Skip to content

Crypto

Cryptographic services provide comprehensive security capabilities including Public Key Infrastructure (PKI), IPsec VPN tunnels, Internet Key Exchange version 2 (IKEv2), and crypto engine compliance controls for secure communication between network devices and endpoints. These services enable encryption, authentication, and integrity protection for data in transit, supporting both site-to-site and remote access VPN scenarios. The crypto subsystem manages certificates, trust relationships, encryption policies, security associations, and cryptographic algorithm compliance settings necessary for establishing and maintaining secure communications across untrusted networks.

Diagram
NameTypeConstraintMandatoryDefault Value
cryptoClass[crypto]No

NameTypeConstraintMandatoryDefault Value
ipsec_profilesList[ipsec_profiles]No
ipsec_transform_setsList[ipsec_transform_sets]No
ikev2Class[ikev2]No
pkiClass[pki]No
engineClass[engine]No

ipsec_profiles (iosxe.devices.configuration.crypto)

Section titled “ipsec_profiles (iosxe.devices.configuration.crypto)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
set_ikev2_profileStringNo
set_isakmp_profileStringNo
set_pfs_groupChoicegroup1, group2, group5, group14, group15, group16, group19, group20, group21, group24No
set_security_association_lifetime_secondsIntegermin: 120, max: 2592000No
set_security_association_lifetime_seconds_legacyIntegermin: 120, max: 2592000No
set_transform_setListStringNo

ipsec_transform_sets (iosxe.devices.configuration.crypto)

Section titled “ipsec_transform_sets (iosxe.devices.configuration.crypto)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
espChoiceesp-3des, esp-aes, esp-des, esp-gcm, esp-gmac, esp-null, esp-sealYes
esp_hmacChoiceesp-md5-hmac, esp-sha-hmac, esp-sha256-hmac, esp-sha384-hmac, esp-sha512-hmacYes
mode_tunnelBooleantrue, falseNo

ikev2 (iosxe.devices.configuration.crypto)

Section titled “ikev2 (iosxe.devices.configuration.crypto)”
NameTypeConstraintMandatoryDefault Value
nat_keepaliveIntegermin: 5, max: 3600No
dpd_intervalIntegermin: 10, max: 3600No
dpd_queryChoiceon-demand, periodicNo
dpd_retryIntegermin: 2, max: 60No
http_url_certificate_lookupBooleantrue, falseNo
profilesList[profiles]No
keyringsList[keyrings]No
policiesList[policies]No
proposalsList[proposals]No

NameTypeConstraintMandatoryDefault Value
trustpointsList[trustpoints]No

engine (iosxe.devices.configuration.crypto)

Section titled “engine (iosxe.devices.configuration.crypto)”
NameTypeConstraintMandatoryDefault Value
compliance_shield_disableBooleantrue, falseNo

profiles (iosxe.devices.configuration.crypto.ikev2)

Section titled “profiles (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
authentication_local_pre_shareBooleantrue, falseNo
authentication_remote_pre_shareBooleantrue, falseNo
config_exchange_requestBooleantrue, falseNo
descriptionStringNo
dpd_intervalIntegermin: 10, max: 3600No
dpd_queryChoiceon-demand, periodicNo
dpd_retryIntegermin: 2, max: 60No
identity_local_addressIPNo
identity_local_key_idStringNo
ivrfStringNo
keyring_localStringNo
lifetimeIntegermin: 120, max: 86400No
match_address_local_interface_loopbackList[match_address_local_interface_loopback]No
match_address_local_interface_loopback_legacyIntegermin: 0, max: 2147483647No
match_address_local_ipIPNo
match_fvrfStringNo
match_fvrf_anyBooleantrue, falseNo
match_identity_remote_ipv4_addressesList[match_identity_remote_ipv4_addresses]No
match_identity_remote_ipv6_prefixesListStringNo
match_identity_remote_keysListStringNo
match_inbound_onlyBooleantrue, falseNo

keyrings (iosxe.devices.configuration.crypto.ikev2)

Section titled “keyrings (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
peersList[peers]No

policies (iosxe.devices.configuration.crypto.ikev2)

