■
mpls ldp igp sync holddown
■
mpls ldp sync
Configuring LDP MD5 Authentication
LDP MD5 authentication provides protection against spoofed TCP segments that can
be introduced into the connection streams for LDP sessions. Authentication is
configurable for both directly connected and targeted peers.
You configure a shared secret (password) on potential LDP peers. Any given pair of
peers must share the same password. When a peer sends a TCP segment to an LSR,
it uses the password and the segment to compute an MD5 digest that it sends along
with the segment.
When the LSR receives the segment, the LSR calculates its own version of the digest
using its instance of the password and the segment. The LSR validates the segment
if the local digest matches the received digest. If the comparison fails—for example,
if the password is not configured the same on both peers—the LSR drops the segment
and does not send a response to the peer.
You can optionally enable a strict authentication mode that allows only peers
configured with passwords to establish sessions. In this mode, LDP hello messages
from peers that have no password are ignored. If you do not configure strict
authentication, then peers that do not have configured passwords can establish
connections with each other.
If you configure LDP MD5 authentication or change the authentication password for
a peer while it is in an established LDP session, MPLS restarts that session.
To configure LDP MD5 authentication:
1.
Set the password for an LDP peer.
host1(config)#
mpls ldp neighbor 10.3.5.1 password rop23ers
2.
(Optional) Set strict LDP authentication mode so that only peers with passwords
can establish LDP sessions.
host1(config)#
mpls ldp strict-security
Related Topics
■
Basic MPLS Configuration Tasks on page 264
■
Additional LDP Configuration Tasks on page 277
■
mpls ldp neighbor password
■
mpls ldp strict-security
Configuring LDP MD5 Authentication
■
281
Chapter 3: Configuring MPLS
Содержание JUNOSE
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 24: ...xxiv Table of Contents JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 37: ...Part 1 Border Gateway Protocol Configuring BGP Routing on page 3 Border Gateway Protocol 1...
Страница 38: ...2 Border Gateway Protocol JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 234: ...198 Monitoring BGP JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 236: ...200 Multiprotocol Layer Switching JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 298: ...262 Point to Multipoint LSPs Configuration JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 346: ...310 Example Traffic Class Configuration for Differentiated Services JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 535: ...There is no no version See undebug ip mbgp Monitoring BGP MPLS VPNs 499 Chapter 5 Configuring BGP MPLS Applications...
Страница 536: ...500 Monitoring BGP MPLS VPNs JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 538: ...502 Layer 2 Services Over MPLS JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 592: ...556 Multiple ATM Virtual Circuits over a Single Pseudowire Example JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 604: ...568 Virtual Private LAN Service JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 618: ...582 VPLS References JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 642: ...606 VPLS Configuration Example with LDP Signaling JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 674: ...638 Virtual Private Wire Service JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 718: ...682 Monitoring MPLS Forwarding Table for VPWS JUNOSe 11 0 x BGP and MPLS Configuration Guide...
Страница 719: ...Part 6 Index Index on page 685 Index 683...
Страница 720: ...684 Index JUNOSe 11 0 x BGP and MPLS Configuration Guide...