![Huawei S6700 Series Скачать руководство пользователя страница 557](http://html.mh-extra.com/html/huawei/s6700-series/s6700-series_configuration-manual_169517557.webp)
Prerequisites
The configurations for a BGP4+ confederation are complete.
Procedure
l
Run the
display bgp
ipv6
peer
[
verbose
] command to check detailed information about
BGP4+ peers.
----End
8.13 Configuring BGP4+ Security
To improve BGP4+ security, you can perform TCP connection authentication.
8.13.1 Establishing the Configuration Task
Before configuring BGP4+ network security, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This can help
you complete the configuration task quickly and accurately.
Applicable Environment
l
BGP4+ authentication
BGP4+ uses TCP as the transport layer protocol. To enhance BGP4+ security, you can
perform the Message Digest 5 (MD5) authentication when TCP connections are created.
The MD5 authentication, however, does not authenticate BGP4+ packets. Instead, it sets
MD5 authentication passwords for TCP connections, and the authentication is then
completed by TCP. If the authentication fails, TCP connections cannot be established.
Pre-configuration Tasks
Before configuring BGP4+ security, complete the following task:
l
Configuring Basic BGP4+ Functions
Data Preparation
Before configure BGP4+ security, you need the following data.
No.
Data
1
BGP4+ peer address or name of the peer group of each switch
2
MD5 authentication password
3
Key-Chain authentication name
8.13.2 Configuring MD5 Authentication
In MD5 authentication of BGP4+, you only need to set MD5 authentication passwords for TCP
connections, and the authentication is performed by TCP. If the authentication fails, TCP
connections cannot be established.
S6700 Series Ethernet Switches
Configuration Guide - IP Routing
8 BGP4+ Configuration
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
538