Configuring IPsec on an OSPFv3 area
IPsec can be configured to secure communications on an OSPFv3 area.
Currently certain keyword parameters must be entered though only one keyword choice is possible for that parameter. For example, the only authentication algorithm is HMAC-SHA1-96, but you must nevertheless enter the sha1 keyword for this algorithm. Also, although ESP is currently the only authentication protocol, you must enter the esp keyword.
Note: When IPsec is configured for an area, the security policy is applied to all the interfaces
in the area.
- Enter the
configure terminalcommand to access global configuration mode. - Enter the
ip router-idcommand to specify the router ID. - Enter the
ipv6 router ospfcommand to enter OSPFv3 configuration mode and enable OSPFv3 on the device. - Enter
area authenticationipsec spi spi esp sha1, specifying an area, and enter a 40-character hexadecimal key.device(config-ospf6-router)# area 0 authentication ipsec spi 600 esp sha1 abcef12345678901234fedcba098765432109876
IPsec is configured in OSPv3 area 0 with a security parameter index (SPI) value of 600, and Hashed Message Authentication Code (HMAC) Secure Hash Algorithm 1 (SHA-1) authentication is enabled.
The following example enables HMAC SHA-1 authentication for the OSPFv3 area, setting an SPI value of 600.
device# configure terminal device(config)# ip router-id 10.11.12.13 device(config)# ipv6 router ospf device(config-ospf6-router)# area 0 authentication ipsec spi 600 esp sha1 abcef12345678901234fedcba098765432109876