Re: md5 authentication for OSPF

From: jpritcha@xxxxxxx
Date: Thu Nov 16 2000 - 12:22:16 GMT-3


   
Julie,

I believe the rule here is that you turn on authentication by area and all
routers in that area must agree on the authentication type. You can have
different passwords within an area. If R1 and R2 are connected via a frame
relay link and R2 and R3 are connected via an HDLC link (and all 4
interfaces are in the same area) you could use one password between R1 and
R2 and a different password between R2 and R3.

Jim

Please respond to "Connary, Julie Ann" <jconnary@cisco.com>

Sent by: nobody@groupstudy.com

To: ccielab@groupstudy.com
cc:

Subject: md5 authentication for OSPF

Hi All,

researching out MD5 authentication for OSPF yields the following two
methods:

ip ospf message-digest-key keyid md5 key (used under the interface)

area area-id authentication message-digest (used under "router ospf
<process-id>")

I am assuming that if an interface is a Frame-Relay with multiple
frame-relay map statements for spokes, that
MD5 authentication must also be used on ALL spokes?

Is there a way to just enable MD5 authentication to a particular neighbor
in a hub and spoke environment? I'm working
on a lab that says that I have to set up the hub with a physical interface
with frame-relay map statements to two spokes (all three routers in Area
0), and then it says to configure MD5 authentication to only one of the
spokes - I'm not sure this is possible.

Thanks,

Julie Ann
------------------------------------------------------------------------
                                         Julie Ann Connary
           | | Network Consulting Engineer
          ||| ||| Federal Support Program
        .|||||. .|||||. 13635 Dulles Technology Drive,
Herndon VA 20171
      .:|||||||||:.:|||||||||:. Pager: 1-888-642-0551
     c i s c o S y s t e m s Email: jconnary@cisco.com

------------------------------------------------------------------------



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 08:25:45 GMT-3