Supported Features and Functionality

The features in the following table are supported for IP unicast communications over IPsec.

Supported Features and Functionality for IPsec Unicast Communications

Feature IPv4
Static point-to-point tunnel setup between two IP endpoints using IKEv2 Yes
Dead Peer Detection (DPD) using IKEv2 Keep Alive Yes
Configurable options for tunnel elements, such as IKE SA Lifetime, IKEv2 Keep Alive Yes
VRF Forwarding
Source and destination addresses of the outer header of the tunneled packet can be:
  • In a different VRF from the VRF for which the packet is received (including the default global VRF)
  • In the same VRF that receives the packet
Yes
Configurable VRF for tunnel (outer IP header for ESP packet) Yes
Multi-VRF forwarding to same remote end point

(Multiple IPsec tunnels are set up on the same remote endpoint, one for each inner VRF. Also, a separate IKE session is set up for each IPsec tunnel.)

Yes
ECMP Yes
LAG Yes
Protocols
Encapsulation Security Protocol (ESP) in tunnel mode Yes
IKE (for tunnel setup and key management) IKEv2 only
Protocols and Features Supported over IPsec Tunnels
DHCP relay Yes
OSPFv2 Yes (OSPFv2 only)
Path MTU discovery Yes
ping Yes
RIPv1 and RIPv2 Yes (RIPv1 and RIPv2 only)
SSH Yes
Telnet Yes
traceroute Yes
Cryptography
Suite B cryptography to provide Top Secret, 256-bit security Yes
AES-CBC-128 and AES-CBC-256 (confidentiality for IKEv2) Yes
Diffie-Hellman groups (key exchange). The default DH group is 20. Alternate options include groups 14 and 19. Multiple DH groups may be configured; when multiple groups are configured, the highest DH group configured on both the remote and peer devices is selected. Yes
HMAC-SHA-256-128 and HMAC-SHA-384-192 for integrity Yes
HMAC-SHA-256 and HMAC-SHA-384 for pseudorandom function (PRF) Yes
ICX7400-SERVICE-MOD hardware-based encryption and decryption (no encryption or decryption is done by software) Yes
AES-GCM-128 and AES-GCM-256

For ESP combined-mode authentication, encryption, and decryption of data

Yes
Line rate support (encryption and decryption at 10 Gbps full duplex) Yes
Line rate support (authentication at 10 Gbps full duplex) Yes
Integrity
Replay protection Yes
Extended sequence numbering (ESN) Yes
Interface-to-Interface Traffic Forwarding (IP Packets)
Jumbo Frame support (IPv4 MTU of 9159 is supported) Yes
Physical interface to IPsec tunnel interface Yes
VE interface to IPsec tunnel interface Yes
GRE tunnel interface to IPSec tunnel interface Yes
IPsec IPv4 tunnel interface to IPv4 IPsec tunnel interface (tunnel stitching)
Note: End-to-end traffic throughput is 5 Gbps full duplex because traffic to the ICX7400-SERVICE-MOD module is doubled at the router where a tunnel re-enters another tunnel.
Yes
IPsec Statistics
Packet counts and byte counts, including:
  • Transmit and Receive packet counts for each tunnel
  • Transmit and Receive byte counts for each tunnel
Yes
IKEv2 packet counters, including IKEv2 Keep Alive packets and IKEv2 error packets Yes
Traps and Syslogs
Up and Down traps and syslogs Yes
Syslogs for IKEv2 session-establishment errors Yes