Configuring an IKEv2 Proposal and Policy

The initial steps in the following procedure describe how to modify standard IKEv2 settings. The last step in the procedure associates a pre-configured IKEv2 proposal to an IKEv2 policy.

  1. (Optional) Enter the following ikev2 commands at the global configuration level to enable the non-default NAT-T option, and to specify the NAT keep-alive time interval.
    In this example, the option is enabled and the keep-alive time interval is set to 30 seconds (the default is 20 seconds).
    device(config)# ikev2 nat-enable
    device(config)# ikev2 nat keepalive 30
    
  2. (Optional) Enter the ikev2 proposal command to designate a non-default proposal for the initial phase of the IKEv2 peer negotiation and to enter IKEv2 proposal configuration mode. (You must be in IKEv2 proposal configuration mode to configure a non-default proposal.)
    In this example, an IKEv2 proposal named a1 is defined.
    device(config)# ikev2 proposal a1
    device(config-ike-proposal-a1)#
    
  3. (Optional) In IKE proposal configuration sub-mode, select a non-default Diffie Hellman (DH) group, or groups. (The default DH group is 20. The non-default groups you can select are groups 14 or 19.)
    In this example, DH group 14 is selected and the default (DH group 20) is disabled. Only DH group 14 will be included in the IKEv2 proposal. The default is disabled to ensure it is not selected during the negotiation because if multiple DH groups are selected, the first matching DH group supported by both ends is automatically selected.)
    device(config-ike-proposal-a1)# dhgroup 14
    device(config-ike-proposal-a1)# no dhgroup 20
    device(config-ike-proposal-a1)# exit
    
  4. (Optional) In IKEv2 proposal configuration sub-mode, configure a pseudorandom function (PRF) for the proposal. This defines the hash size algorithm for the IKEv2.
    In this example, the SHA-256 algorithm is added to the PRF algorithms configured for a1. Because the SHA-384 algorithm is configured by default, both the SHA-384 and SHA-256 algorithms are configured for IKEv2 proposal a1 after executing this step. Configuration of multiple PRF algorithms is allowed.
    device(config-ike-proposal-a1)# prf sha256
    
  5. (Optional) In IKEv2 proposal configuration sub-mode, enter the integrity command followed by the encryption algorithm to configure an integrity algorithm for the proposal as shown in the following example.

    This step adds the SHA-256 algorithm to the integrity algorithms configured for the proposal a1. Because the SHA-384 algorithm is configured by default, both the SHA-384 and SHA-256 algorithms are configured for a1 after executing this step. Configuration of multiple integrity algorithms is allowed.

    When you want to configure the SHA-256 algorithm only for the proposal, you must first add the SHA-256 algorithm and then remove the default algorithm by using the command no integrity sha384.

    device(config-ike-proposal-a1)# integrity sha256
    
  6. (Optional) In IKEv2 proposal configuration sub-mode, enter the encryption command to configure an encryption algorithm for the proposal as shown in the following example.

    In the example, the AES-CBC-128 algorithm is added to the encryption algorithms configured for proposal a1. Because the AES-CBC-256 algorithm is configured by default, both the AES-CBC-256 and AES-CBC-128 algorithms are configured for IKEv2 Proposal a1 after executing this step. Configuration of multiple encryption algorithms is allowed.

    When you want to configure the AES-CBC-128 algorithm only for the proposal, you must first add the AES-CBC-128 algorithm and then remove the default algorithm using the command no encryption aes-cbc-256.

    device(config-ike-proposal-a1)# encryption aes-cbc-128
    
  7. Enter the ikev2 policy command in general configuration mode to designate an IKEv2 policy, to enter IKEv2 policy configuration mode, and to bind a pre-configured authentication proposal to protect IKE during negotiations.
    device(config)# ikev2 policy test-policy
    device(config-ike-test-policy)# proposal a1
    device(config-ike-test-policy)# exit