< Home

Configuring MSDP Key-Chain Authentication

You must configure Key-Chain authentication on both MSDP peers. Encryption algorithms and passwords configured for Key-Chain authentication on both peers must be the same; otherwise, the TCP connection cannot be set up between MSDP peers and MSDP messages cannot be transmitted. By default, MSDP Key-Chain authentication is not configured for MSDP. Configuring MSDP Key-Chain authentication is recommended to ensure system security.

Prerequisites

Context

Keychain and new TCP extension options enable each TCP connection to be configured with a password. You can set different encryption algorithms and validity periods for passwords. In addition, passwords can be changed at any time. This significantly improves security of encrypted packets.

Only MSDP packets passing keychain authentication are processed. This effectively prevents attacks that are conducted through malicious packets.

Procedure

  • Do as follows on the FW configured with MSDP peers:
    1. Access the system view.

      system-view

    2. Access the MSDP view.

      msdp [ vpn-instance vpn-instance-name ]

    3. Configure MSDP Key-Chain authentication.

      peer peer-address keychain keychain-name

      You must configure Key-Chain authentication on both MSDP peers. Encryption algorithms and passwords configured for Key-Chain authentication on both peers must be the same; otherwise, the TCP connection cannot be set up between MSDP peers and MSDP messages cannot be transmitted.

      Before configuring MSDP Key-Chain authentication, configure a Key-Chain in accordance with the configured keychain-name; otherwise, the TCP connection cannot be set up.

      MSDP MD5 authentication and MSDP Key-Chain authentication are mutually exclusive.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic