87
Parameters
hmac-md5
: Specifies HMAC-MD5 authentication.
md5
: Specifies MD5 authentication.
simple
: Specifies simple authentication.
key-id
: Specifies a key by its ID in the range of 1 to 255.
cipher
: Specifies a key in encrypted form.
plain
: Specifies a key in plaintext form. For security purposes, the key specified in plaintext form
will be stored in encrypted form.
string
: Specifies the key. This argument is case sensitive.
•
In simple authentication mode, the plaintext form of the key is a string of 1 to 8 characters. The
encrypted form of the key is a string of 33 to 41 characters.
•
In MD5/HMAC-MD5 authentication mode, the plaintext form of the key is a string of 1 to 16
characters. The encrypted form of the key is a string of 33 to 53 characters.
Usage guidelines
To establish or maintain adjacencies, interfaces attached to the same network segment must have
the same authentication mode and key.
If MD5 or HMAC-MD5 authentication is configured, you can configure multiple keys, each having a
unique key ID and key string. To minimize the risk of key compromise, use only one key for an
interface and delete the old key after key replacement.
To replace the key used for MD5 or HMAC-MD5 authentication on an interface, you must configure
the new key before removing the old key from each router. OSPF uses the key rollover mechanism to
ensure that the routers can pass authentication before the replacement is complete on the interface.
After you configure a new key on a router, the router sends copies of the same packet, each
authenticated by a different key, including the new key and the keys in use. This practice continues
until the router detects that all its neighbors have the new key.
Examples
# On VLAN-interface 10, enable MD5 authentication, and set the interface key ID to 15 and the key
to
123456
in plaintext form.
<Sysname> system-view
[Sysname] interface vlan-interface 10
[Sysname-Vlan-interface10] ospf authentication-mode md5 15 plain 123456
# On VLAN-interface 10, enable simple authentication, and set the key to
123456
in plaintext form.
<Sysname> system-view
[Sysname] interface vlan-interface 10
[Sysname-Vlan-interface10] ospf authentication-mode simple plain 123456
Related commands
authentication-mode
ospf bfd enable
Use
ospf bfd enable
to enable BFD on an OSPF interface.
Use
undo
ospf
bfd enable
to disable BFD on an OSPF interface.
Syntax
ospf bfd enable
[
echo
]
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...