Configuring IPv4 and IPv6 IPsec Tunnels
- Use of PKI: If your IPsec tunnel configuration involves the use of PKI options (for example, a PKI entity or PKI trustpoint), make sure you complete the PKI configuration before you begin setting up the IPsec tunnel. The PKI options must be configured before you can select them as part of the tunnel setup process.
- Use of global IKEv2 parameters: If you need to configure any global IKEv2 parameters, make sure you complete the configuration before you begin setting up the IPsec tunnel.
Effect of Authentication Method on IKEv2 Profile Settings
The type or method of authentication you select for IKE transactions affects IKEv2 profile options you should select when setting up IPsec tunnels.
The recommended IKEv2 profile options are:
Complete the following steps to set up the IPsec tunnel.
- Enter one of the following commands in tunnel interface configuration mode to select
the tunnel mode for the IPsec virtual terminal interface (VTI).
The following example specifies IPv4 as the IPsec tunnel mode for Tunnel 1.
- Enter the
tunnel protection ipsec profilecommand in tunnel interface configuration mode to assign a previously configured IPsec profile that will be used to encapsulate outgoing packets. (This binds the profile to the VTI.)The following example assigns the previously created IPsec profile test-profile to Tunnel 1. - Enter the
tunnel sourcecommand to specify the tunnel source. This is the local endpoint of the tunnel. If you are specifying an IP address, it should be consistent with the tunnel mode you have specified.The tunnel source can be one of the following:- The IPv4 address of a physical, virtual, or loopback interface as shown in the following
example.
device(config)# interface tunnel 1 device(config-tnif-1)# tunnel source 192.168.1.2
- The global IPv6 address of a physical, virtual, or loopback interface as shown in
the following example.
device(config) interface tunnel 3 device(config-tnif-3)# tunnel mode ipsec ipv6 device(config-tnif-3)# tunnel source 10:1:1::1/64
- The interface on which the required tunnel source IPv4 address or IPv6 address has
been configured as shown in the following example.
device(config) interface tunnel 1 device(config-tnif-1)# tunnel source ethernet 1/1/1
- The IPv4 address of a physical, virtual, or loopback interface as shown in the following
example.
- Enter the
tunnel destinationcommand to specify the tunnel destination. This is the remote endpoint of the tunnel. Use an IP address consistent with the tunnel mode you have specified.The following example specifies an IPv4 tunnel destination.The following example specifies an IPv6 destination. - Specify the tunnel address. This is the IPv4 or IPv6 address of the tunnel port,
not a tunnel endpoint.
- For an IPv4 tunnel, enter the
ip addresscommand followed by the IPv4 tunnel address. - For an IPv6 tunnel, enter the
ipv6 addresscommand followed by the IPv6 tunnel address.
The following example configures an IPv4 address for the tunnel port.The following example configures an IPv6 address for the tunnel port. - For an IPv4 tunnel, enter the
- In global configuration mode, enter the
ipsec profilecommand followed by the IPsec profile name to enter IPsec profile configuration mode. In this mode, specify a previously configured IPsec proposal and a previously configured IKEv2 profile for use.The following example provides required syntax.device(config)# ipsec profile < ipsec_profile_name > device(config-ipsec-profile-name) proposal < ipsec_proposal > device(config-ipsec-profile-name) ike-profile < ike_profile_name >
The following example configures the IPsec profile a1 to use the IPsec proposal test-proposal and the IKEv2 profile test-profile.
Summary Examples
The following example shows the steps and syntax needed to configure an IPv4 IPsec tunnel.
device(config)# interface tunnel < tunnel_id > device(config-tnif-id)# tunnel mode ipsec ipv4 device(config-tnif-id)# tunnel protection ipsec profile < ipsec_profile_name > device(config-tnif-id)# tunnel protection ipsec profile < profile-name > device(config-tnif-id)# tunnel source < ipv4-address > <-- ethernet < port > may be used instead. device(config-tnif-id)# tunnel destination < tunnel destination ipv4-address > device(config-tnif-id)# ip address < tunnel ip-address >
The following example applies the IPsec profile a1 to the tunnel with IP address 10.0.0.1 255.255.255.0. It also specifies the source (local endpoint) and destination addresses to be used for IPsec connections over the tunnel.
device(config)# interface tunnel 1 device(config-tnif-1)# tunnel mode ipsec ipv4 device(config-tnif-1)# tunnel protection ipsec profile a1 device(config-tnif-1)# tunnel source 10.1.1.1 device(config-tnif-1)# tunnel destination 10.1.1.2 device(config-tnif-1)# ip address 10.0.0.1 255.255.255.0
The following example adds an IPv6 address to the IPv4 tunnel interface shown in the previous example, which enables the tunnel to transmit IPv6 packets.
device(config-tnif-1)# ipv6 address 36:1:1::1/120 device(config-tnif-1)# exit
The following example shows the steps and syntax needed to configure an IPv6 IPsec tunnel.
device# configure terminal device(config)# interface tunnel < tunnel_id > device(config-tnif-id)# tunnel mode ipsec ipv6 device(config-tnif-id)# tunnel protection ipsec profile < ipsec_profile_name > device(config)# interface tunnel < tunnel_id > device(config-tnif-id)# tunnel source < ipv6_address > <-- ethernet < port > may be used instead. device(config-tnif-id)# tunnel destination < ipv6_address > device(config-tnif-id)# ip address < tunnel_port_ipv6_address >
The following example creates an IPv6 IPsec tunnel and applies the previously configured IPsec profile ipv6prof.
device# configure terminal device(config)# interface tunnel 3 device(config-tnif-3)# tunnel mode ipsec ipv6 device(config-tnif-3)# tunnel protection ipsec profile ipv6prof device(config-tnif-3)# tunnel source 10::1 device(config-tnif-3)# tunnel destination 10::2 device(config-tnif-3)# ipv6 address 10:10:10::1/120
The following example outlines the full process of creating an authentication proposal (here, using a previously defined pre-shared key), including the proposal in an IKEv2 profile, associating the IKEv2 profile with an IPsec profile, and configuring an IPsec tunnel protected by the IPsec profile.
device# configure terminal device(config)# ikev2 auth-proposal preshared device(config-ike-preshared)# pre-shared-key 2 ! ! device(config)# ikev2 profile p2 device(config-ike-profile-p2)# authentication preshared device(config-ike-profile-p2)# local-identifier address 10::1 device(config-ike-profile-p2)# remote-identifier address 10::2 device(config-ike-profile-p2)# match-identity local address 10::1 device(config-ike-profile-p2)# match-identity remote address 10::2 device(config-ike-profile-p2)# exit ! device(config)# ipsec profile ipv6prof device(config-ipsec-profile-ipv6prof)# ike-profile p2 device(config-ipsec-profile-ipv6prof)# exit device# configure terminal device(config)# interface tunnel 3 device(config-tnif-3)# tunnel mode ipsec ipv6 device(config-tnif-3)# tunnel protection ipsec profile ipv6prof device(config-tnif-3)# tunnel source 10::1 device(config-tnif-3)# tunnel destination 10::2 device(config-tnif-3)# ipv6 address 10:10:10::1/120 device(config-tnif-3)# show running-config interface tunnel 3 ! interface tunnel 3 tunnel mode ipsec ipv6 tunnel protection ipsec profile ipv6prof tunnel source 10::1 tunnel destination 10::2 ipv6 address 10:10:10::1/120