area virtual-link authentication ipsec (OSPFv3)

Enables IPsec (IP Security) authentication for virtual links in an OSPFv3 area.
Syntax
area { ip-addr | decimal } virtual-link E.F.G.H authentication ipsec spi value esp sha1 key [ no-encrypt ] key
no area { IPv6 address | decimal } virtual-link E.F.G.H authentication ipsec spi spi
Command Default

Authentication is not enabled on a virtual-link.

The 40 hexadecimal character key is encrypted by default. Use the no-encrypt parameter to disable encryption.

Parameters
ip-addr
Area address in IP address format.
decimal
Area address in decimal format.
E.F.G.H
ID of the OSPFv3 device at the remote end of the virtual link.
ipsec

Specifies that IP security (IPsec) is the protocol that authenticates the packets.

spi
Specifies the Security Policy Index (SPI).
value
Specifies the SPI value. Valid values range from decimal numbers 256 through 4294967295. The near-end and far-end values must be the same.
esp
Specifies Encapsulating Security Payload (ESP) as the protocol to provide packet-level security. This is the only option currently available.
sha1
Enables Hashed Message Authentication Code (HMAC) Secure Hash Algorithm 1 (SHA-1) authentication on the OSPFv3 area.
key
Number used in the calculation of the message digest. The 40 hexadecimal character key is stored in encrypted format by default.
no-encrypt
The 40-character key is not encrypted upon either its entry or its display.
key
The 40 hexadecimal character key.
Modes

OSPFv3 router configuration mode

OSPFv3 router VRF configuration mode

Usage Guidelines

Currently certain keyword parameters must be entered though only one keyword choice is possible for that parameter. For example, the only authentication algorithm is HMAC-SHA1-96, but you must nevertheless enter the sha1 keyword for this algorithm. Also, although ESP is currently the only authentication protocol, you must enter the esp keyword.

The no form of the command removes authentication from the virtual-links in the area.

Examples

The following example configures IPsec on a virtual link in an OSPFv3 area, and encryption is disabled.

device# configure terminal
device(config)# ip router-id 10.1.2.2
device(config)# ipv6 router ospf
device(config-ospf6-router)# area 2 virtual-link 10.1.2.2 authentication ipsec spi 600 esp sha1 no-encrypt 1134567890223456789012345678901234567890