area virtual-link authentication ipsec (OSPFv3)
area
{
ip-addr
|
decimal
}
virtual-link
E.F.G.H
authentication
ipsec
spi
value
esp
sha1
key
[
no-encrypt
]
key
no area
{
IPv6 address
|
decimal
}
virtual-link
E.F.G.H
authentication
ipsec
spi
spi
Authentication is not enabled on a virtual-link.
The 40 hexadecimal character key is encrypted by default. Use the no-encrypt parameter to disable encryption.
- esp
- Specifies Encapsulating Security Payload (ESP) as the protocol to provide packet-level security. This is the only option currently available.
- sha1
- Enables Hashed Message Authentication Code (HMAC) Secure Hash Algorithm 1 (SHA-1) authentication on the OSPFv3 area.
- key
- Number used in the calculation of the message digest. The 40 hexadecimal character key is stored in encrypted format by default.
OSPFv3 router configuration mode
OSPFv3 router VRF configuration mode
Currently certain keyword parameters must be entered though only one keyword choice is possible for that parameter. For example, the only authentication algorithm is HMAC-SHA1-96, but you must nevertheless enter the sha1 keyword for this algorithm. Also, although ESP is currently the only authentication protocol, you must enter the esp keyword.
The
no form of the command removes authentication from the virtual-links in the area.
The following example configures IPsec on a virtual link in an OSPFv3 area, and encryption is disabled.
device# configure terminal device(config)# ip router-id 10.1.2.2 device(config)# ipv6 router ospf device(config-ospf6-router)# area 2 virtual-link 10.1.2.2 authentication ipsec spi 600 esp sha1 no-encrypt 1134567890223456789012345678901234567890