Section titled “policies (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
proposalsListStringYes
deviceStringNo
match_address_local_ipListIPNo
match_fvrfStringNo
match_fvrf_anyBooleantrue, falseNo
match_inbound_onlyBooleantrue, falseNo

proposals (iosxe.devices.configuration.crypto.ikev2)

Section titled “proposals (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
encryptionListChoice[aes_cbc_128, aes_cbc_192, aes_cbc_256, aes_gcm_128, aes_gcm_256, en_3des]No
groupListChoice[1, 2, 14, 15, 16, 19, 20, 21, 24]No
integrityListChoice[md5, sha1, sha256, sha384, sha512]No
prfListChoice[md5, sha1, sha256, sha384, sha512]No

trustpoints (iosxe.devices.configuration.crypto.pki)

Section titled “trustpoints (iosxe.devices.configuration.crypto.pki)”
NameTypeConstraintMandatoryDefault Value
idStringYes
enrollment_mode_raBooleantrue, falseNo
enrollment_pkcs12Booleantrue, falseNo
enrollment_selfsignedBooleantrue, falseNo
enrollment_terminalBooleantrue, falseNo
hashChoicemd5, sha1, sha256, sha384, sha512No
revocation_checkListStringNo
rsakeypairStringNo
source_interfaceStringNo
subject_nameStringNo
usageChoiceike, ssl-client, ssl-serverNo

match_address_local_interface_loopback (iosxe.devices.configuration.crypto.ikev2.profiles)

Section titled “match_address_local_interface_loopback (iosxe.devices.configuration.crypto.ikev2.profiles)”
NameTypeConstraintMandatoryDefault Value
loopback_numberIntegermin: 0, max: 2147483647Yes

match_identity_remote_ipv4_addresses (iosxe.devices.configuration.crypto.ikev2.profiles)

Section titled “match_identity_remote_ipv4_addresses (iosxe.devices.configuration.crypto.ikev2.profiles)”
NameTypeConstraintMandatoryDefault Value
addressIPYes
maskIPNo

peers (iosxe.devices.configuration.crypto.ikev2.keyrings)

Section titled “peers (iosxe.devices.configuration.crypto.ikev2.keyrings)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
descriptionStringNo
hostnameStringNo
identity_addressIPNo
identity_email_domainStringNo
identity_email_nameStringNo
identity_fqdn_domainStringNo
identity_fqdn_nameStringNo
identity_key_idStringNo
ipv4_addressIPNo
ipv4_maskIPNo
ipv6_prefixStringNo
pre_shared_keyStringNo
pre_shared_key_encryptionChoice0, 6No
pre_shared_key_localStringNo
pre_shared_key_local_encryptionChoice0, 6No
pre_shared_key_remoteStringNo
pre_shared_key_remote_encryptionChoice0, 6No

