Loading...
Loading...
Weak cryptographic encryption algorithms should not be used for OSPFv3 IPsec as they are insecure and do not provide adequate protection from modern threats. These algorithms should be replaced with stronger algorithms. The following algorithms will be rejected when configured: Under Interface interface ospfv3 encryption ipsec spi 0x100 esp Under Area: router ospfv3 area encryption ipsec spi esp Under Virtual Link: router ospfv3 address-family ipv6 unicast area virtual-link encryption ipsec spi esp
Device configured with weak cryptographic algorithms used in an IPsec configuration.
Update the configuration to use strong cryptographic algorithms used for IPsec. If that's not possible, then the following configuration command is required for IPsec to continue to function with the weak algorithms upon an upgrade to IOS XE version 17.11.1: Device(config)#crypto engine compliance shield disable Note the above command will only take effect after a reboot. Cisco does NOT recommend this option as these weak cryptographic algorithms are insecure and do not provide adequate protection from modern threats and should only be used as a last resort.
Weak cryptographic encryption algorithms should not be used for OSPFv3 IPsec as they are insecure and do not provide adequate protection from modern threats. These algorithms should be replaced with stronger algorithms. The following algorithms will be rejected when configured: Under Interface interface ospfv3 encryption ipsec spi 0x100 esp Under Area: router ospfv3 area encryption ipsec spi esp Under Virtual Link: router ospfv3 address-family ipv6 unicast area virtual-link encryption ipsec spi esp
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.