Configuring IPsec on an OSPFv3 interface
For IPsec to work, the IPsec configuration must be the same on all the routers to which an interface connects.
Currently certain keyword parameters must be entered though only one keyword choice is possible for that parameter. For example, the only authentication algorithm is HMAC-SHA1-96, but you must nevertheless enter the sha1 keyword for this algorithm. Also, although ESP is currently the only authentication protocol, you must enter the esp keyword.
- Enter the
configure terminalcommand to access global configuration mode. - Enter the
interfacecommand and specify an interface. - Enter the
ipv6 ospf areacommand to assign a specified area to the interface. - Enter
ipv6 ospf authenticationipsec spi value esp sha1 and specify a 40-character hexadecimal key.device(config-vif-1)# ipv6 ospf authentication ipsec spi 512 esp sha1 abcef12345678901234fedcba098765432109876
IPsec is configured on the specified interface with a security parameter index (SPI) value of 512, and the Encapsulating Security Payload (ESP) protocol is selected. Secure Hash Algorithm 1 (SHA-1) authentication is enabled.
The following example enables ESP and SHA-1 on a specified OSPFv3 virtual Ethernet (VE) interface.
device# configure terminal device(config)# interface ve 1 device(config-vif-1)# ipv6 ospf area 0 device(config-vif-1)# ipv6 ospf authentication ipsec spi 512 esp sha1 abcef12345678901234fedcba098765432109876