IPv6 over IPsec Tunnels

IPv6 over IPsec tunnel is supported in this release.

Note: The following combinations are support between payload and tunnel type.
  • IPv4 payload over IPv4 tunnel
  • IPv6 payload over IPv6 tunnel
  • IPv6 payload over IPv4 tunnel

To configure the IPv6 over IPsec tunnels:

  1. Enter the tunnel mode ipsec ipv6 command to configure the underneath IPv6 tunnel source, IPv6 tunnel destination and the IKE policy is IPv6. Option of ipv6 match-address will be introduced to ikev2.

    device# configure terminal
    device(config)# interface tunnel1
    device(config-tnif-1)# tunnel source 30::1
    device(config-tnif-1)# tunnel destination 40::1
    device(config-tnif-1)# tunnel mode ipsec ipv6
    device(config-tnif-1)# tunnel protection ipsec profile prof-green
    device(config-tnif-1)# ipv6 add 90::1/64
    device(config-tnif-1)# exit
    

  2. Enter the ikev2 auth-proposal command to enter the pre-shared key and complete the Ikev2 authentication proposal.
    device(config)# ikev2 auth-proposal a12
    device(config-ike-auth-proposal-a12)# pre-shared-key 2 $MlVzZCFAbg==
    device(config-ike-auth-proposal-a12)# exit
    
  3. Enter the ipsec proposal command to configure the IPsec proposal, for example, to specify an encryption algorithm as shown.
    device(config)#ipsec proposal a12
    device(config-ipsec-proposal-a12)# encryption-algorithm aes-gcm-128
    device(config-ipsec-proposal-a12)# exit
    
  4. Configure the Ikev2 policy with address match.
    device(config)# ikev2 policy a12
    device(config-ike-policy-a12)# proposal a12
    device(config-ike-policy-a12)# match address-local 2001:100::1/64
    device(config-ike-policy-a12)# ipsec profile a12
    device(config-ipsec-profile-a12)# proposal a12
    device(config-ipsec-profile-a12)# ike-profile a12
    device(config-ipsec-profile-a12)# lifetime 1440
    device(config-ipsec-profile-a12)# replay-protection
    device(config-ipsec-profile-a12)# exit
    
  5. Configure the Ikev2 profile.
    device(config-ipsec-profile-a12)# ikev2 profile a12
    device(config-ipsec-profile-a12)# description ikeprofile12
    device(config-ipsec-profile-a12)# authentication a12
    device(config-ipsec-profile-a12)# lifetime 2880
    device(config-ipsec-profile-a12)# local-identifier key-id IPSEC-GREEN
    device(config-ipsec-profile-a12)# remote-identifier key-id IPSEC-BLUE
    device(config-ipsec-profile-a12)# match-identity local key-id IPSEC-GREEN
    device(config-ipsec-profile-a12)# match-identity remote key-id IPSEC-BLUE
    device(config-ipsec-profile-a12)# exit
    
  6. (Optional) Enter the show ikev2 proposal, show ikev2 profile, and show ikev2 policy commands to display the configuration.
    device(config)# show ikev2 proposal a12
    ================================================================
    Name                : a12
    Encryption          : aes256,aes128
    Integrity           : sha384,
    Prf                 : sha384,
    DH Group            : 384_ECP/Group 20,2048_MODP/Group 14,
    Ref Count           : 1
    
    device(config)# show ikev2 profile a12 
    ================================================================
    IKEv2 Profile       : a12
    Auth Profile        : a12
    Match Criteria      :
     Inside VRF         : any
      Local: 
       keyid IPSEC-X
      Remote: 
       keyid IPSEC-XX
    Local Identifier    : keyid IPSEC-GREEN
    Remote Identifier   : keyid IPSEC-BLUE
    Lifetime            : 172800 sec
    Keepalive Check     : 300 sec
    Ref Count           : 1
    
    device(config)# show ikev2 policy a12
    ================================================================
    Name                : a12
    Vrf                 : any
    Local Address/Mask  : 2001:100::1/64
    Proposal            : a12