  • The identity_fqdn_name and identity_fqdn_domain attributes (under keyrings[].peers[]) are mutually exclusive. Use identity_fqdn_name for a specific FQDN (e.g., gateway5), or identity_fqdn_domain for a domain suffix (e.g., example.com).
crypto pki trustpoint trustpoint1
enrollment selfsigned
enrollment pkcs12
usage ike
subject-name cn=Router1
rsakeypair mykey
hash sha256
!
crypto ipsec transform-set TEST esp-aes esp-sha-hmac
mode tunnel
!
crypto ipsec profile vpn200
set transform-set TEST
set ikev2-profile PROFILE1
set isakmp-profile PROFILE1
set pfs group20
set security-association lifetime seconds 3600
!
crypto ikev2 proposal PROPOSAL1
encryption aes-cbc-256
integrity sha256
group 16
!
crypto ikev2 proposal PROPOSAL2
encryption aes-gcm-256
integrity sha384
group 20
!
crypto ikev2 policy POLICY1
proposal PROPOSAL1
match address local 1.2.3.4
match fvrf any
!
crypto ikev2 policy POLICY2
proposal PROPOSAL1
match fvrf VRF1
!
crypto ikev2 keyring KEYRING1
peer PEER1
description My description
address 1.2.3.4 255.255.255.248
identity key-id key1
pre-shared-key local 6 cisco123
pre-shared-key remote 6 cisco123
peer PEER2
description temp
hostname gateway1
identity email-domain cisco.com
pre-shared-key 6 cisco123
peer PEER3
description temp2
hostname gateway4
identity email abc
peer PEER4
description FQDN name identity example
hostname gateway5.example.com
identity fqdn gateway5
pre-shared-key 6 cisco123
!
crypto ikev2 profile PROFILE1
description My description
match identity remote address 1.2.3.4 255.255.255.0
match identity remote key-id key1
match address local 1.2.3.4
match address local interface Loopback100
match fvrf any
match inbound-only
identity local key-id KEY1
authentication remote pre-share
authentication local pre-share
keyring local KEYRING1
lifetime 28800
dpd 10 2 periodic
no config-exchange request
!
crypto ikev2 profile PROFILE2
description VRF-specific profile
match fvrf VRF1
authentication remote pre-share
authentication local pre-share
!
crypto engine compliance shield disable
iosxe:
devices:
- name: Device1
configuration:
crypto:
pki:
trustpoints:
- id: trustpoint1
enrollment_selfsigned: true
enrollment_pkcs12: false
rsakeypair: mykey
subject_name: cn=Router1
hash: sha256
usage: ike
ipsec_profiles:
- name: vpn200
set_transform_set: [TEST]
set_isakmp_profile: PROFILE1
set_pfs_group: group20
set_security_association_lifetime_seconds: 3600
ipsec_transform_sets:
- name: TEST
esp: esp-aes
esp_hmac: esp-sha-hmac
mode_tunnel: true
ikev2:
nat_keepalive: 20
dpd_interval: 10
dpd_query: periodic
dpd_retry: 5
http_url_certificate_lookup: true
profiles:
- name: PROFILE1
description: My description
authentication_remote_pre_share: true
authentication_local_pre_share: true
identity_local_key_id: KEY1
lifetime: 28800
match_address_local_interface_loopback_legacy: 100 # IOS-XE versions before 17.18.x
match_address_local_interface_loopback: # IOS-XE 17.18.x and later
- loopback_number: 100
match_address_local_ip: 1.2.3.4
match_fvrf_any: true
match_inbound_only: true
match_identity_remote_ipv4_addresses:
- address: 1.2.3.4
mask: 255.255.255.0
match_identity_remote_keys: [key1]
keyring_local: KEYRING1
dpd_interval: 10
dpd_retry: 2
dpd_query: periodic
config_exchange_request: false
- name: PROFILE2
description: VRF-specific profile
authentication_remote_pre_share: true
authentication_local_pre_share: true
match_fvrf: VRF1
keyrings:
- name: KEYRING1
peers:
- name: PEER1
description: My description
ipv4_address: 1.2.3.4
ipv4_mask: 255.255.255.248
identity_key_id: key1
pre_shared_key_local_encryption: "6"
pre_shared_key_local: cisco123
pre_shared_key_remote_encryption: "6"
pre_shared_key_remote: cisco123
- name: PEER2
description: temp
hostname: gateway1
ipv6_prefix: 2001::1/128
identity_email_domain: cisco.com
pre_shared_key_encryption: "6"
pre_shared_key: cisco123
- name: PEER3
description: temp2
hostname: gateway4
ipv6_prefix: 2001::2/128
identity_email_name: abc
- name: PEER4
description: FQDN name identity example
hostname: gateway5.example.com
identity_fqdn_name: gateway5
pre_shared_key_encryption: "6"
pre_shared_key: cisco123
policies:
- name: POLICY1
proposals: [PROPOSAL1]
match_address_local_ip: [1.2.3.4]
match_fvrf_any: true
match_inbound_only: false
- name: POLICY2
proposals: [PROPOSAL1]
match_fvrf: VRF1
proposals:
- name: PROPOSAL1
encryption_aes_cbc_256: true
group_sixteen: true
integrity_sha256: true
- name: PROPOSAL2
encryption_aes_gcm_256: true
group_twenty: true
integrity_sha384: true
engine:
compliance_shield_disable: true

Cryptographic services provide comprehensive security capabilities including Public Key Infrastructure (PKI), IPsec VPN tunnels, and Internet Key Exchange version 2 (IKEv2) for secure communication between network devices and endpoints. These services enable encryption, authentication, and integrity protection for data in transit, supporting both site-to-site and remote access VPN scenarios. The crypto subsystem manages certificates, trust relationships, encryption policies, and security associations necessary for establishing and maintaining secure communications across untrusted networks.

