ospfv3 and ipsec
Today a co-worker asked me about setting up the appropriate remote-gateway field in IPsec for the SA with OSPFv3 on JUNOS. Upon looking a bit deeper at this configuration, it appears that OSPFv3 with IPsec is used for securing virtual links; as it is not the same as the functionality that MD5 provides for OSPFv2 on broadcast links. Interesting, I think this is more the reason to run ISIS as your IGP ;)
The relevant link: http://www.juniper.net/techpubs/software/junos/junos76/feature-guide-76/html/fg-ipsec30.html#1084093
Well, another thing to truely consider is only running OSPFv2 for traffic engineering and advertising links and loopbacks, and then to implement 6PE on top as an MPLS overlay.
Originally published on truman.net. See the archived copy.