The features in the following table are supported for IP unicast communications over
IPsec.
Supported Features and Functionality for IPsec Unicast Communications
Feature
IPv4
Static point-to-point tunnel setup between two IP endpoints using IKEv2
Yes
Dead Peer Detection (DPD) using IKEv2 Keep Alive
Yes
Configurable options for tunnel elements, such as IKE SA Lifetime, IKEv2 Keep Alive
Yes
VRF Forwarding
Source and destination addresses of the outer header of the tunneled packet can be:
In a different VRF from the VRF for which the packet is received (including the default
global VRF)
In the same VRF that receives the packet
Yes
Configurable VRF for tunnel (outer IP header for ESP packet)
Yes
Multi-VRF forwarding to same remote end point
(Multiple IPsec tunnels are set up on the same remote endpoint, one for each inner
VRF. Also, a separate IKE session is set up for each IPsec tunnel.)
Yes
ECMP
Yes
LAG
Yes
Protocols
Encapsulation Security Protocol (ESP) in tunnel mode
Yes
IKE (for tunnel setup and key management)
IKEv2 only
Protocols and Features Supported over IPsec Tunnels
DHCP relay
Yes
OSPFv2
Yes (OSPFv2 only)
Path MTU discovery
Yes
ping
Yes
RIPv1 and RIPv2
Yes (RIPv1 and RIPv2 only)
SSH
Yes
Telnet
Yes
traceroute
Yes
Cryptography
Suite B cryptography to provide Top Secret, 256-bit security
Yes
AES-CBC-128 and AES-CBC-256 (confidentiality for IKEv2)
Yes
Diffie-Hellman groups (key exchange). The default DH group is 20. Alternate options
include groups 14 and 19. Multiple DH groups may be configured; when multiple groups
are configured, the highest DH group configured on both the remote and peer devices
is selected.
Yes
HMAC-SHA-256-128 and HMAC-SHA-384-192 for integrity
Yes
HMAC-SHA-256 and HMAC-SHA-384 for pseudorandom function (PRF)
Yes
ICX7400-SERVICE-MOD hardware-based encryption and decryption (no encryption or decryption is done by
software)
Yes
AES-GCM-128 and AES-GCM-256
For ESP combined-mode authentication, encryption, and decryption of data
Yes
Line rate support (encryption and decryption at 10 Gbps full duplex)
Yes
Line rate support (authentication at 10 Gbps full duplex)
Note: End-to-end traffic throughput is 5 Gbps full duplex because traffic to the
ICX7400-SERVICE-MOD module is doubled at the router where a tunnel re-enters another tunnel.
Yes
IPsec Statistics
Packet counts and byte counts, including:
Transmit and Receive packet counts for each tunnel
Transmit and Receive byte counts for each tunnel
Yes
IKEv2 packet counters, including IKEv2 Keep Alive packets and IKEv2 error packets