Diagram
NameTypeConstraintMandatoryDefault Value
cryptoClass[crypto]No

NameTypeConstraintMandatoryDefault Value
ipsec_profilesList[ipsec_profiles]No
ipsec_transform_setsList[ipsec_transform_sets]No
ikev2Class[ikev2]No
pkiClass[pki]No

ipsec_profiles (iosxe.devices.configuration.crypto)

Section titled “ipsec_profiles (iosxe.devices.configuration.crypto)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
set_transform_setListStringNo
set_ikev2_profileStringNo
set_isakmp_profileStringNo

ipsec_transform_sets (iosxe.devices.configuration.crypto)

Section titled “ipsec_transform_sets (iosxe.devices.configuration.crypto)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
espChoiceesp-3des, esp-aes, esp-des, esp-gcm, esp-gmac, esp-null, esp-sealYes
esp_hmacChoiceesp-md5-hmac, esp-sha-hmac, esp-sha256-hmac, esp-sha384-hmac, esp-sha512-hmacYes
mode_tunnelBooleantrue, falseNo

ikev2 (iosxe.devices.configuration.crypto)

Section titled “ikev2 (iosxe.devices.configuration.crypto)”
NameTypeConstraintMandatoryDefault Value
nat_keepaliveIntegermin: 5, max: 3600No
dpd_intervalIntegermin: 10, max: 3600No
dpd_queryChoiceon-demand, periodicNo
dpd_retryIntegermin: 2, max: 60No
http_url_certificate_lookupBooleantrue, falseNo
profilesList[profiles]No
keyringsList[keyrings]No
policiesList[policies]No
proposalsList[proposals]No

NameTypeConstraintMandatoryDefault Value
trustpointsList[trustpoints]No

profiles (iosxe.devices.configuration.crypto.ikev2)

Section titled “profiles (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
authentication_local_pre_shareBooleantrue, falseNo
authentication_remote_pre_shareBooleantrue, falseNo
config_exchange_requestBooleantrue, falseNo
descriptionStringNo
dpd_intervalIntegermin: 10, max: 3600No
dpd_queryChoiceon-demand, periodicNo
dpd_retryIntegermin: 2, max: 60No
identity_local_addressStringNo
identity_local_key_idStringNo
ivrfStringNo
keyring_localStringNo
match_address_local_ipStringNo
match_fvrfStringNo
match_fvrf_anyBooleantrue, falseNo
match_identity_remote_ipv4_addressesList[match_identity_remote_ipv4_addresses]No
match_identity_remote_ipv6_prefixesListStringNo
match_identity_remote_keysListStringNo
match_inbound_onlyBooleantrue, falseNo

keyrings (iosxe.devices.configuration.crypto.ikev2)

Section titled “keyrings (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
peersList[peers]No

policies (iosxe.devices.configuration.crypto.ikev2)

Section titled “policies (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
proposalsListStringYes
deviceStringNo
match_address_local_ipListStringNo
match_fvrfStringNo
match_fvrf_anyBooleantrue, falseNo
match_inbound_onlyBooleantrue, falseNo

proposals (iosxe.devices.configuration.crypto.ikev2)

Section titled “proposals (iosxe.devices.configuration.crypto.ikev2)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
encryptionListChoice[aes_cbc_128, aes_cbc_192, aes_cbc_256, aes_gcm_128, aes_gcm_256, en_3des]No
groupListChoice[1, 2, 14, 15, 16, 19, 20, 21, 24]No
integrityListChoice[md5, sha1, sha256, sha384, sha512]No
prfListChoice[md5, sha1, sha256, sha384, sha512]No

trustpoints (iosxe.devices.configuration.crypto.pki)

