151
•
Configure IP addresses for interfaces to ensure IP connectivity between neighboring nodes.
•
Enable IS-IS.
Configuring neighbor relationship authentication
With neighbor relationship authentication configured, an interface adds the password in the specified
mode into hello packets to the peer and checks the password in the received hello packets. If the
authentication succeeds, it forms the neighbor relationship with the peer.
The authentication mode and password at both ends must be identical.
To prevent packet exchange failure in case of an authentication password change, configure the
interface not to check the authentication information in the received packets.
To configure neighbor relationship authentication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type interface-number
N/A
3.
Specify the authentication
mode and password.
isis authentication-mode
{
md5
|
simple
|
gca
key-id
{
hmac-sha-1
|
hmac-sha-224
|
hmac-sha-256
|
hmac-sha-384
|
hmac-sha-512
} } {
cipher
cipher-string
|
plain
plain-string
} [
level-1
|
level-2
] [
ip
|
osi
]
By default, no
authentication is
configured.
4.
(Optional.) Configure the
interface not to check the
authentication information in
the received hello packets.
isis authentication send-only
[
level-1
|
level-2
]
When the authentication
mode and password are
configured, the interface
checks the authentication
information in the received
packets by default.
Configuring area authentication
Area authentication prevents the router from installing routing information from untrusted routers into the
Level-1 LSDB. The router encapsulates the authentication password in the specified mode in Level-1
packets (LSP, CSNP, and PSNP) and checks the password in received Level-1 packets.
Routers in a common area must have the same authentication mode and password.
To prevent packet exchange failure in case of an authentication password change, configure IS-IS not to
check the authentication information in the received packets.
To configure area authentication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter IS-IS view.
isis
[
process-id
] [
vpn-instance
vpn-instance-name
]
N/A