Configuring an IKEv2 Authentication Proposal for Use in an IPsec Profile
Follow these steps to configure an IKEv2 authentication proposal.
- Based on your certification method, do one of the following:
- To use a pre-defined shared secret (PSK), configure an IKEv2 authentication proposal.
Note: You must define a pre-shared key in Common Criteria mode, as no default value is configured. A warning message is displayed if no pre-shared key has been defined in the authentication proposal.
- For X.509 certification, configure a PKI trustpoint.
The following example provides command syntax for specifying a pre-shared key.device# configure terminal device(config)# ikev2 auth-proposal < proposalname > device(config-ike-auth-proposalname)# pre-shared-key < valid-key > device(config-ike-auth-proposalname)# exit
Note: Valid keys must be at least eight characters in length. They must contain a mix of at least three character types (uppercase alpha characters, lowercase alpha characters, numeric characters, non-alpha ASCII characters). The first character must not be the only uppercase alpha character in the key, and the last character must not be the only numeric character in the key. The system returns an error if the pre-shared key is not valid.The following example defines a valid pre-shared key for use with IKEv2 authentication proposal "withKey-L2."device# configure terminal device(config)# ikev2 auth-proposal withKeyL2 device(config-ike-auth-withKeyL2)# pre-shared-key m!XYZ#79L device(config-ike-auth-withKeyL2)# exit
Note: Bit-based pre-shared key are supported on ICX 7450 devices. To specify a bit-based preshared key in the IKE auth-proposal, enter auth-proposal bit-based configuration submode, and add the prefix "0x" to a hexadecimal value.The following example creates a bit-based pre-shared key on an ICX 7450 device.ICX_7450_device# configure terminal ICX_7450_device(config)# ike auth-proposal bit-based ICX_7450_device(config-ike-auth-proposal-bit-based)# 0xabcd10908
The following example provides command syntax for specifying a trustpoint for use with X.509 certification.device# configure terminal device(config)# ikev2 auth-proposal < proposalname > device(config-ike-auth-proposalname)# pki-trustpoint < trustpointname > [ sign | verify ]
The following example configures a PKI trustpoint for the Certificate Authority for use in X.509 certification. In the example, the server abcd is established as the PKI trustpoint for both certificate signature and verification.device# configure terminal device(config)# ikev2 auth-proposal abcd-CA device(config-ike-auth-proposal-abcd-CA)# pki-trustpoint abcd-CA sign device(config-ike-auth-proposal-abcd-CA)# pki-trustpoint abcd-CA verify
Note: A full example of setting up for X.509 certification is presented in the section "Configuration example: creating an IPsec profile for tunnels that use X.509 certificates." - To use a pre-defined shared secret (PSK), configure an IKEv2 authentication proposal.
- Configure an IKEv2 profile that uses IP addresses or distinguished names as local
and remote identifiers.
Note: DN is the subject name of the PKI local certificate. Domain name may contain common name, state, country, organization name and organization unit name of the entity for which the PKI certificate is presented.The following example provides command syntax.
device(config)# ikev2 profile < profilename > device(config-ike-profile-profilename)# authentication < auth-proposalname > device(config-ike-profile-profilename)# local-identifier address < ip-address | ipv6-address | dn > device(config-ike-profile-profilename)# remote-identifier address < ip-address | ipv6-address | dn > device(config-ike-profile-profilename)# match-identity local address < ip-address | ipv6-address | dn > device(config-ike-profile-profilename)# match-identity remote address < ip-address | ipv6-address | dn > device(config-ike-profile-profilename)# exit
The example below uses IP addresses as identifiers.device(config)# ikev2 profile withKeyL2 device(config-ike-profile-withKeyL2)# authentication withKeyL2 device(config-ike-profile-withKeyL2)# local-identifier address 15.1.1.2 device(config-ike-profile-withKeyL2)# remote-identifier address 15.1.1.1 device(config-ike-profile-withKeyL2)# match-identity local address 15.1.1.2 device(config-ike-profile-withKeyL2)# match-identity remote address 15.1.1.1 device(config-ike-profile-withKeyL2)# exit
The following example uses distinguished names as identifiers.device(config)# ikev2 profile with_standalone device(config-ike-profile-with_standalone)# authentication withCert device(config-ike-profile-with_standalone)# local-identifier dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT" device(config-ike-profile-with_standalone)# remote-identifier dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME" device(config-ike-profile-with_standalone)# match-identity local dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT" device(config-ike-profile-with_standalone)# match-identity remote dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME" device(config-ike-profile-with_standalone)# exit
- Configure an IPsec profile that uses a previously configured IKEv2 profile.
device(config)# ipsec profile withKeyL2 device(config-ipsec-profile-withKeyL2)# ike-profile withKeyL2 <--- pre-configured IKEv2 profile device(config-ipsec-profile-withKeyL2)# exit
Note: To use the IPsec profile, you must associate it with a specific tunnel. This process is described in the section "Configuring an IPv4 or IPv6 IPsec tunnel."
The following example configures IPsec tunnel 1 to use an IPsec profile that references IKEv2 settings from a specific IKEv2 profile.
device# configure terminal device(config)# ikev2 auth-proposal withKeyL2 device(config-ike-auth-withKeyL2)# pre-shared-key 2 device(config-ike-auth-withKeyL2)# exit device(config)# ikev2 profile withKeyL2 device(config-ike-profile-withKeyL2)# authentication withKeyL2 <--- authentication proposal name device(config-ike-profile-withKeyL2)# local-identifier address 15.1.1.2 device(config-ike-profile-withKeyL2)# remote-identifier address 15.1.1.1 device(config-ike-profile-withKeyL2)# match-identity local address 15.1.1.2 device(config-ike-profile-withKeyL2)# match-identity remote address 15.1.1.1 device(config-ike-profile-withKeyL2)# exit device(config)# ipsec profile withKeyL2 device(config-ipsec-profile-withKeyL2)# ike-profile withKeyL2 <--- previously configured IKEv2 profile device(config-ipsec-profile-withKeyL2)# exit device(config)# interface tunnel 1 device(config-tnif-1)# interface tunnel 1 device(config-tnif-1)# tunnel mode ipsec ipv4 device(config-tnif-1)# tunnel protection ipsec profile withKeyL2 <---- previously configured IPsec profile device(config-tnif-1)# tunnel source 15.1.1.2 device(config-tnif-1)# tunnel destination 15.1.1.1 device(config-tnif-1)# ip address 15.15.15.1 255.255.255.0