Configuring an IKEv2 Authentication Proposal
Internet Key Exchange version 2 (IKEv2) authentication proposal configuration sets
parameters that are used to authenticate IKEv2 peer devices. After configuration,
an IKEv2 authentication proposal must be attached to an IKEv2 profile for use in IKEv2
negotiations.
- Method for local device authentication: pre-shared
- Method for remote device authentication: pre-shared
- Pre-shared key: $QG5HTT1Ebk1TVW5NLWIhVW5ATVMhLS0rc1VA
When the default IKEv2 authentication proposal is not acceptable, perform the following task to configure an IKEv2 authentication proposal.
- From privileged EXEC mode, enter global configuration mode.
- Create an IKEv2 authentication proposal and enter configuration mode for the proposal.
- Specify an authentication method for local device authentication.
This example specifies using a pre-shared key for local device authentication.
- Specify an authentication method for remote device authentication.
This example specifies using a pre-shared key for remote device authentication.
- (Optional) There is a default pre-shared key that is assigned to an IKEv2 authentication
proposal. Use the
pre-shared-keycommand to specify an alternate pre-shared key. The following example configures a text-based pre-shared key (ps_key) for the proposal. - Return to privileged EXEC mode.
- Verify the IKEv2 authentication proposal configuration.
device# show ikev2 auth-proposal auth_blue ========================================================================= Ikev2 Auth-Proposal : auth_blue Local Auth Method : pre_shared Remote Auth Method : pre_shared pre-share-key : $cTJkQ1x4Wnx7UQ==
The following example creates and configures an IKEv2 authentication proposal named auth_blue.
device# configure terminal device(config)# ikev2 auth-proposal auth_blue device(config-ike-auth-proposal-auth_blue)# method local pre-shared device(config-ike-auth-proposal-auth_blue)# method remote pre-shared device(config-ike-auth-proposal-auth_blue)# pre-shared-key ps_key device(config-ike-auth-proposal-auth_blue)# end
To use the IKEv2 authentication proposal in IKEv2 negotiations, attach it to an IKEv2
profile by using the
authentication command in IKEv2 profile configuration mode.