If you want to encrypt and authenticate sent and received IPv6 PIM messages, configure IPv6 PIM IP Security (IPsec). IPv6 PIM IPsec protects a device against attacks launched using forged IPv6 PIM messages.
IPv6 PIM IPsec provides a complete set of security protection mechanisms to authenticate the sent and received IPv6 PIM messages, protecting devices against attacks launched using forged IPv6 PIM messages.
IPv6 PIM IPsec configured in the interface view has the same effect as that configured in the IPv6 PIM view, but their application scopes are different:
IPv6 PIM IPsec configured in the interface view takes precedence over IPv6 PIM IPsec configured in the IPv6 PIM view. If no IPv6 PIM IPsec configuration exists in the interface view, the interface uses the IPv6 PIM IPsec configuration in the IPv6 PIM view.
Before configuring IPv6 PIM IPsec, complete the following tasks:
Configure basic IPsec functions.
If the ipsec sa and hello ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
If the pim ipv6 ipsec sa and pim ipv6 hello ipsec sa commands are both configured, the command configured later overrides the command configured earlier.
Run the display pim ipv6 interface interface-type interface-number verbose command to check the detailed IPv6 PIM IPsec configuration on an interface.
# Display the IPv6 PIM IPsec configuration on GE0/1/0. The command output shows that IPv6 PIM IPsec has been configured on GE0/1/0, the SA policy is named 1, and IPsec authentication applies only to IPv6 PIM Hello messages.