ipv6 ospf authentication ipsec spi
ipv6 ospf authentication ipsec spi
value
esp
sha1
key
[
no-encrypt
]
key
}
no ipv6 ospf authentication spi
Authentication is disabled.
The 40-hexadecimal character key is encrypted by default. Use the no-encrypt parameter to disable encryption.
- esp
- Specifies Encapsulating Security Payload (ESP) as the protocol to provide packet-level security. This is the only option currently available.
- sha1
- Enables Hashed Message Authentication Code (HMAC) Secure Hash Algorithm 1 (SHA-1) authentication.
- key
- Number used in the calculation of the message digest. The 40 hexadecimal character key is stored in encrypted format by default.
Interface subtype configuration mode
The 40 hexadecimal character key is encrypted by default. The system adds the following in the configuration to indicate that the key is encrypted:
- encrypt = the key string uses proprietary simple cryptographic 2-way algorithm
- encryptb64 = the key string uses proprietary base64 cryptographic 2-way algorithm
To change an existing key, you must specify a different SPI value to that of the value already configured.
Theno form of the command removes the SPI value from the interface.
The following example enables ESP and HMAC-SHA-1 on a specified OSPFv3 virtual Ethernet (VE) interface.
device# configure terminal device(config)# interface ve 1 device(config-vif-1)# ipv6 ospf area 0 device(config-vif-1)# ipv6 ospf authentication ipsec spi 512 esp sha1 abcef12345678901234fedcba098765432109876