RE: OSPFv3 authentication is ISAKMP based ? I know it is IPSec

From: Antonio Soares (amsoares@netcabo.pt)
Date: Wed Jul 11 2007 - 18:34:27 ART


Actually it only uses IPSEC AH. May use IPSEC ESP in 12.4T.

http://www.cisco.com/univercd/cc/td/doc/product/software/ios123/123cgcr/ipv6
_c/sa_ospf3.htm#wp1143078

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of Ben
Sent: quarta-feira, 11 de Julho de 2007 16:57
To: johngibson1541@yahoo.com
Cc: ccielab@groupstudy.com
Subject: Re: OSPFv3 authentication is ISAKMP based ? I know it is IPSec
based.

John
I haven't looked at it extensively, but I don't think is uses ISAKMP. One of
the command options is SPI value, which typically is needed when you do not
want IPSec session keys to be dynamically negotiated.

Ben

On 7/11/07, johngibson1541@yahoo.com <johngibson1541@yahoo.com> wrote:
>
> I know it utilizes IPv6 ESP header or some security header.
>
> But I don't know the boundary between ISAKMP and IPSec.
>
> How could something complicated as IPSec be configured in 1 or 2 lines
> in OSPFv3 ? 3560 document seems to give up on OSPFv3 authentication.
>
> John
>
> ______________________________________________________________________
> _ Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Sat Aug 18 2007 - 08:17:40 ART