Configuring an IKEv2 Proposal
Internet Key Exchange version 2 (IKEv2) proposal configuration sets parameters that
are exchanged in the first phase of IKEv2 peer negotiations. After configuration,
an IKEv2 proposal must be attached to an IKEv2 policy for use in IKEv2 negotiations.
- From privileged EXEC mode, enter global configuration mode.
- Create an IKEv2 proposal and enter configuration mode for the proposal.
- Configure an encryption algorithm for the proposal.
This step adds the AES-CBC-128 algorithm to the encryption algorithms configured for prop_RTB. Because the AES-CBC-256 algorithm is configured by default, both the AES-CBC-256 and AES-CBC-128 algorithms are configured for prop_RTB after executing this step. Configuration of multiple encryption algorithms is allowed.
- Configure an integrity algorithm for the proposal.
This step adds the SHA-256 algorithm to the integrity algorithms configured for prop_RTB. Because the SHA-384 algorithm is configured by default, both the SHA-384 and SHA-256 algorithms are configured for prop_RTB after executing this step. Configuration of multiple integrity algorithms is allowed.
- Configure a pseudorandom function (PRF) for the proposal.
This step adds the SHA-256 algorithm to the PRF algorithms configured for prop_RTB. Because the SHA-384 algorithm is configured by default, both the SHA-384 and SHA-256 algorithms are configured for prop_RTB after executing this step. Configuration of multiple PRF algorithms is allowed.
- Configure a DH group for the proposal.
This step adds DH group 19 to the DH groups configured for prop_RTB. Because DH group 20 is configured by default, both DH groups (19 and 20) are configured for prop_RTB after executing this step. Configuration of multiple DH groups is allowed.
- Return to privileged EXEC mode.
- Verify the IKEv2 proposal configuration.
The following example shows how to create and configure an IKEv2 proposal named prop-RTB. This example also shows how to remove default configurations; that is, by first configuring an alternate algorithm or DH group and then removing the default configuration.
device# configure terminal device(config)# ikev2 proposal prop_RTB device(config-ike-proposal-prop_RTB)# encryption aes-cbc-128 device(config-ike-proposal-prop_RTB)# no encryption aes-cbc-256 device(config-ike-proposal-prop_RTB)# integrity sha256 device(config-ike-proposal-prop_RTB)# no intergrity sha384 device(config-ike-proposal-prop_RTB)# prf sha256 device(config-ike-proposal-prop_RTB)# no prf sha384 device(config-ike-proposal-prop_RTB)# dhgroup 19 device(config-ike-proposal-prop_RTB)# no dhgroup 20 device(config-ike-proposal-prop_RTB)# end
To use the IKEv2 proposal in IKEv2 negotiations, attach it to an IKEv2 policy by using
the
proposal command in IKEv2 policy configuration mode.