Ospf And Route Redistribution - Avaya 8800 Configuration Manual

Ethernet routing switch
Table of Contents

Advertisement

security mechanisms prevent a malicious person from joining an OSPF domain and advertising
false information in the OSPF LSAs. Likewise, security prevents a misconfigured router from
joining an OSPF domain.
Simple Password
The Simple Password security mechanism is a simple-text password mechanism; only routers
that contain the same authentication ID in their LSA headers can communicate with each
other.
Avaya recommends that you not use this security mechanism because the password is stored
in plain text and can be read from the configuration file or from the LSA packet.
Message Digest 5
Avaya recommends that you use Message Digest 5 (MD5) for OSPF security because it
provides standards-based (RFC 1321) authentication using 128-bit encryption. When you use
MD5 for OSPF security, it is almost impossible for a malicious user to compute or extrapolate
the decrypting codes from the OSPF packets.
When you use MD5, each OSPF packet has a message digest appended to it. The digest must
be matched between sending and receiving routers. The message digest is calculated at both
the sending and receiving routers based on the MD5 key and any padding, and then compared.
If the message digest computed at the sender and receiver does not match, the packet is
rejected.

OSPF and route redistribution

Redistribution imports routes from one protocol to another. Redistribution sends route updates
for a protocol-based route through another protocol. For example, if OSPF routes exist in a
router and they must be sent through a BGP network, then configure redistribution of OSPF
routes through BGP. This sends OSPF routes to a router that uses BGP.
Routes can be redistributed:
• on an interface basis
• on a global basis between protocols on a single VRF instance (intraVRF)
• between the same or different protocols on different VRF instances (interVRF)
Configure interface-based redistribution by configuring a route policy and applying it to the
interface. Configure the route policy with the match parameter set to the protocol from which
routes should be learned. For example, to redistribute RIP routes to OSPF, apply the following
route policy to a RIP-enabled interface:
config ip route-policy ospf_pol seq 1 create
Configuration — OSPF and RIP
Open Shortest Path First
June 2011
53

Advertisement

Table of Contents
loading

This manual is also suitable for:

8600

Table of Contents