EIGRP authentication using key chain with validity period

From: Anh Khoa Le Viet <lvakhoa_at_gmail.com>
Date: Sat, 11 Jul 2009 19:36:32 +0800

Hi Group,

I took a mock lab from a vendor today with task about the EIGRP
authentication: An MD5 hash of the password CISCO1 should be used from
12:00AM on
1/1/2006 to 11:59PM on 12/31/2006 and An MD5 hash of the password CISCO2
should be used after this. I think I come out with the right solution:

key chain EIGRP
 key 1
  key-string CISCO1
  accept-lifetime 00:00:00 Jan 1 2006 00:29:59 Jan 1 2007
  send-lifetime 00:00:00 Jan 1 2006 11:59:59 Dec 31 2006
 key 2
  key-string CISCO2
  accept-lifetime 00:00:00 Jan 1 2007 infinite
  send-lifetime 00:00:00 Jan 1 2007 infinite

But the thing is: do we need to configure ntp server and client for this
kind of task? At the time I did the configuration, the clock showed in
Routers is 2009 year time. But at the end of the lab, I did reboot all the
routers and found out that EIGRP did come up, quickly found that the clock
was back to 2002 and no EIGRP neighbors came up :(. We can not do set
datetime manually on the routers as if we reboot, it will came back to
default datetime, so the only option is NTP.

Could you pleas give some advise on this kind of task? Should we add NTP in
the real lab or no need to do that if in the IP Services portion, no NTP
task?

Thanks and best Regards,
Khoa

Blogs and organic groups at http://www.ccie.net
Received on Sat Jul 11 2009 - 19:36:32 ART

This archive was generated by hypermail 2.2.0 : Sat Aug 01 2009 - 13:10:22 ART