© Copyright Lenovo 2017
Table 293.
Layer 3 IPsec Configuration Options (continued)
Command Syntax and Usage
ipv6 ospf encryption ipsec spi <256‐4294967295> esp
{3des|aescbc|null} <encryption key (hexadecimal)> {md5|sha1|none}
<authentication key (hexadecimal)>
Configures the Security Parameters Index (SPI), encryption algorithm,
authentication algorithm, and authentication key for the Encapsulating
Security Payload (ESP). The ESP algorithms supported are:
3des (hexadecimal key length is 48)
aescbc (hexadecimal key length is 32)
null means ESP with no encryption.
The authentication algorithms supported are:
md5 (hexadecimal key length is 32)
sha1 (hexadecimal key length is 40)
none means ESP with no authentication.
Note: If the encryption algorithm is null, the authentication algorithm must be
either MD5 or SHA1. If an encryption algorithm is specified (3DES or
AES‐CBC), the authentication algorithm can be none.
Command mode: Interface IP
no ipv6 ospf encryption ipsec spi <256‐4294967295>
Disables the specified Encapsulating Security Payload (ESP) SPI.
Command mode: Interface IP
ipv6 ospf encryption ipsec default
Resets the Encapsulating Security Payload (ESP) configuration to default
values.
Command mode: Interface IP
Chapter 4: Configuration Commands
555