RE: HSRP authentication FUN

From: Colin Barber (Colin.Barber@telewest.co.uk)
Date: Mon Sep 09 2002 - 05:16:57 GMT-3


Yes, the default password is cisco.

http://www.cisco.com/univercd/cc/td/doc/product/lan/c3550/1216ea1/3550scg/sw
hsrp.htm#xtocid203077

from the link:
(Optional) authentication string-Enter a string to be carried in all HSRP
messages. The authentication string can be up to eight characters in length;
the default string is cisco.

Colin

-----Original Message-----
From: Volkov, Dmitry (Toronto - BCE) [mailto:dmitry_volkov@ca.ml.com]
Sent: 08 September 2002 22:54
To: 'ccielab@groupstudy.com'
Subject: HSRP authentication FUN

Hi,

Maybe many of you guys khow that, but it took me a while until I got it:

by default HSRP uses authentication word 'cisco'.

I put : standby 1 authentication 'cisco' on one router and no standby auth
on the other one:
HSRP was working ! I put another word : ccie instead of cisco and standby
group was broken:

06:53:21: %STANDBY-3-BADAUTH: Bad authentication from 170.240.8.1, group 1,
remote state Active

I put sniffer and found that both routers with hsrp auth enabled and without
one exchange hellos with word 'cisco' in auth field of hello packet. So they
are authenticated by default without "standby authentication" command :)

Dmitry
------------------------------------------------------------------------------
Live Life in Broadband
www.telewest.co.uk

The information transmitted is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material.
Statements and opinions expressed in this e-mail may not represent those of the company. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender immediately and delete the material from any computer.

==============================================================================



This archive was generated by hypermail 2.1.4 : Mon Oct 07 2002 - 07:43:47 GMT-3