Re: OSPF Virtual link and area authentication (md5)

From: Jason Aarons (jaarons@xxxxxxxxxxx)
Date: Sun Sep 12 1999 - 23:57:28 GMT-3


   
What does "debug ip ospf adj" show ?

----Original Message Follows----
From: Mason Harris <MHarris@nspnet.com>
Reply-To: Mason Harris <MHarris@nspnet.com>
To: "'ccielab@groupstudy.com'" <ccielab@groupstudy.com>
Subject: OSPF Virtual link and area authentication (md5)
Date: Sun, 12 Sep 1999 20:23:04 -0400

Hello All--

My lab routers are all 11.2 configured in a typical multi-area OSPF config
like this:

    area 0 area 1 area 2
r1--------r3=========r5---------r4

R1 and r3 are part of area 0
r3 and r5 are part of area 1 (w/ virtual-link)
r5 and r4 are part of area 2

First, everything works as expected without any authentication. I see all
routes both E1, E2, IA, etc. (this is part of a bigger lab config)

Problem is when I configure authentication and the appropriate key and
password on the respective interfaces of Area 0, everything works great,
except for area 2 and the virtual link.

Area 2 will not see any OSPF (IA or external) routes via the vlink unless I
configure r5 with the area 0 authentication message-digest command under
OSPF but with NO key or password statement under any interface.

But the behavior is inconsistent. After i remove the authentication
statement on r5 and do a shut/no shut on r5's s0 intf, sometimes the routes
come back and sometimes they don't. Sho ip ospf virtual-link shows it is
always up, irregardless if routes appear or don't.

I am pulling my hair out. Anybody know if this is a bug or if I am just
missing the big picture? Can provide config snippets, if necessary.

TIA,
Mason



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 08:21:50 GMT-3