area authentication (IPsec)

Enables IPSec authentication for an OSPF Version 3 (OSPFv3) area.
Syntax
area { ip-address | decimal } authentication ipsec spi value esp sha1 key
area { ip-address | decimal } authentication ipsec spi value esp sha1 no-encrypt key
no area { ipv6-address | decimal } authentication ipsec spi value
Command Default

Authentication is not enabled on an area.

The key is stored in encrypted format by default.

Parameters
ip-address
Area ID in IP address format.
decimal
Area ID in decimal format.
ipsec

Specifies that IP security (IPsec) is the protocol that authenticates the packets.

spi
Specifies the Security Policy Index (SPI).
value
Specifies the SPI value. Valid values range from decimal numbers 256 through 4294967295. The near-end and far-end values must be the same.
esp
Specifies Encapsulating Security Payload (ESP) as the protocol to provide packet-level security. This is the only option currently available.
sha1
Enables Hashed Message Authentication Code (HMAC) Secure Hash Algorithm 1 (SHA-1) authentication on the OSPFv3 area.
key
Number used in the calculation of the message digest. The 40 hexadecimal character key is stored in encrypted format by default.
no-encrypt
The 40-character key is not encrypted upon either its entry or its display.
key
The 40 hexadecimal character key.
Modes

OSPFv3 router configuration mode

OSPFv3 router VRF configuration mode

Usage Guidelines

The 40 hexadecimal character key is encrypted by default. The system adds the following in the configuration to indicate that the key is encrypted:

  • encrypt = the key string uses proprietary simple cryptographic 2-way algorithm
  • encryptb64 = the key string uses proprietary base64 cryptographic 2-way algorithm

Use the no-encrypt parameter to disable encryption.

Currently certain keyword parameters must be entered though only one keyword choice is possible for that parameter. For example, the only authentication algorithm is HMAC-SHA1-96, but you must nevertheless enter the sha1 keyword for this algorithm. Also, although ESP is currently the only authentication protocol, you must enter the esp keyword.

The no form of the command removes an authentication specification for an area from the configuration.

Examples

The following example enables esp and SHA-1 authentication for an OSPFv3 area, setting a SPI value of 900.

device# configure terminal
device(config)# ip router-id 10.1.2.3 
device(config)# ipv6 router ospf 
device(config-ospf6-router)# area 0 authentication ipsec spi 750 esp sha1 abcef12345678901234fedcba098765432109876