IPv6 over IPsec Tunnels
IPv6 over IPsec tunnel is supported in this release.
To configure the IPv6 over IPsec tunnels:
-
Enter the
tunnel mode ipsec ipv6command to configure the underneath IPv6 tunnel source, IPv6 tunnel destination and the IKE policy is IPv6. Option of ipv6 match-address will be introduced to ikev2.device# configure terminal device(config)# interface tunnel1 device(config-tnif-1)# tunnel source 30::1 device(config-tnif-1)# tunnel destination 40::1 device(config-tnif-1)# tunnel mode ipsec ipv6 device(config-tnif-1)# tunnel protection ipsec profile prof-green device(config-tnif-1)# ipv6 add 90::1/64 device(config-tnif-1)# exit
- Enter the
ikev2 auth-proposalcommand to enter the pre-shared key and complete the Ikev2 authentication proposal.device(config)# ikev2 auth-proposal a12 device(config-ike-auth-proposal-a12)# pre-shared-key 2 $MlVzZCFAbg== device(config-ike-auth-proposal-a12)# exit
- Enter the
ipsec proposalcommand to configure the IPsec proposal, for example, to specify an encryption algorithm as shown.device(config)#ipsec proposal a12 device(config-ipsec-proposal-a12)# encryption-algorithm aes-gcm-128 device(config-ipsec-proposal-a12)# exit
- Configure the Ikev2 policy with address match.
device(config)# ikev2 policy a12 device(config-ike-policy-a12)# proposal a12 device(config-ike-policy-a12)# match address-local 2001:100::1/64 device(config-ike-policy-a12)# ipsec profile a12 device(config-ipsec-profile-a12)# proposal a12 device(config-ipsec-profile-a12)# ike-profile a12 device(config-ipsec-profile-a12)# lifetime 1440 device(config-ipsec-profile-a12)# replay-protection device(config-ipsec-profile-a12)# exit
- Configure the Ikev2 profile.
device(config-ipsec-profile-a12)# ikev2 profile a12 device(config-ipsec-profile-a12)# description ikeprofile12 device(config-ipsec-profile-a12)# authentication a12 device(config-ipsec-profile-a12)# lifetime 2880 device(config-ipsec-profile-a12)# local-identifier key-id IPSEC-GREEN device(config-ipsec-profile-a12)# remote-identifier key-id IPSEC-BLUE device(config-ipsec-profile-a12)# match-identity local key-id IPSEC-GREEN device(config-ipsec-profile-a12)# match-identity remote key-id IPSEC-BLUE device(config-ipsec-profile-a12)# exit
- (Optional) Enter the
show ikev2 proposal,show ikev2 profile, andshow ikev2 policycommands to display the configuration.device(config)# show ikev2 proposal a12 ================================================================ Name : a12 Encryption : aes256,aes128 Integrity : sha384, Prf : sha384, DH Group : 384_ECP/Group 20,2048_MODP/Group 14, Ref Count : 1 device(config)# show ikev2 profile a12 ================================================================ IKEv2 Profile : a12 Auth Profile : a12 Match Criteria : Inside VRF : any Local: keyid IPSEC-X Remote: keyid IPSEC-XX Local Identifier : keyid IPSEC-GREEN Remote Identifier : keyid IPSEC-BLUE Lifetime : 172800 sec Keepalive Check : 300 sec Ref Count : 1 device(config)# show ikev2 policy a12 ================================================================ Name : a12 Vrf : any Local Address/Mask : 2001:100::1/64 Proposal : a12