Configuring IPv4 and IPv6 IPsec Tunnels

To set up an IPsec IPv4 or IPv6 tunnel, you must specify the tunnel interface by tunnel number, designate the tunnel mode (IPv4 or IPv6), and set the IKE and IPsec options for the tunnel. Once the tunnel is created, you can use it to transmit IP packets securely.
Pre-requisites:
  • Use of PKI: If your IPsec tunnel configuration involves the use of PKI options (for example, a PKI entity or PKI trustpoint), make sure you complete the PKI configuration before you begin setting up the IPsec tunnel. The PKI options must be configured before you can select them as part of the tunnel setup process.
  • Use of global IKEv2 parameters: If you need to configure any global IKEv2 parameters, make sure you complete the configuration before you begin setting up the IPsec tunnel.

Note: You can use an IPsec IPv4 tunnel to transmit IPv6 packets, but you cannot use an IPsec IPv6 tunnel to transmit IPv4 packets.
Note: Only IKEv2 is supported; IKEv1 is not supported.
Note: ICX 7450 devices do not support transport mode for IPsec tunnel configuration; they support "tunnel" mode only.
Note: The network administrator must ensure that the IKE cryptographic algorithms and key sizes that are configured for a tunnel are stronger than the IPsec cryptographic algorithms and key sizes used by the same tunnel.

Effect of Authentication Method on IKEv2 Profile Settings

The type or method of authentication you select for IKE transactions affects IKEv2 profile options you should select when setting up IPsec tunnels.

The recommended IKEv2 profile options are:

  • PKI-based authentication: When using PKI-based authentication, it is recommended that you select Distinguished Name (DN).
  • Pre-shared key authentication: When using pre-shared key authentication (PSK), use IP addresses as local and remote identifiers.

Complete the following steps to set up the IPsec tunnel.

  1. Enter one of the following commands in tunnel interface configuration mode to select the tunnel mode for the IPsec virtual terminal interface (VTI).
    • ipv4: tunnel mode ipsec ipv4
    • ipv6: tunnel mode ipsec ipv6
    The following example specifies IPv4 as the IPsec tunnel mode for Tunnel 1.
    device(config)# interface tunnel 1
    device(config-tnif-1)# tunnel mode ipsec ipv4
  2. Enter the tunnel protection ipsec profile command in tunnel interface configuration mode to assign a previously configured IPsec profile that will be used to encapsulate outgoing packets. (This binds the profile to the VTI.)
    The following example assigns the previously created IPsec profile test-profile to Tunnel 1.
    device(config)# interface tunnel 1
    device(config-tnif-1)# tunnel protection ipsec profile test-profile
  3. Enter the tunnel source command to specify the tunnel source. This is the local endpoint of the tunnel. If you are specifying an IP address, it should be consistent with the tunnel mode you have specified.
    The tunnel source can be one of the following:
    • The IPv4 address of a physical, virtual, or loopback interface as shown in the following example.
      device(config)# interface tunnel 1
      device(config-tnif-1)# tunnel source 192.168.1.2
    • The global IPv6 address of a physical, virtual, or loopback interface as shown in the following example.
      device(config) interface tunnel 3
      device(config-tnif-3)# tunnel mode ipsec ipv6
      device(config-tnif-3)# tunnel source 10:1:1::1/64
    • The interface on which the required tunnel source IPv4 address or IPv6 address has been configured as shown in the following example.
      device(config) interface tunnel 1
      device(config-tnif-1)# tunnel source ethernet 1/1/1
  4. Enter the tunnel destination command to specify the tunnel destination. This is the remote endpoint of the tunnel. Use an IP address consistent with the tunnel mode you have specified.
    The following example specifies an IPv4 tunnel destination.
    device(config-tnif-1)# tunnel destination 10.1.1.2
    The following example specifies an IPv6 destination.
    device(config-tnif-3)# tunnel destination 10:1:1::2/64
  5. Specify the tunnel address. This is the IPv4 or IPv6 address of the tunnel port, not a tunnel endpoint.
    • For an IPv4 tunnel, enter the ip address command followed by the IPv4 tunnel address.
      • As an option, so that the IPv4 tunnel can also transmit IPv6 packets, also enter an IPv6 address for the same IPv4 tunnel interface.
    • For an IPv6 tunnel, enter the ipv6 address command followed by the IPv6 tunnel address.
    The following example configures an IPv4 address for the tunnel port.
    device(config-tnif-1)# ip address 36.0.8.108/32
    The following example configures an IPv6 address for the tunnel port.
    device(config-tnif-3)# ipv6 address 10:10:10::1/120
    The following example, when configured on an IPv4 tunnel interface, adds an IPv6 address as a tunnel port, which enables the tunnel to transmit IPv6 packets.
    device(config-tnif-1)# ipv6 address 36:1:1::1/120
    
