Configuring HMAC-SHA-1 or HMAC-SHA-256 Authentication on an OSPFv3 Area

To configure an OSPFv3 area so all devices within the area use HMAC-SHA-1 or HMAC-SHA-256 authentication, complete the following steps.
  1. Enter the configure terminal command to access global configuration mode.
    device# configure terminal
  2. Enter the ip router-id command to specify the required router.
    device(config)# ip router-id 10.1.1.1
  3. Enter the ipv6 router ospf command to enter OSPFv3 configuration mode and enable OSPFv3 on the device.
    device(config)# ipv6 router ospf
  4. Enter the area area-ID authentication command, with the required authentication option and parameters. The following example enables HMAC-SHA-1 authentication with key ID 10 and key string "mypasswordkey".
    device(config-ospf6-router)# area 1 authentication hmac-sha-1 key-id 10 key mypasswordkey
Note: This configuration instructs all interfaces within the area to use HMAC-SHA-1 or HMAC-SHA-256 authentication. It is possible to remove this configuration from individual interfaces using the ipv6 ospf authentication disable command on the required interface.

The following example enables HMAC-SHA-1 authentication using the key ID 10 and key string "mypasswordkey" on the specified area.

device# configure terminal
device(config)# ip router-id 10.1.1.1
device(config)# ipv6 router ospf
device(config-ospf6-router)# area 1 authentication hmac-sha-1 key-id 10 key mypasswordkey