OSPFv2

OSPFv2 protocol uses IPsec with IP ESP and HMAC-SHA-196, and is allowed in FIPS mode. OSPF allows peer-to-peer authentication or client-to-server authentication. You can apply OSPFv2 IPsec authentication at the interface level using commands similar to the following example.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ipv6 ospf authentication ipsec spi 256 esp sha1 1234567890123456789012345678901234567890

Use the following syntax to configure the IPsec-SHA1 key:

Syntax: ipv6 ospf authentication ipsec spi spinum esp sha1 key

Use the following syntax to remove the IPsec-SHA1 key configuration:

Syntax: no ipv6 ospf authentication ipsec spi spinum esp sha1 encrypt key

The key is retained even when unconfigured and appears in the running configuration as shown in the following example.

ICX7750-48C Router# show running-config interface ethernet 1/1/1
interface Ethernet 1/1/1
ipv6 address 2002::20/64
ipv6 ospf area 1
ipv6 ospf authentication ipsec spi 500 esp sha1 encrypt $Wnw4M09tWVd7UVp8ODNPbVlXe1FafDgzT21ZV3tRWnw4M09tWVd7UQ==

Related OSPFv2 authentication command options are available as shown in the following syntax statements.

Syntax: ip ospf authentication { hmac-sha-1 | hmac-sha-256 } key-id key-id-value key key-string

Syntax: no ip ospf authentication { hmac-sha-1 | hmac-sha-256 } key-id key-id-value key key-string

Syntax: ip ospf authentication keychain keychain-name

Syntax: no ip ospf authentication keychain keychain-name