Applying Ipsec Policies For Ospfv3 - HP 3600 v2 series Configuration Manual

Hide thumbs Also See for 3600 v2 series:
Table of Contents

Advertisement

Applying IPsec policies for OSPFv3

To protect routing information and defend attacks, OSPFv3 can authenticate protocol packets by using
an IPsec policy.
Outbound OSPFv3 packets carry the Security Parameter Index (SPI) defined in the relevant IPsec policy.
A device uses the SPI carried in a received packet to match against the configured IPsec policy. If they
match, the device accepts the packet; otherwise, it discards the packet and will not establish a neighbor
relationship with the sending device.
You can configure an IPsec policy for an area, an interface or a virtual link.
To implement area-based IPsec protection, you need to configure the same IPsec policy on the
routers in the target area.
To implement interface-based IPsec protection, you need to configure the same IPsec policy on the
interfaces between two neighboring routers.
To implement virtual link-based IPsec protection, you need to configure the same IPsec policy on the
two routers connected over the virtual link.
If an interface and its area each have an IPsec policy configured, the interface uses its own IPsec policy.
If a virtual link and area 0 each have an IPsec policy configured, the virtual link uses its own IPsec policy.
Configuration prerequisites
Before applying an IPsec policy for OSPFv3, you need to complete following tasks.
Create an IPsec proposal
Create an IPsec policy
For more information about IPsec policy configuration, see Security Configuration Guide.
Configuration Procedure
Follow these steps to apply an IPsec policy in an area:
To do...
Enter system view
Enter OSPFv3 view
Enter OSPF area view
Apply an IPsec policy in the area
Follow these steps to apply an IPsec policy on an interface:
To do...
Enter system view
Enter interface view
Apply an IPsec policy on the
interface
Follow these steps to apply an IPsec policy on a virtual link:
Use the command...
system-view
ospfv3 [ process-id ]
area area-id
enable ipsec-policy policy-name
Use the command...
system-view
interface interface-type
interface-number
ospfv3 ipsec-policy policy-name
[ instance instance-id ]
294
Remarks
Required
Not configured by default
Remarks
Required
Not configured by default

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents