
SEND TIMER :
Start time : 2012-03-14 00:00
End time : 2012-08-08 23:59
Status : Active
RECEIVE TIMER :
Start time : 2012-03-14 00:00
End time : 2012-08-08 23:59
Status : Active
DEFAULT SEND KEY ID INFORMATION
Default : Not configured
13.4 Configuring TCP Authentication parameters
This section descries how to configure the TCP Authentication parameters of Keychain module.
13.4.1 Establishing the Configuration Task
Applicable Environment
Keychain is needed to provide authentication support to all the needed applications.
Authenticated TCP communication is required between two peers.TCP based applications can
communicate with other vendor nodes by using the authenticated TCP connection.
For authenticated communication, TCP uses TCP Enhanced Authentication Option. Currently
different vendors use different Kind value to represent the TCP Enhanced Authentication Option
type. So in order to communicate with other vendors, kind value should be made configurable
based on the type of vendor to which it is connected. Similarly TCP Enhanced Authentication
Option has a field named algorithm ID which represents the authentication algorithm type. As
algorithm IDs are not defined by IANA(Internet Assigned Numbers Authority), Currently
different vendor uses different algorithm ID to represent the same algorithm.
In order to communicate with the other vendors, user has to configure the TCP algorithm ID in
the key chain for the algorithms depending on the peer node type.
Pre-configuration Tasks
Before configuring the Keychain feature on the peer Router s, configure the Network Time
Protocol (NTP) so that the time is consistent on the two Router s.
Data Preparation
To configure basic keychain features, you need the following data.
No.
Data
1
Keychain Name
2
TCP kind value
3
TCP algorithm id for each authentication algorithm
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
13 Keychain Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
274