OSPFv3

The OSPFv3 protocol uses IPsec with IP ESP and HMAC-SHA-196 and HMAC-SHA-256 and is allowed in FIPS mode. OSPF allows peer-to-peer authentication or client-to-server authentication. You can apply OSPFv3 IPsec authentication at the interface level using commands similar to the following example.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ipv6 ospf authentication ipsec spi 256 esp sha1 1234567890123456789012345678901234567890

Use the following syntax to configure the IPsec-SHA1 key:

Syntax: ipv6 ospf authentication ipsec spi spinum esp sha1 key

Use the following syntax to remove the IPsec-SHA1 key configuration:

Syntax: no ipv6 ospf authentication ipsec spi spinum esp sha1 encrypt key

The key is retained when unconfigured and appears in the running configuration as shown in the following example.

ICX7750-48C Router# show running-config interface ethernet 1/1/1
interface Ethernet 1/1/1
ipv6 address 2002::20/64
ipv6 ospf area 1
ipv6 ospf authentication ipsec spi 500 esp sha1 encrypt $Wnw4M09tWVd7UVp8ODNPbVlXe1FafDgzT21ZV3tRWnw4M09tWVd7UQ==key

Related OSPFv3 authentication command options are available as shown in the following syntax statements.

Syntax: ipv6 ospf authentication { hmac-sha-1 | hmac-sha-256 } key-id key-id-value key key-string

Syntax: no ipv6 ospf authentication { hmac-sha-1 | hmac-sha-256 } key-id key-id-value key key-string

Syntax: ipv6 ospf authentication keychain keychain-name

Syntax: no ipv6 ospf authentication keychain keychain-name

The following commands are entered in IPv6 OSPF router configuration mode.

Syntax: area area-id authentication { hmac-sha-1 | hmac-sha-256 } key-id key-id-value key key-string

Syntax: no area area-id authentication { hmac-sha-1 | hmac-sha-256 } key-id key-id-value key key-string

Syntax: area area-id authentication keychain keychain-name

Syntax: no area area-id authentication keychain keychain-name