RE: ospf area authentication

From: "Hoonpongsimanont
Date: Tue Mar 29 2005 - 07:40:21 GMT-3


Hi John,

You have to wait for dead timer expiry before the other spoke declare
neighbor down. In NBMA interface, that timer is 120 seconds. Did you wait
that long?

One more thing, I think you don't need to configure key chain for OSPF
authentication.

Cheers,
David
-----Original Message-----
From: John Matus [mailto:john_matus@hotmail.com]
Sent: Tuesday, March 29, 2005 11:08 AM
To: ccielab@groupstudy.com
Subject: ospf area authentication

ok, here is the situation.
i go to enable area authtication for 3 router connected in hub-and-spoke
topology. the config is as follows:

all router:
router os 1
  area 1 authen message-digest

int s0/0
  ip o message-digest-key 1 md5 cisco

  key chan cisco
     key 1
        key-string cisco

so i've done that on the hub and one of the spokes, and the adjacencies of
those 2 routers go down and up as i input the interface level commands, but
the other spoke that is only configured with the area authentication and no
the interface level authentication STILL maintains its adjacency. why
exactly is that???? my expectation is that it would go down and stay down
untill i've configured the interface level authentication...............or
am i wrong (probably)....



This archive was generated by hypermail 2.1.4 : Sun Apr 03 2005 - 17:56:53 GMT-3