Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

Bronze

key chain ,md5 authentication in ospf

Hi every body

Can we use key chain with ospf for md5 authenticatin?

My book shows an example of using key chain with eigrp for md5 autentication. I am just wondering if the same is possible for ospf.

thanks

2 ACCEPTED SOLUTIONS

Accepted Solutions
Cisco Employee

Re: key chain ,md5 authentication in ospf

Hi Sarah,

OSPF is not using key chain, it is using authentication key you configured in the OSPF process or interface level.

http://www.cisco.com/en/US/docs/ios/iproute/configuration/guide/irp_ospf_cfg_ps6350_TSD_Products_Configuration_Guide_Chapter.html#wp1054174

HTH,

jerry

Re: key chain ,md5 authentication in ospf

That is correct

Here is an example how you do it:

Interface level:

R5(config-if)#ip ospf authentication message-digest

R5(config-if)#ip ospf authentication-key MYKEY

Or

Process-level:

R5(config-router)#area 0 authentication message-digest

R5(config-if)#ip ospf authentication-key MYKEY

The authentication-key is typed at the interface level.

Key chain is for EIGRP or RIP

5 REPLIES
Cisco Employee

Re: key chain ,md5 authentication in ospf

Hi Sarah,

OSPF is not using key chain, it is using authentication key you configured in the OSPF process or interface level.

http://www.cisco.com/en/US/docs/ios/iproute/configuration/guide/irp_ospf_cfg_ps6350_TSD_Products_Configuration_Guide_Chapter.html#wp1054174

HTH,

jerry

in case someone else find

in case someone else find this post, currently IOS-XE (and may be XR) does support key chain,
have a look here: http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_ospf/configuration/xe-3s/iro-xe-3s-book/iro-ospfv2-crypto-authen-xe.html

Re: key chain ,md5 authentication in ospf

That is correct

Here is an example how you do it:

Interface level:

R5(config-if)#ip ospf authentication message-digest

R5(config-if)#ip ospf authentication-key MYKEY

Or

Process-level:

R5(config-router)#area 0 authentication message-digest

R5(config-if)#ip ospf authentication-key MYKEY

The authentication-key is typed at the interface level.

Key chain is for EIGRP or RIP

Cisco Employee

Re: key chain ,md5 authentication in ospf

Hi,

Key chain is for EIGRP or RIP

... or for IS-IS with the new-style authentication :)

Best regards,

Peter

New Member

I know I'm posting on a very

I know I'm posting on a very old thread but I feel it necessary to point out that this is incorrect just in case someone stumbles across this post as I have.

R5(config-if)#ip ospf authentication message-digest

R5(config-if)#ip ospf authentication-key MYKEY (This is the command used for a plain text authentication key. This in combination with the above command would cause authentication not to be used at all.)

The correct configuration would be as follows:

R5(config-if)#ip ospf authentication message-digest

R5(config-if)#ip ospf message-digest-key 1 md5 MYKEY

The same applies for process level configuration.

5799
Views
6
Helpful
5
Replies
CreatePlease to create content