area authentication (IPsec)
area
{
ip-address
|
decimal
}
authentication
ipsec
spi
value
esp
sha1
key
area
{
ip-address
|
decimal
}
authentication
ipsec
spi
value
esp
sha1
no-encrypt
key
no area
{
ipv6-address
|
decimal
}
authentication
ipsec
spi
value
Authentication is not enabled on an area.
The key is stored in encrypted format by default.
- esp
- Specifies Encapsulating Security Payload (ESP) as the protocol to provide packet-level security. This is the only option currently available.
- sha1
- Enables Hashed Message Authentication Code (HMAC) Secure Hash Algorithm 1 (SHA-1) authentication on the OSPFv3 area.
- key
- Number used in the calculation of the message digest. The 40 hexadecimal character key is stored in encrypted format by default.
OSPFv3 router configuration mode
OSPFv3 router VRF configuration mode
The 40 hexadecimal character key is encrypted by default. The system adds the following in the configuration to indicate that the key is encrypted:
- encrypt = the key string uses proprietary simple cryptographic 2-way algorithm
- encryptb64 = the key string uses proprietary base64 cryptographic 2-way algorithm
Use the no-encrypt parameter to disable encryption.
Currently certain keyword parameters must be entered though only one keyword choice is possible for that parameter. For example, the only authentication algorithm is HMAC-SHA1-96, but you must nevertheless enter the sha1 keyword for this algorithm. Also, although ESP is currently the only authentication protocol, you must enter the esp keyword.
The
no form of the command removes an authentication specification for an area from the
configuration.
The following example enables esp and SHA-1 authentication for an OSPFv3 area, setting a SPI value of 900.
device# configure terminal device(config)# ip router-id 10.1.2.3 device(config)# ipv6 router ospf device(config-ospf6-router)# area 0 authentication ipsec spi 750 esp sha1 abcef12345678901234fedcba098765432109876