![Alcatel-Lucent 7950 SR System Management Manual Download Page 52](http://html1.mh-extra.com/html/alcatel-lucent/7950-sr/7950-sr_system-management-manual_2892148052.webp)
Other Security Features
Page 52
7950 SR OS System Management Guide
The TCP Enhanced Authentication Option is a TCP extension that enhances security for BGP,
LDP and other TCP-based protocols. This includes the ability to change keys in a BGP or LDP
session seamlessly without tearing down the session. It is intended for applications where
secure administrative access to both the end-points of the TCP connection is normally
available.
TCP peers can use this extension to authenticate messages passed between one another. This
strategy improves upon current practice, which is described in RFC 2385,
Protection of BGP
Sessions
via the TCP MD5 Signature Option
. Using this new strategy, TCP peers can update
authentication keys during the lifetime of a TCP connection. TCP peers can also use stronger
authentication algorithms to authenticate routing messages.
Packet Formats
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
Kind
| Length
|T|K|
Alg ID|Res|
Key ID |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
Authentication Data |
| // |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Option Syntax
•
Kind: 8 bits
The Kind field identifies the TCP Enhanced Authentication Option. This value will be
assigned by IANA.
•
Length: 8 bits
The Length field specifies the length of the TCP Enhanced Authentication Option, in
octets. This count includes two octets representing the Kind and Length fields.
The valid range for this field is from 4 to 40 octets, inclusive.
For all algorithms specified in this memo the value will be 16 octets.
•
T-Bit: 1 bit
The T-bit specifies whether TCP Options were omitted from the TCP header for the
purpose of MAC calculation. A value of 1 indicates that all TCP options other than the
Extended Authentication Option were omitted. A value of 0 indicates that TCP
options were included.
The default value is 0.
•
K-Bit: 1 bit
This bit is reserved for future enhancement. Its value MUST be equal to zero.
•
Alg ID: 6 bits
The Alg ID field identifies the MAC algorithm.
Summary of Contents for 7950 SR
Page 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Page 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Page 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Page 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Page 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Page 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Page 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Page 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Page 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Page 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Page 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Page 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Page 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Page 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Page 460: ...Standards and Protocols Page 460 Standards and Protocols...