OSPF Auth with Key Rollover on Hub & Spoke (non-broadcast)

From: Bill Wagner (billccie2b@hotmail.com)
Date: Wed Jul 26 2006 - 19:49:18 ART


Can anyone please help me solve this problem regarding OSPF authentication?

The topology is a hub and spoke frame-relay network where the spokes can
talk to each other through the hub. OSPF is running in a non-broadcast mode.
Due to the topology I set the spokes to have an OSPF priority of 0 and
create neighbor statements on the hub. I build key 1 for all three devices.
From there I create a new key for the rollover on the hub and only one spoke
as per the requirements. If I reset the peers the spoke with the old key
will not come back online. Debug shows that only the new key is being sent
to the spoke which it does not accept because it does not know about it.
Since the spokes have a priority of 0 I am unable to install a neighbor
statement in the ospf routing process on the spoke using the old key. The
only solution I could find was to bump the priority up on the spoke with the
old key, but this presents a problem if the spoke router boots before the
hub since OSPF does not support premption. Can anyone tell me what I am
missing or if this is not possible? Oh one more thing is that I cannot
change the OSPF network type or the frame relay topology.

Thanks in advance,

Bill



This archive was generated by hypermail 2.1.4 : Tue Aug 01 2006 - 07:13:48 ART