Allied Telesis AR2050V Command Reference Manual page 1023

Secure, for alliedware plus version 5.4.7-1.x
Table of Contents

Advertisement

OSPF
3
IP
6 C
V
FOR
V
OMMANDS
-
AREA VIRTUAL
LINK ENCRYPTION IPSEC SPI
Mode
Router Configuration
Usage
When you issue this command, authentication and encryption are both enabled.
Use this command on an OSPFv3 area virtual link, use the
esp
Index) value on all interfaces that connect to the same link. SPI values are used by
link interfaces. Use a different SPI value for a different link interface when using
OSPFv3 with link interfaces.
Security is achieved using the IPv6 ESP extension header. ESP is used to provide
confidentiality, integrity, authentication, and confidentiality. Authentication fields
are removed from OSPF for IPv6 packet headers. The IPv6 ESP extension header is
required for integrity, authentication, and confidentiality.
Note that interface configuration takes priority over area configuration. If an
interface configuration is removed then an area configuration is applied to an
interface instead.
Use the sha1 keyword to choose SHA-1 authentication instead of entering the
md5 keyword to use MD5 authentication. The SHA-1 algorithm is more secure
than the MD5 algorithm. SHA-1 uses a 40 hexadecimal character key instead of a
32 hexadecimal character key as used for MD5 authentication.
See the
and examples.
Example
To enable ESP encryption, but not apply an AES-CBC key or a 3DES key, and MD5
authentication with a 32 hexadecimal character key for virtual links in OPSPF area
1, use the commands:
awplus#
awplus(config)#
awplus(config-router)#
ipsec spi 1000 esp null md5 1234567890ABCDEF1234567890ABCDEF
C613-50186-01 Rev B
Parameter
null
md5
<MD5-key>
sha1
<SHA1-key>
command on an OSPFv3 area. Configure the same SPI (Security Parameters
OSPFv3 Feature Overview and Configuration Guide
configure terminal
router ipv6 ospf
Command Reference for AR2050V
AlliedWare Plus™ Operating System - Version 5.4.7-1.x
Description
Specify ESP without AES-CBC or 3DES encryption applied.
Specify the MD5 (Message-Digest 5) encryption algorithm.
Enter an MD5 key containing 32 hexadecimal characters.
Specify the SHA-1 (Secure Hash Algorithm 1) encryption
algorithm.
Enter an SHA-1 key containing 40 hexadecimal characters.
area 1 virtual-link 10.0.0.1 encryption
area encryption ipsec spi
for more information
1023

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents