33
Enabling source IP address check on incoming RIP updates
You can enable source IP address check on incoming RIP updates.
For a message received on an Ethernet interface, RIP compares the source IP address of the message with
the IP address of the interface. If they are not in the same network segment, RIP discards the message.
IMPORTANT:
Disable the source IP address check feature if the RIP neighbor is not directly connected.
To enable source IP address check on incoming RIP updates:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RIP view.
rip
[
process-id
] [
vpn-instance
vpn-instance-name
]
N/A
3.
Enable source IP address
check on incoming RIP
messages.
validate-source-address
Optional.
Enabled by default.
Configuring RIPv2 message authentication
In a network requiring high security, configure this task to implement RIPv2 message validity check and
authentication. This feature does not apply to RIPv1 because RIPv1 does not support authentication.
Although you can specify an authentication mode for RIPv1 in interface view, the configuration does not
take effect.
RIPv2 supports simple authentication and MD5 authentication.
To configure RIPv2 message authentication:
Step Command
1.
Enter system view.
system-view
2.
Enter interface view.
interface
interface-type interface-number
3.
Configure RIPv2
authentication.
rip authentication-mode
{
md5
{
rfc2082
[
cipher
]
key-string
key-id
|
rfc2453
[
cipher
]
key-string
} |
simple
[
cipher
]
password
}
Specifying a RIP neighbor
Usually, RIP sends messages to broadcast or multicast addresses. On non-broadcast or multicast links,
you must manually specify RIP neighbors.
Follow these guidelines when you specify a RIP neighbor:
•
Do not use the
peer
ip-address
command when the neighbor is directly connected because the
neighbor may receive both the unicast and multicast (or broadcast) of the same routing information.
•
If a specified neighbor is not directly connected, then disable the source address check on incoming
updates.
To specify a RIP neighbor: