Configuring OSPF Configuring OSPF Authentication.

Slides:



Advertisements
Similar presentations
© 2007 Cisco Systems, Inc. All rights reserved.ICND2 v1.0—4-1 Single-Area OSPF Implementation Implementing OSPF.
Advertisements

Chapter 7 RIP version 2.
一、统计范围 注册地在湖里区的具有房地产开发资质的 房地产开发企业 无论目前是否有开发项目 无论开发的项目是在湖里区还是在其他区 没有开发项目的企业需要报送年报和月报 中的资金表(空表)。 新成立的项目公司,要先入库,再报报表。
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicBSCI Configuring EIGRP BSCI Module 2-4 – Configuring EIGRP Authentication.
© 2007 Cisco Systems, Inc. All rights reserved.ICND2 v1.0—5-1 EIGRP Implementation Implementing EIGRP.
位置相关查询处理 研究背景及意义 移动计算、无线通信以及定位技术的快速发展,使 得位置相关的查询处理及基于位置的信息服务技术 已经成为一个热点研究领域 。 大量的应用领域 ( 如地理信息系统、智能导航、交 通管制、天气预报、军事、移动电子商务等 ) 均迫 切需要有效地查询这些数据对象。
1 © 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicBSCI Module 3 OSPF BSCI Module 3.
吉林大学远程教育课件 主讲人 : 杨凤杰学 时: 64 ( 第六十二讲 ) 离散数学. 最后,我们构造能识别 A 的 Kleene 闭包 A* 的自动机 M A* =(S A* , I , f A* , s A* , F A* ) , 令 S A* 包括所有的 S A 的状态以及一个 附加的状态 s.
1 为了更好的揭示随机现象的规律性并 利用数学工具描述其规律, 有必要引入随 机变量来描述随机试验的不同结果 例 电话总机某段时间内接到的电话次数, 可用一个变量 X 来描述 例 检测一件产品可能出现的两个结果, 也可以用一个变量来描述 第五章 随机变量及其分布函数.
计算机文化基础 第 13 章 多表操作. 多表操作 以前所进行的操作中,在同一时刻只能打开一个表文 件,这是单工作区操作。但是在有些情况下,我们需要同时 了解多个表文件中的内容,例如 图 8-1 。在表文件 Stud1.DBF 中,有姓名,班级,电话三项;在 Stud2.DBF 中, 有姓名,性别,籍贯,英语四个字段。在单工作区操作方式.
例9:例9: 第 n-1 行( -1 )倍加到第 n 行上,第( n-2 ) 行( -1 )倍加到第 n-1 行上,以此类推, 直到第 1 行( -1 )倍加到第 2 行上。
数 学 系 University of Science and Technology of China DEPARTMENT OF MATHEMATICS 第 3 章 曲线拟合的最小二乘法 给出一组离散点,确定一个函数逼近原函数,插值是这样的一种手段。 在实际中,数据不可避免的会有误差,插值函数会将这些误差也包括在内。
© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBSCI Configuring EIGRP BSCI Module 2-2 – Implementing and Verifying EIGRP.
主讲教师:陈殿友 总课时: 124 第十一讲 极限的运算法则. 第一章 二、 极限的四则运算法则 三、 复合函数的极限运算法则 一 、无穷小运算法则 机动 目录 上页 下页 返回 结束 §5 极限运算法则.
在发明中学习 线性代数 概念的引入 李尚志 中国科学技术大学. 随风潜入夜 : 知识的引入 之一、线性方程组的解法 加减消去法  方程的线性组合  原方程组的解是新方程的解 是否有 “ 增根 ” ?  互为线性组合 : 等价变形  初等变换  高斯消去法.
© 2009 Cisco Systems, Inc. All rights reserved. ROUTE v1.0—3-1 Implementing a Scalable Multiarea Network OSPF- Based Solution Configuring and Verifying.
© 2009 Cisco Systems, Inc. All rights reserved.ROUTE v1.0—6-1 Connecting an Enterprise Network to an ISP Network Configuring and Verifying Basic BGP Operations.
© 2009 Cisco Systems, Inc. All rights reserved. ROUTE v1.0—2-1 Implementing an EIGRP-Based Solution Implementing and Verifying EIGRP Authentication.
1 CCNA 3 v3.1 Module 2. 2 CCNA 3 Module 2 Single Area OSPF.
周期信号的傅里叶变换. 典型非周期信号 ( 如指数信号, 矩形信号等 ) 都是满足绝对可 积(或绝对可和)条件的能量信号,其傅里叶变换都存在, 但绝对可积(或绝对可和)条件仅是充分条件, 而不是必 要条件。引入了广义函数的概念,在允许傅里叶变换采用 冲激函数的前提下, 使许多并不满足绝对可积条件的功率.
Department of Mathematics 第二章 解析函数 第一节 解析函数的概念 与 C-R 条件 第二节 初等解析函数 第三节 初等多值函数.
1 第 7 章 存储过程、触发器和程序包 在很多时候,都需要保存 PL/SQL 程序块,以便 随后可以重新使用。这也意味着,程序块需要一个名 称,这样需才可以调用或者引用它。命名的 PL/SQL 程序块可被独立编译并存储在数据库中,任何与数据 库相连接的应用程序都可以访问这些存储的 PL/SQL 程序块。
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—3-1 Determining IP Routes Enabling RIP.
Chapter 5 IP Address Configuration Connecting People To Information.
© 2003, Cisco Systems, Inc. All rights reserved. CSPFA 3.1—4-1 EIGRP 配置 EIGRP 是一种高级的距离矢量型路由选择协议, 但它又依 赖于一些常见于链路状态型路由选择协议的特性。
OSPFv3 CIS 185 Advanced Routing (CCNP 1) Spring 2006 Rick Graziani Based on Chapter 4: Dynamic Routing Protocols, Routing TCP/IP 2 nd Edition, Jeff Doyle.
OSPF in Multiple Area.
Single-Area OSPF Implementation
1 © 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicBSCI Module 3 OSPF BSCI Module 3.
© 2003, Cisco Systems, Inc. All rights reserved. 1 配置 IS-IS 中间系统.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 5: Adjust and Troubleshoot Single- Area OSPF Scaling Networks.
Advantages of Dynamic Routing over Static Routing : Advertise only the directly connected networks. Updates the topology changes dynamically. Administrative.
OSPF 路由交換協定 王振生.
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—3-1 Determining IP Routes Enabling OSPF.
OSPF alfred. Step 1 建立校園骨幹 Dlink 3627 Lab, 含出口 Wan 建立 forti3950 學校 vlan and 10 筆靜態路由指到 Dlink 確認 dlink3627 與 forti 3950 學校 vlan 互通. Ex:3950 ERDC.
Cisco Public ITE PC v4.0 Chapter 管理你的网络环境 CCNA ( )
1 © 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicBSCI Module 3 OSPF SAvPS 2009 Genči.
Open standard protocol Successor of RIP Classless routing protocol Uses Shortest Path First (SPF) Algorithm Updates are sent through Multicast IP address.
E /24 LAN /24LAN – / /8 S0 S /8 Head Office Branch Office E /16.
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—3-1 Determining IP Routes Enabling RIP.
网络设计与管理实践 DHCP 和网络地址转换 首都师范大学信息工程学院
Border Gateway Protocol Route Summarization © 2003, Cisco Systems, Inc. All rights reserved. 1.
CCNA3 ’s PAQ PAQ Pre-Assessment Quiz Produced by Mohamed BEN HASSINE CNA Instructor The American University of Paris.
是什么? 有什么用? 机要文件科研成果商业机密 原创设计 重要资料,有时难免被泄露或被剽窃。
© 2002, Cisco Systems, Inc. All rights reserved. 1 Routing Overview.
Cisco proprietary protocol Classless routing protocol Metric (32 bit) : Composite Metric (BW + Delay) by default. Administrative distance is 90 Updates.
© 2003, Cisco Systems, Inc. All rights reserved..
PE3PE2 CE2-VPNACE1-VPNA MPLS/VPN Backbone MPLS VPN Lab Setup.
OSPF. OSPF 协议概述 链路状态信息 RTA RTC RTD RTB 链路状态数据库 每台路由器会将当前正确的链路状态信息向一定 的范围内的所有主机发送 它支持区域的概念,同一区域内的路由器最终都 可以拥有对此区域相同的拓扑描述 每台路由器接收到此信息之后,根据最短路径算 法计算最优的下一跳.
Jose Luis Flores / Amel Walkinshaw
Minimizing Service Loss and Data Theft in a Campus Network Describing STP Security Mechanisms.
© 2006, Shenzhen Polytechnic. All rights reserved. 1 Cisco 发现协议 Cisco Discovery Protocol 深圳职业技术学院计算机系网络专业.
Configuring EIGRP Configuring EIGRP Authentication.
OSPF – Link State Routing Protocol 1. Introduction to OSPF OSPF is: – Classless – Link-state routing protocol – Uses the concept of areas for scalability.
Basic Border Gateway Protocol Path Manipulation Using Route Maps © 2003, Cisco Systems, Inc. All rights reserved. 1.
人 有 悲 欢 离 合, 月有阴晴圆缺。月有阴晴圆缺。 华师大版七年级数学第二册 海口市第十中学 数学组 吴锐.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNP 1 v3.0 Module 4 Routing Information Protocol version 2.
Border Gateway Protocol Route Summarization © 2003, Cisco Systems, Inc. All rights reserved. 1.
111 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3: Switching Basics and Intermediate Routing v3.0.
--- CCIE R&S Advanced Lab Session 4 OSPF ---
§7.2 估计量的评价标准 上一节我们看到,对于总体 X 的同一个 未知参数,由于采用的估计方法不同,可 能会产生多个不同的估计量.这就提出一 个问题,当总体的一个参数存在不同的估 计量时,究竟采用哪一个好呢?或者说怎 样评价一个估计量的统计性能呢?下面给 出几个常用的评价准则. 一.无偏性.
ROUTING AND ROUTING TABLES 2 nd semester
Cisco Routers Routers collectively provide the main feature of the network layer—the capability to forward packets end-to-end through a network. routers.
OSPF BSCI Module 3.
Connecting an Enterprise Network to an ISP Network
報告題目:OSPF 指導教授:陳明仕 報告者:黃元志 學號M
EIGRP.
3D 老虎机 最好是在线老虎机游戏是一个赚钱而获 得乐趣的明确方式。 而他们愿意毫不犹豫地花钱。 在线老虎机游戏会给你一个很公平的优 势,因为它依赖运气和时间。
Implementing EIGRP EIGRP Implementation.
Rick Graziani Cabrillo College
Presentation transcript:

Configuring OSPF Configuring OSPF Authentication

OSPF Authentication Types OSPF supports 2 types of authentication: –Simple password (or plain text) authentication –MD5 authentication Router generates and checks every OSPF packet. Router authenticates the source of each routing update packet that it receives. Configure a “key” (password); each participating neighbor must have same key configured.

Configuring OSPF Simple Password Authentication ip ospf authentication-key password Router(config-if)# Assigns a password to be used with neighboring routers Router(config-if)# ip ospf authentication [message-digest | null] Specifies the authentication type for an interface (since Cisco IOS software 12.0) Router(config-router)# area area-id authentication [message-digest] Specifies the authentication type for an area (was in Cisco IOS software before 12.0) ( 如果有这个命令,则不需要在每个接 口上指定认证类型 2 命令,直接配置密码 1 命令,方便!)

Configuring OSPF Authentication 注意! 1 :如果配置了接口认证和区域认证,接口认证优先 。( 比如,区域是明文,接口上密文,还是密文。) 2 : ospf 认证有 3 类, 0 (无,默认) 1 (明文) 2 (密文) 3 :在区域里配置的命令可以不同,但是一对邻居之间必 须相同,如果是密文( md5 ), key-id ,密码都得相同

Example Simple Password Authentication Configuration Loopback

R2 Configuration for Simple Password Authentication interface Loopback0 ip address interface Serial0/0/1 ip address ip ospf authentication ip ospf authentication-key plainpas router ospf 10 log-adjacency-changes network area 0 network area 0

Verifying Simple Password Authentication R1#sh ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface FULL/ - 00:00: Serial0/0/1 R1#show ip route Gateway of last resort is not set /8 is variably subnetted, 2 subnets, 2 masks O /32 [110/782] via , 00:01:17, Serial0/0/1 C /24 is directly connected, Loopback /27 is subnetted, 1 subnets C is directly connected, Serial0/0/1 R1#ping Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to , timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 28/29/32 ms

Configuring OSPF MD5 Authentication ip ospf message-digest-key key-id md5 key Router(config-if)# Assigns a key ID and key to be used with neighboring routers Router(config-if)# ip ospf authentication [message-digest | null] Specifies the authentication type for an interface (since Cisco IOS software 12.0) Router(config-router)# area area-id authentication [message-digest] Specifies the authentication type for an area (was in Cisco IOS software before 12.0) 可以配置多个钥匙( key-id ),用于新旧密钥的替换,这样接口上 会发送多个 ospf 数据包 copy ,一旦新的可以使用,将旧的删除

Example MD5 Authentication Configuration

R2 Configuration for MD5 Authentication interface Loopback0 ip address interface Serial0/0/1 ip address ip ospf authentication message-digest ip ospf message-digest-key 1 md5 secretpass router ospf 10 log-adjacency-changes network area 0 network area 0

Verifying MD5 Authentication R1#sho ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface FULL/ - 00:00: Serial0/0/1 R1#show ip route Gateway of last resort is not set /8 is variably subnetted, 2 subnets, 2 masks O /32 [110/782] via , 00:00:37, Serial0/0/1 C /24 is directly connected, Loopback /27 is subnetted, 1 subnets C is directly connected, Serial0/0/1 R1#ping Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to , timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 28/28/32 ms

