Configuring the Open Shortest Path First Protocol
20-27
20
When using simple password authentication, a password is included in the packet.
If it does not match the password configured on the receiving router, the packet is
discarded. This method provides very little security as it is possible to learn the
authentication key by snooping on routing protocol packets.
When using Message-Digest 5 (MD5) authentication, the router uses the MD5
algorithm to verify data integrity by creating a 128-bit message digest from the
authentication key. Without the proper key and key-id, it is nearly impossible to
produce any message that matches the prespecified target message digest.
Before specifying MD5 authentication, configure the message-digest key-id and
key (see Message Digest Key-id).
The Authentication Key and Message Digest Key-id must be used consistently
throughout the autonomous system. (Note that the Message Digest Key-id field is
enabled only when MD5 authentication type is selected.)
•
Authentication Key
– Assign a plain-text password used by neighboring routers
to verify the authenticity of routing protocol messages. (Range: 1-8 characters for
simple password or 1-16 characters for MD5 authentication; Default: no key)
When plain-text or Message-Digest 5 (MD5) authentication is enabled as
described in the preceding item, this password (key) is inserted into the OSPF
header when routing protocol packets are originated by this device.
A different password can be assigned to each network interface, but the password
must be used consistently on all neighboring routers throughout a network (that is,
autonomous system). All neighboring routers in the same network with the same
password will exchange routing data.
•
Message Digest Key-id
– Assigns a key-id used in conjunction with the
authentication key to verify the authenticity of routing protocol messages sent to
neighboring routers. (Range: 1-255; Default: none)
Normally, only one key is used per interface to generate authentication information
for outbound packets and to authenticate incoming packets. Neighbor routers must
use the same key identifier and key value.
When changing to a new key, the router will send multiple copies of all protocol
messages, one with the old key and another with the new key. Once all the
neighboring routers start sending protocol messages back to this router with the
new key, the router will stop using the old key. This rollover process gives the
network administrator time to update all the routers on the network without
affecting the network connectivity. Once all the network routers have been updated
with the new key, the old key should be removed for security reasons.
Summary of Contents for ES4626F
Page 2: ......
Page 4: ...ES4626F ES4650F F1 1 0 2 E062009 R01 ST 149100000013A...
Page 6: ...ii...
Page 34: ...Getting Started...
Page 44: ...Introduction 1 10 1...
Page 62: ...Initial Configuration 2 18 2...
Page 64: ...Switch Management...
Page 76: ...Configuring the Switch 3 12 3...
Page 118: ...Basic Management Tasks 4 42 4...
Page 164: ...User Authentication 6 28 6...
Page 176: ...Access Control Lists 7 12 7...
Page 284: ...Quality of Service 14 8 14...
Page 294: ...Multicast Filtering 15 10 15...
Page 300: ...Domain Name Service 16 6 16...
Page 310: ...Dynamic Host Configuration Protocol 17 10 17...
Page 320: ...Configuring Router Redundancy 18 10 18...
Page 344: ...IP Routing 19 24 19...
Page 356: ...Unicast Routing 20 12 20 Web Click Routing Protocol RIP Statistics Figure 20 5 RIP Statistics...
Page 386: ...Unicast Routing 20 42 20...
Page 388: ...Command Line Interface...
Page 400: ...Overview of the Command Line Interface 21 12 21...
Page 466: ...SNMP Commands 24 16 24...
Page 520: ...Access Control List Commands 26 18 26...
Page 546: ...Rate Limit Commands 30 2 30...
Page 612: ...VLAN Commands 34 24 34...
Page 626: ...Class of Service Commands 35 14 35...
Page 670: ...DHCP Commands 39 16 39...
Page 716: ...IP Interface Commands 41 36 41...
Page 768: ...IP Routing Commands 42 52 42...
Page 770: ...Appendices...
Page 791: ......
Page 792: ...ES4626F ES4650F E062009 R01 ST 149100000013A...