OSPFv3
The OSPFv3 protocol uses IPsec with IP ESP and HMAC-SHA-196 and HMAC-SHA-256 and is allowed in FIPS mode. OSPF allows peer-to-peer authentication or client-to-server authentication. You can apply OSPFv3 IPsec authentication at the interface level using commands similar to the following example.
device# configure terminal device(config)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# ipv6 ospf authentication ipsec spi 256 esp sha1 1234567890123456789012345678901234567890
Use the following syntax to configure the IPsec-SHA1 key:
Syntax:
ipv6 ospf authentication ipsec spi
spinum
esp sha1
key
Use the following syntax to remove the IPsec-SHA1 key configuration:
Syntax:
no ipv6 ospf authentication ipsec spi
spinum
esp sha1
encrypt
key
The key is retained when unconfigured and appears in the running configuration as shown in the following example.
ICX7750-48C Router# show running-config interface ethernet 1/1/1 interface Ethernet 1/1/1 ipv6 address 2002::20/64 ipv6 ospf area 1 ipv6 ospf authentication ipsec spi 500 esp sha1 encrypt $Wnw4M09tWVd7UVp8ODNPbVlXe1FafDgzT21ZV3tRWnw4M09tWVd7UQ==key
Related OSPFv3 authentication command options are available as shown in the following syntax statements.
Syntax:
ipv6 ospf authentication
{
hmac-sha-1
|
hmac-sha-256
}
key-id
key-id-value
key
key-string
Syntax:
no ipv6 ospf authentication
{
hmac-sha-1
|
hmac-sha-256
}
key-id
key-id-value
key
key-string
Syntax:
ipv6 ospf authentication
keychain
keychain-name
Syntax:
no ipv6 ospf authentication
keychain
keychain-name
The following commands are entered in IPv6 OSPF router configuration mode.
Syntax:
area
area-id
authentication
{
hmac-sha-1
|
hmac-sha-256
}
key-id
key-id-value
key
key-string
Syntax:
no area
area-id
authentication
{
hmac-sha-1
|
hmac-sha-256
}
key-id
key-id-value
key
key-string
Syntax:
area
area-id
authentication
keychain
keychain-name
Syntax:
no area
area-id
authentication
keychain
keychain-name