area <AREA-ID> authentication ipsec


area <AREA-ID> authentication ipsec spi <SPI-INDEX> <AUTH-TYPE> <KEY-TYPE> <AUTH-KEY>

no area <AREA-ID> authentication


Configures IPSec AH authentication for the specified area. OSPFv3 interfaces which have IPsec configured at the interface context will not use area level IPsec.

The no form of this command removes IPSec AH authentication for the specified area.


IPSec is not supported for 6in6 tunnel interfaces.

Command context



Specifies the area ID is one of the following formats.
  • OSPF area identifier in IPv4 format (x.x.x.x), where x is a decimal number from 0 to 255.

  • OSPF area identifier in decimal format. Range: 0 to 4294967295.


Specifies the Security Parameters Index (SPI) to use. The SPI is an identification tag carried in the IPsec AH header. It enables the receiving OSPF process to select and use the Security Association (SA) from the SA table. The SPI must be unique on the switch. Range: 256-4294967295 characters.


Specifies the algorithm to use for authentication: md5 or sha1.


Specifies the key type to use: plaintext (unencrypted), hex-string (encrypted) or ciphertext (encrypted).


Specifies the key.


Administrators or local user group members with execution rights for this command.


Setting area 1 to use IPsec authentication(AH):

switch(config)# router ospfv3 1
switch(config-ospfv3-1)# area 1 authentication ipsec spi 256 sha1 plaintext abcd

Removing IPsec authentication (AH) on area 1:

switch(config)# router ospfv3 1
switch(config-ospfv3-1)# no area 1 authentication