Dell Force10 S25-01-GE-24V FTOS 8.4.2.7 Command Line Reference Guide for E-Ser - Page 1071
ipv6 ospf encryption
View all Dell Force10 S25-01-GE-24V manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 1071 highlights
ipv6 ospf encryption e t Configure an IPsec encryption policy for OSPFv3 packets on an IPv6 interface. Syntax ipv6 ospf encryption {null | ipsec spi number esp encryption-algorithm [key-encryption-type] key authentication-algorithm [key-encryption-type] key} Parameters null ipsec spi number esp encryption-algorithm key-encryption-type key authentication-algorith m key-encryption-type key Causes an encryption policy configured for the area to not be inherited on the interface. Security Policy index (SPI) value that identifies an IPsec security policy. Range: 256 to 4294967295. Encryption algorithm used with ESP. Valid values are: 3DES, DES, AES-CBC, and NULL. For AES-CBC, only the AES-128 and AES-192 ciphers are supported. (OPTIONAL) Specifies if the key is encrypted. Valid values: 0 (key is not encrypted) or 7 (key is encrypted). Text string used in encryption. The required lengths of a non-encrypted or encrypted key are: 3DES - 48 or 96 hex digits; DES - 16 or 32 hex digits; AES-CBC 32 or 64 hex digits for AES-128 and 48 or 96 hex digits for AES-192. Specifies the authentication algorithm to use for encryption. Valid values are MD5 or SHA1. (OPTIONAL) Specifies if the authentication key is encrypted. Valid values: 0 (key is not encrypted) or 7 (key is encrypted). Text string used in authentication. For MD5 authentication, the key must be 32 hex digits (non-encrypted) or 64 hex digits (encrypted). For SHA-1 authentication, the key must be 40 hex digits (non-encrypted) or 80 hex digits (encrypted). Default Not configured. Command Modes INTERFACE Command History Version 8.4.2.0 Introduced Usage Information Before you enable IPsec encryption on an OSPFv3 interface, you must first enable IPv6 unicast routing globally, configure an IPv6 address and enable OSPFv3 on the interface, and assign the interface to an area. An SPI value must be unique to one IPsec security policy (authentication or encryption) on the router. You must configure the same encryption policy (same SPI and keys) on each OSPFv3 interface in a link. To remove an IPsec encryption policy from an interface, enter the no ipv6 ospf encryption spi number command. To remove null authentication on an interface to allow the interface to inherit the authentication policy configured for the OSPFv3 area, enter the no ipv6 ospf encryption null command. Open Shortest Path First (OSPFv2 and OSPFv3) | 1071