Troubleshooting Simple Password Authentication R1#debug ip ospf adj OSPF adjacency events debugging is on R1# *Feb 17 18:42:01.250: OSPF: 2 Way Communication to on Serial0/0/1, state 2WAY *Feb 17 18:42:01.250: OSPF: Send DBD to on Serial0/0/1 seq 0x9B6 opt 0x52 flag 0x7 len 32 *Feb 17 18:42:01.262: OSPF: Rcv DBD from on Serial0/0/1 seq 0x23ED opt0x52 flag 0x7 len 32 mtu 1500 state EXSTART *Feb 17 18:42:01.262: OSPF: NBR Negotiation Done. We are the SLAVE *Feb 17 18:42:01.262: OSPF: Send DBD to on Serial0/0/1 seq 0x23ED opt 0x52 flag 0x2 len 72 R1#show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface FULL/ - 00:00: Serial0/0/1 debug ip ospf adj Router# Displays the OSPF adjacency-related events

Troubleshooting Simple Password Authentication Problems R1# *Feb 17 18:51:31.242: OSPF: Rcv pkt from , Serial0/0/1 : Mismatch Authentication type. Input packet specified type 0, we use type 1 R2# *Feb 17 18:50:43.046: OSPF: Rcv pkt from , Serial0/0/1 : Mismatch Authentication type. Input packet specified type 1, we use type 0 Simple authentication on R1, no authentication on R2 R1# *Feb 17 18:54:01.238: OSPF: Rcv pkt from , Serial0/0/1 : Mismatch Authentication Key - Clear Text R2# *Feb 17 18:53:13.050: OSPF: Rcv pkt from , Serial0/0/1 : Mismatch Authentication Key - Clear Text Simple authentication on R1 and R2, but different passwords

Troubleshooting MD5 Authentication R1#debug ip ospf adj OSPF adjacency events debugging is on *Feb 17 17:14:06.530: OSPF: Send with youngest Key 1 *Feb 17 17:14:06.546: OSPF: 2 Way Communication to on Serial0/0/1, state 2WAY *Feb 17 17:14:06.546: OSPF: Send DBD to on Serial0/0/1 seq 0xB37 opt 0x52 flag 0x7 len 32 *Feb 17 17:14:06.546: OSPF: Send with youngest Key 1 *Feb 17 17:14:06.562: OSPF: Rcv DBD from on Serial0/0/1 seq 0x32F opt 0x52 flag 0x7 len 32 mtu 1500 state EXSTART *Feb 17 17:14:06.562: OSPF: NBR Negotiation Done. We are the SLAVE *Feb 17 17:14:06.562: OSPF: Send DBD to on Serial0/0/1 seq 0x32F opt 0x52 flag 0x2 len 72 *Feb 17 17:14:06.562: OSPF: Send with youngest Key 1 R1#show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface FULL/ - 00:00: Serial0/0/1

Troubleshooting MD5 Authentication Problems R1# *Feb 17 17:56:16.530: OSPF: Send with youngest Key 1 *Feb 17 17:56:26.502: OSPF: Rcv pkt from , Serial0/0/1 : Mismatch Authentication Key - No message digest key 2 on interface *Feb 17 17:56:26.530: OSPF: Send with youngest Key 1 R2# *Feb 17 17:55:28.226: OSPF: Send with youngest Key 2 *Feb 17 17:55:28.286: OSPF: Rcv pkt from , Serial0/0/1 : Mismatch Authentication Key - No message digest key 1 on interface *Feb 17 17:55:38.226: OSPF: Send with youngest Key 2 MD5 authentication on both R1 and R2, but R1 has key 1 and R2 has key 2, both with the same passwords:

Summary When authentication is configured, the router generates and checks every OSPF packet and authenticates the source of each routing update packet that it receives. OSPF supports two types of authentication: –Simple password (or plain text) authentication: The router sends an OSPF packet and key. –MD5 authentication: The router generates a message digest, or hash, of the key, key ID, and message. The message digest is sent with the packet; the key is not sent. To configure simple password authentication, use the ip ospf authentication-key password command and the ip ospf authentication command.

Summary (Cont.) To configure MD5 authentication, use the ip ospf message- digest-key key-id md5 key command and the ip ospf authentication message-digest command. Use show ip ospf neighbor, show ip route, and debug ip ospf adj to verify and troubleshoot both types of authentication. With MD5 authentication, the debug ip ospf adj command output indicates the key ID sent.