  6. In global configuration mode, enter the ipsec profile command followed by the IPsec profile name to enter IPsec profile configuration mode. In this mode, specify a previously configured IPsec proposal and a previously configured IKEv2 profile for use.
    The following example provides required syntax.
    device(config)# ipsec profile < ipsec_profile_name >
    device(config-ipsec-profile-name) proposal < ipsec_proposal >
    device(config-ipsec-profile-name) ike-profile < ike_profile_name >
    
    The following example configures the IPsec profile a1 to use the IPsec proposal test-proposal and the IKEv2 profile test-profile.
    device(config)# ipsec profile a1
    device(config-ipsec-profile-a1) proposal test-proposal
    device(config-ipsec-profile-a1) ike-profile test-profile
    device(config-ipsec-profile-a1)# exit
    

Summary Examples

The following example shows the steps and syntax needed to configure an IPv4 IPsec tunnel.

device(config)# interface tunnel < tunnel_id >
device(config-tnif-id)# tunnel mode ipsec ipv4
device(config-tnif-id)# tunnel protection ipsec profile < ipsec_profile_name >
device(config-tnif-id)# tunnel protection ipsec profile < profile-name >
device(config-tnif-id)# tunnel source < ipv4-address >  <-- ethernet < port > may be used instead.
device(config-tnif-id)# tunnel destination < tunnel destination ipv4-address >
device(config-tnif-id)# ip address < tunnel ip-address >

The following example applies the IPsec profile a1 to the tunnel with IP address 10.0.0.1 255.255.255.0. It also specifies the source (local endpoint) and destination addresses to be used for IPsec connections over the tunnel.

device(config)# interface tunnel 1
device(config-tnif-1)# tunnel mode ipsec ipv4
device(config-tnif-1)# tunnel protection ipsec profile a1
device(config-tnif-1)# tunnel source 10.1.1.1
device(config-tnif-1)# tunnel destination 10.1.1.2
device(config-tnif-1)# ip address 10.0.0.1 255.255.255.0

The following example adds an IPv6 address to the IPv4 tunnel interface shown in the previous example, which enables the tunnel to transmit IPv6 packets.

device(config-tnif-1)# ipv6 address 36:1:1::1/120
device(config-tnif-1)# exit

The following example shows the steps and syntax needed to configure an IPv6 IPsec tunnel.

device# configure terminal
device(config)# interface tunnel < tunnel_id >
device(config-tnif-id)# tunnel mode ipsec ipv6
device(config-tnif-id)# tunnel protection ipsec profile < ipsec_profile_name >
device(config)# interface tunnel < tunnel_id >
device(config-tnif-id)# tunnel source < ipv6_address >         <-- ethernet < port > may be used instead.
device(config-tnif-id)# tunnel destination < ipv6_address >
device(config-tnif-id)# ip address < tunnel_port_ipv6_address >

The following example creates an IPv6 IPsec tunnel and applies the previously configured IPsec profile ipv6prof.

device# configure terminal
device(config)# interface tunnel 3
device(config-tnif-3)# tunnel mode ipsec ipv6
device(config-tnif-3)# tunnel protection ipsec profile ipv6prof
device(config-tnif-3)# tunnel source 10::1
device(config-tnif-3)# tunnel destination 10::2
device(config-tnif-3)# ipv6 address 10:10:10::1/120

The following example outlines the full process of creating an authentication proposal (here, using a previously defined pre-shared key), including the proposal in an IKEv2 profile, associating the IKEv2 profile with an IPsec profile, and configuring an IPsec tunnel protected by the IPsec profile.

device# configure terminal
device(config)# ikev2 auth-proposal preshared
device(config-ike-preshared)# pre-shared-key 2
!

!
device(config)# ikev2 profile p2
device(config-ike-profile-p2)# authentication preshared
device(config-ike-profile-p2)# local-identifier address 10::1
device(config-ike-profile-p2)# remote-identifier address 10::2
device(config-ike-profile-p2)# match-identity local address 10::1
device(config-ike-profile-p2)# match-identity remote address 10::2
device(config-ike-profile-p2)# exit
!
device(config)# ipsec profile ipv6prof
device(config-ipsec-profile-ipv6prof)# ike-profile p2
device(config-ipsec-profile-ipv6prof)# exit

device# configure terminal
device(config)# interface tunnel 3
device(config-tnif-3)# tunnel mode ipsec ipv6
device(config-tnif-3)# tunnel protection ipsec profile ipv6prof
device(config-tnif-3)# tunnel source 10::1
device(config-tnif-3)# tunnel destination 10::2
device(config-tnif-3)# ipv6 address 10:10:10::1/120


device(config-tnif-3)#  show running-config interface tunnel 3
!
interface tunnel 3
tunnel mode ipsec ipv6
tunnel protection ipsec profile ipv6prof
tunnel source 10::1
tunnel destination 10::2
ipv6 address 10:10:10::1/120