ipv6 ospf authentication ipsec spi

Specifies the IP security (IPsec) security policy index (SPI) value for an OSPFv3 interface.
Syntax
ipv6 ospf authentication ipsec spi value esp sha1 key [ no-encrypt ] key }
no ipv6 ospf authentication spi
Command Default

Authentication is disabled.

The 40-hexadecimal character key is encrypted by default. Use the no-encrypt parameter to disable encryption.

Parameters
ipsec

Specifies IPsec as the authentication protocol.

spi
Specifies the Security Policy Index (SPI).
value
Specifies the SPI value. Valid values range from decimal numbers 256 through 4294967295. The near-end and far-end values must be the same.
esp
Specifies Encapsulating Security Payload (ESP) as the protocol to provide packet-level security. This is the only option currently available.
sha1
Enables Hashed Message Authentication Code (HMAC) Secure Hash Algorithm 1 (SHA-1) authentication.
key
Number used in the calculation of the message digest. The 40 hexadecimal character key is stored in encrypted format by default.
no-encrypt
The 40-character key is not encrypted upon either its entry or its display.
key
The 40 hexadecimal character key.
Modes

Interface subtype configuration mode

Usage Guidelines

The 40 hexadecimal character key is encrypted by default. The system adds the following in the configuration to indicate that the key is encrypted:

  • encrypt = the key string uses proprietary simple cryptographic 2-way algorithm
  • encryptb64 = the key string uses proprietary base64 cryptographic 2-way algorithm

To change an existing key, you must specify a different SPI value to that of the value already configured.

Theno form of the command removes the SPI value from the interface.

Examples

The following example enables ESP and HMAC-SHA-1 on a specified OSPFv3 virtual Ethernet (VE) interface.

device# configure terminal
device(config)# interface ve 1
device(config-vif-1)# ipv6 ospf area 0
device(config-vif-1)# ipv6 ospf authentication ipsec spi 512 esp sha1 abcef12345678901234fedcba098765432109876