Section titled “trustpoints (iosxe.devices.configuration.crypto.pki)”
NameTypeConstraintMandatoryDefault Value
idStringYes
enrollment_mode_raBooleantrue, falseNo
enrollment_pkcs12Booleantrue, falseNo
enrollment_selfsignedBooleantrue, falseNo
enrollment_terminalBooleantrue, falseNo
hashChoicemd5, sha1, sha256, sha384, sha512No
revocation_checkListStringNo
rsakeypairStringNo
source_interfaceStringNo
subject_nameStringNo
usageChoiceike, ssl-client, ssl-serverNo

match_identity_remote_ipv4_addresses (iosxe.devices.configuration.crypto.ikev2.profiles)

Section titled “match_identity_remote_ipv4_addresses (iosxe.devices.configuration.crypto.ikev2.profiles)”
NameTypeConstraintMandatoryDefault Value
addressStringYes
maskStringNo

peers (iosxe.devices.configuration.crypto.ikev2.keyrings)

Section titled “peers (iosxe.devices.configuration.crypto.ikev2.keyrings)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
descriptionStringNo
hostnameStringNo
identity_addressStringNo
identity_email_domainStringNo
identity_email_nameStringNo
identity_fqdn_domainStringNo
identity_fqdn_nameStringNo
identity_key_idStringNo
ipv4_addressStringNo
ipv4_maskStringNo
ipv6_prefixStringNo
pre_shared_keyStringNo
pre_shared_key_encryptionChoice0, 6No
pre_shared_key_localStringNo
pre_shared_key_local_encryptionChoice0, 6No
pre_shared_key_remoteStringNo
pre_shared_key_remote_encryptionChoice0, 6No

iosxe:
devices:
- name: Device1
configuration:
crypto:
pki:
trustpoints:
- id: trustpoint1
enrollment_selfsigned: true
rsakeypair: mykey
subject_name: cn=Router1
hash: sha256
ipsec_profiles:
- name: vpn200
set_transform_set: [TEST]
set_isakmp_profile_ikev2_profile_ikev2_profile_case_ikev2_profile: PROFILE1
ipsec_transform_sets:
- name: TEST
esp: esp-aes
esp_hmac: esp-sha-hmac
mode_tunnel: true
ikev2:
nat_keepalive: 20
dpd_interval: 10
dpd_query: periodic
dpd_retry: 5
profiles:
- name: PROFILE1
description: My description
authentication_remote_pre_share: true
authentication_local_pre_share: true
identity_local_key_id: KEY1
match_address_local_ip: 1.2.3.4
match_fvrf_any: true
match_identity_remote_ipv4_addresses:
- address: 1.2.3.4
mask: 255.255.255.0
match_identity_remote_keys: [key1]
keyring_local: KEYRING1
dpd_interval: 10
dpd_retry: 2
dpd_query: periodic
config_exchange_request: false
keyrings:
- name: KEYRING1
peers:
- name: PEER1
description: My description
ipv4_address: 1.2.3.4
ipv4_mask: 255.255.255.248
identity_key_id: key1
pre_shared_key_local_encryption: "6"
pre_shared_key_local: cisco123
pre_shared_key_remote_encryption: "6"
pre_shared_key_remote: cisco123
- name: PEER2
description: temp
hostname: gateway1
ipv6_prefix: 2001::1/128
identity_email_domain: cisco.com
pre_shared_key_encryption: "6"
pre_shared_key: cisco123
- name: PEER3
description: temp2
hostname: gateway4
ipv6_prefix: 2001::2/128
identity_email_name: abc
policies:
- name: POLICY1
proposals: [PROPOSAL1]
match_address_local_ip: [1.2.3.4]
match_fvrf_any: true
proposals:
- name: PROPOSAL1
encryption_aes_cbc_256: true
group_sixteen: true
integrity_sha256: true
- name: PROPOSAL2
encryption_aes_gcm_256: true
group_twenty: true
integrity_sha384: true