Configuring an IKEv2 Proposal and Policy
The initial steps in the following procedure describe how to modify standard IKEv2 settings. The last step in the procedure associates a pre-configured IKEv2 proposal to an IKEv2 policy.
- (Optional) Enter the following
ikev2commands at the global configuration level to enable the non-default NAT-T option, and to specify the NAT keep-alive time interval. - (Optional) Enter the
ikev2 proposalcommand to designate a non-default proposal for the initial phase of the IKEv2 peer negotiation and to enter IKEv2 proposal configuration mode. (You must be in IKEv2 proposal configuration mode to configure a non-default proposal.) - (Optional) In IKE proposal configuration sub-mode, select a non-default Diffie Hellman
(DH) group, or groups. (The default DH group is 20. The non-default groups you can
select are groups 14 or 19.)
In this example, DH group 14 is selected and the default (DH group 20) is disabled. Only DH group 14 will be included in the IKEv2 proposal. The default is disabled to ensure it is not selected during the negotiation because if multiple DH groups are selected, the first matching DH group supported by both ends is automatically selected.)
device(config-ike-proposal-a1)# dhgroup 14 device(config-ike-proposal-a1)# no dhgroup 20 device(config-ike-proposal-a1)# exit
- (Optional) In IKEv2 proposal configuration sub-mode, configure a pseudorandom function
(PRF) for the proposal. This defines the hash size algorithm for the IKEv2.
In this example, the SHA-256 algorithm is added to the PRF algorithms configured for a1. Because the SHA-384 algorithm is configured by default, both the SHA-384 and SHA-256 algorithms are configured for IKEv2 proposal a1 after executing this step. Configuration of multiple PRF algorithms is allowed.
device(config-ike-proposal-a1)# prf sha256
- (Optional) In IKEv2 proposal configuration sub-mode, enter the
integritycommand followed by the encryption algorithm to configure an integrity algorithm for the proposal as shown in the following example.This step adds the SHA-256 algorithm to the integrity algorithms configured for the proposal a1. Because the SHA-384 algorithm is configured by default, both the SHA-384 and SHA-256 algorithms are configured for a1 after executing this step. Configuration of multiple integrity algorithms is allowed.
When you want to configure the SHA-256 algorithm only for the proposal, you must first add the SHA-256 algorithm and then remove the default algorithm by using the command
no integrity sha384.device(config-ike-proposal-a1)# integrity sha256
- (Optional) In IKEv2 proposal configuration sub-mode, enter the
encryptioncommand to configure an encryption algorithm for the proposal as shown in the following example.In the example, the AES-CBC-128 algorithm is added to the encryption algorithms configured for proposal a1. Because the AES-CBC-256 algorithm is configured by default, both the AES-CBC-256 and AES-CBC-128 algorithms are configured for IKEv2 Proposal a1 after executing this step. Configuration of multiple encryption algorithms is allowed.
When you want to configure the AES-CBC-128 algorithm only for the proposal, you must first add the AES-CBC-128 algorithm and then remove the default algorithm using the command
no encryption aes-cbc-256.device(config-ike-proposal-a1)# encryption aes-cbc-128
- Enter the
ikev2 policycommand in general configuration mode to designate an IKEv2 policy, to enter IKEv2 policy configuration mode, and to bind a pre-configured authentication proposal to protect IKE during negotiations.