Configuring an IKEv2 Authentication Proposal for Use in an IPsec Profile

Follow these steps to configure an IKEv2 authentication proposal.

  1. Based on your certification method, do one of the following:
    • To use a pre-defined shared secret (PSK), configure an IKEv2 authentication proposal.
      Note: You must define a pre-shared key in Common Criteria mode, as no default value is configured. A warning message is displayed if no pre-shared key has been defined in the authentication proposal.
    • For X.509 certification, configure a PKI trustpoint.
    The following example provides command syntax for specifying a pre-shared key.
    device# configure terminal
    device(config)# ikev2 auth-proposal < proposalname >
    device(config-ike-auth-proposalname)# pre-shared-key < valid-key >
    device(config-ike-auth-proposalname)# exit
    Note: Valid keys must be at least eight characters in length. They must contain a mix of at least three character types (uppercase alpha characters, lowercase alpha characters, numeric characters, non-alpha ASCII characters). The first character must not be the only uppercase alpha character in the key, and the last character must not be the only numeric character in the key. The system returns an error if the pre-shared key is not valid.
    The following example defines a valid pre-shared key for use with IKEv2 authentication proposal "withKey-L2."
    device# configure terminal
    device(config)# ikev2 auth-proposal withKeyL2
    device(config-ike-auth-withKeyL2)# pre-shared-key m!XYZ#79L
    device(config-ike-auth-withKeyL2)# exit
    
    Note: Bit-based pre-shared key are supported on ICX 7450 devices. To specify a bit-based preshared key in the IKE auth-proposal, enter auth-proposal bit-based configuration submode, and add the prefix "0x" to a hexadecimal value.
    The following example creates a bit-based pre-shared key on an ICX 7450 device.
    ICX_7450_device# configure terminal
    ICX_7450_device(config)# ike auth-proposal bit-based
    ICX_7450_device(config-ike-auth-proposal-bit-based)# 0xabcd10908
    
    The following example provides command syntax for specifying a trustpoint for use with X.509 certification.
    device# configure terminal
    device(config)# ikev2 auth-proposal < proposalname >
    device(config-ike-auth-proposalname)# pki-trustpoint < trustpointname > [ sign | verify ]
    
    The following example configures a PKI trustpoint for the Certificate Authority for use in X.509 certification. In the example, the server abcd is established as the PKI trustpoint for both certificate signature and verification.
    device# configure terminal
    device(config)# ikev2 auth-proposal abcd-CA
    device(config-ike-auth-proposal-abcd-CA)# pki-trustpoint abcd-CA sign
    device(config-ike-auth-proposal-abcd-CA)# pki-trustpoint abcd-CA verify
    
    Note: A full example of setting up for X.509 certification is presented in the section "Configuration example: creating an IPsec profile for tunnels that use X.509 certificates."
  2. Configure an IKEv2 profile that uses IP addresses or distinguished names as local and remote identifiers.
    Note: DN is the subject name of the PKI local certificate. Domain name may contain common name, state, country, organization name and organization unit name of the entity for which the PKI certificate is presented.
    The following example provides command syntax.
    device(config)# ikev2 profile < profilename >
    device(config-ike-profile-profilename)# authentication < auth-proposalname > 
    device(config-ike-profile-profilename)# local-identifier address < ip-address | ipv6-address | dn >
    device(config-ike-profile-profilename)# remote-identifier address < ip-address | ipv6-address | dn >
    device(config-ike-profile-profilename)# match-identity local address < ip-address | ipv6-address | dn >
    device(config-ike-profile-profilename)# match-identity remote address < ip-address | ipv6-address | dn >
    device(config-ike-profile-profilename)# exit
    
    The example below uses IP addresses as identifiers.
    device(config)# ikev2 profile withKeyL2
    device(config-ike-profile-withKeyL2)# authentication withKeyL2 
    device(config-ike-profile-withKeyL2)# local-identifier address 15.1.1.2
    device(config-ike-profile-withKeyL2)# remote-identifier address 15.1.1.1
    device(config-ike-profile-withKeyL2)# match-identity local address 15.1.1.2
    device(config-ike-profile-withKeyL2)# match-identity remote address 15.1.1.1
    device(config-ike-profile-withKeyL2)# exit
    
    The following example uses distinguished names as identifiers.
    device(config)# ikev2 profile with_standalone 
    device(config-ike-profile-with_standalone)# authentication withCert
    device(config-ike-profile-with_standalone)# local-identifier dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT"
    device(config-ike-profile-with_standalone)# remote-identifier dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME"
    device(config-ike-profile-with_standalone)# match-identity local dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT"
    device(config-ike-profile-with_standalone)# match-identity remote dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME"
    device(config-ike-profile-with_standalone)#  exit
    
  3. Configure an IPsec profile that uses a previously configured IKEv2 profile.
    device(config)# ipsec profile withKeyL2
    device(config-ipsec-profile-withKeyL2)# ike-profile withKeyL2  <--- pre-configured IKEv2 profile
    device(config-ipsec-profile-withKeyL2)# exit
    
    Note: To use the IPsec profile, you must associate it with a specific tunnel. This process is described in the section "Configuring an IPv4 or IPv6 IPsec tunnel."

The following example configures IPsec tunnel 1 to use an IPsec profile that references IKEv2 settings from a specific IKEv2 profile.

device# configure terminal
device(config)# ikev2 auth-proposal withKeyL2
device(config-ike-auth-withKeyL2)# pre-shared-key 2
device(config-ike-auth-withKeyL2)# exit
device(config)# ikev2 profile withKeyL2
device(config-ike-profile-withKeyL2)# authentication withKeyL2            <--- authentication proposal name
device(config-ike-profile-withKeyL2)# local-identifier address 15.1.1.2
device(config-ike-profile-withKeyL2)# remote-identifier address 15.1.1.1
device(config-ike-profile-withKeyL2)# match-identity local address 15.1.1.2
device(config-ike-profile-withKeyL2)# match-identity remote address 15.1.1.1
device(config-ike-profile-withKeyL2)# exit
device(config)# ipsec profile withKeyL2
device(config-ipsec-profile-withKeyL2)# ike-profile withKeyL2             <--- previously configured IKEv2 profile
device(config-ipsec-profile-withKeyL2)# exit
device(config)# interface tunnel 1
device(config-tnif-1)# interface tunnel 1
device(config-tnif-1)# tunnel mode ipsec ipv4
device(config-tnif-1)# tunnel protection ipsec profile withKeyL2           <---- previously configured IPsec profile
device(config-tnif-1)# tunnel source 15.1.1.2
device(config-tnif-1)# tunnel destination 15.1.1.1
device(config-tnif-1)# ip address 15.15.15.1 255.255.255.0