cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
875
Views
10
Helpful
8
Replies

Securing OSPFv3 with GDOI

kasper123
Level 4
Level 4

Hi,

I have a GDOI setup that encrypts IPv6 traffic between routers. I would also like to encrypt the OSPFv3 between those routers but wasn't able to get it working yet.

What access list entries do I need to use to encrypt the OSPFv3 traffic?

Thank you in advance.

8 Replies 8

@kasper123 you don't, you explictly do not encrypt routing protocol traffic when using GETVPN.

@Rob Ingram why not? This traffic also needs be encrypted but without OSPFv3 encryption.

As GDOI is already in place I have a requirement to use it also for this.

@kasper123 because you are relying on the routing protocol to route those encrypted packets.

@Rob Ingram no, the routers are in the same subnet and I don't rely on this routing protocol to route the encrypted packets.

so finally you decide to use GET to secure the OSPF, 
can you draw topolgy and include the KS  location.

you need ACL with GET

@MHM Cisco World routers are in different sites connected over xconnect. Effectively they are in the same L2 domain with IPv6 addresses in the same subnet.

KS server is independent and running over IPv4. I encrypt only IPv6 with GDOI.

the ACL use in GM work like filter to filter which traffic will be secure and which not.
the ACL will start with deny control traffic, control traffic include the routing protocol that make GM and KS reachable.
and you can after deny control traffic only add permit any any.