1:12346
192.161.1.2:12346 Lo200 Tu14095200 0x2400087E
biz-internet.172.16.255.15#silver.10.1.1.1 15.20.100.1:12346
192.161.1.5:12346 Lo200 Tu14095200 0x2400088C
public-internet.172.16.255.15#biz-internet.10.1.1.1 10.0.20.15:12346
192.161.1.4:12346 Gi2 Tu2 0x24000878
Display detailed SD-WAN IKEv2 session information
The following command displays detailed information for all SD-WAN IKEv2 sessions:
hub1# show crypto ikev2 sdwan session detail
TLOC Info:
Remote TLOC : mpls:201.201.30.31
Local TLOC : public-internet:201.201.201.101
IPSec Proxy :
Remote address : 11.30.1.31:12346
Local address : 11.1.2.1:12346
Route Info:
Peer private address : 11.30.1.31:12346
Peer NAT address : 11.30.1.31:12346
Peer SYMNAT address : 0.0.0.0:0
My private address : 11.1.2.1:12346
My NAT address : 11.1.2.1:12346
My SYMNAT address : 0.0.0.0:0
SYMNAT Type : no symnat
SYMNAT Notify Pending : FALSE
Use private local : FALSE
Loopback : FALSE
Loopback bind : FALSE
Loopback bind i/f : N/A
Route via interface : TenGigabitEthernet0/1/1
WAN interface : TenGigabitEthernet0/1/1
Tunnel interface : Tunnel200
Crypto map tag : Tunnel200-sdwan-head-IPv4 66263
Crypto session handle : 0x40001637
Outbound SA Flow ID : 0x24010446
BFD local discriminator: 23633
Local PSK tag : CD935EDD
Local next PSK tag : 376F50C5
Remote PSK tag : 2CC3B04A
Remote next PSK tag : 2CC3B04A
Remote PSK expire : FALSE
Session Events:
Jul 27 12:21:36.053 UTC: [RP -> SDWAN IKEv2] session create request received
Jul 27 12:21:36.053 UTC: Crypto map head exists
Jul 27 12:21:36.053 UTC: Crypto map create succeeded
Jul 27 12:22:06.188 UTC: Notify IPSec SA create success
TLOC Info:
Remote TLOC : biz-internet:201.201.30.31
Local TLOC : public-internet:201.201.201.101
IPSec Proxy :
Remote address : 11.30.12.31:12346
Local address : 11.1.2.1:12346
Route Info:
Peer private address : 11.30.12.31:12346
Peer NAT address : 11.30.12.31:12346
Peer SYMNAT address : 0.0.0.0:0
My private address : 11.1.2.1:12346
My NAT address : 11.1.2.1:12346
My SYMNAT address : 0.0.0.0:0
SYMNAT Type : no symnat
SYMNAT Notify Pending : FALSE
Use private local : FALSE
Loopback : FALSE
Loopback bind : FALSE
Loopback bind i/f : N/A
Route via interface : TenGigabitEthernet0/1/1
WAN interface : TenGigabitEthernet0/1/1
Tunnel interface : Tunnel200
Crypto map tag : Tunnel200-sdwan-head-IPv4 66265
Crypto session handle : 0x40001E41
Outbound SA Flow ID : 0x2400FAE0
BFD local discriminator: 23643
Local PSK tag : CD935EDD
Local next PSK tag : 376F50C5
Remote PSK tag : 2CC3B04A
Remote next PSK tag : 2CC3B04A
Remote PSK expire : FALSE
Session Events:
Jul 27 12:21:36.053 UTC: [RP -> SDWAN IKEv2] session create request received
Jul 27 12:21:36.053 UTC: Crypto map head exists
Jul 27 12:21:36.053 UTC: Crypto map create succeeded
Jul 27 12:22:06.188 UTC: Notify IPSec SA create success
Filter sessions by remote system IP
Use this command to inspect detailed session state for remote system IP 201.201.30.31:
hub1# show crypto ikev2 sdwan session remote-sysip 201.201.30.31 detail
TLOC Info:
Remote TLOC : mpls:201.201.30.31
Local TLOC : public-internet:201.201.201.101
IPSec Proxy :
Remote address : 11.30.1.31:12346
Local address : 11.1.2.1:12346
Route Info:
Peer private address : 11.30.1.31:12346
Peer NAT address : 11.30.1.31:12346
Peer SYMNAT address : 0.0.0.0:0
My private address : 11.1.2.1:12346
My NAT address : 11.1.2.1:12346
My SYMNAT address : 0.0.0.0:0
SYMNAT Type : no symnat
SYMNAT Notify Pending : FALSE
Use private local : FALSE
Loopback : FALSE
Loopback bind : FALSE
Loopback bind i/f : N/A
Route via interface : TenGigabitEthernet0/1/1
WAN interface : TenGigabitEthernet0/1/1
Tunnel interface : Tunnel200
Crypto map tag : Tunnel200-sdwan-head-IPv4 66263
Crypto session handle : 0x40001637
Outbound SA Flow ID : 0x24010446
BFD local discriminator: 23633
Local PSK tag : CD935EDD
Local next PSK tag : 376F50C5
Remote PSK tag : 2CC3B04A
Remote next PSK tag : 2CC3B04A
Remote PSK expire : FALSE
Session Events:
Jul 27 12:21:36.053 UTC: [RP -> SDWAN IKEv2] session create request received
Jul 27 12:21:36.053 UTC: Crypto map head exists
Jul 27 12:21:36.053 UTC: Crypto map create succeeded
Jul 27 12:22:06.188 UTC: Notify IPSec SA create success
Filter sessions by TLOC pair
Use this command to inspect detailed session state for the specified local and remote TLOC pair:
hub1# show crypto ikev2 sdwan session tloc-pair public-internet.201.201.201.101#green.201.201.30.31 detail
TLOC Info:
Remote TLOC : green:201.201.30.31
Local TLOC : public-internet:201.201.201.101
IPSec Proxy :
Remote address : 11.30.15.31:12346
Local address : 11.1.2.1:12346
Route Info:
Peer private address : 11.30.15.31:12346
Peer NAT address : 11.30.15.31:12346
Peer SYMNAT address : 0.0.0.0:0
My private address : 11.1.2.1:12346
My NAT address : 11.1.2.1:12346
My SYMNAT address : 0.0.0.0:0
SYMNAT Type : no symnat
SYMNAT Notify Pending : FALSE
Use private local : FALSE
Loopback : FALSE
Loopback bind : FALSE
Loopback bind i/f : N/A
Route via interface : TenGigabitEthernet0/1/1
WAN interface : TenGigabitEthernet0/1/1
Tunnel interface : Tunnel200
Crypto map tag : Tunnel200-sdwan-head-IPv4 66268
Crypto session handle : 0x40001650
Outbound SA Flow ID : 0x240111CE
BFD local discriminator: 23658
Local PSK tag : CD935EDD
Local next PSK tag : 376F50C5
Remote PSK tag : 2CC3B04A
Remote next PSK tag : 2CC3B04A
Remote PSK expire : FALSE
Session Events:
Jul 27 12:21:36.053 UTC: [RP -> SDWAN IKEv2] session create request received
Jul 27 12:21:36.053 UTC: Crypto map head exists
Jul 27 12:21:36.053 UTC: Crypto map create succeeded
Jul 27 12:22:06.188 UTC: Notify IPSec SA create success