Configuring Vrrp Authentication (Ipv4 Only) - Juniper EX9200 Features Manual

High availability feature guide ex series
Hide thumbs Also See for EX9200:
Table of Contents

Advertisement

High Availability Feature Guide for EX9200 Switches
Release History Table
Related
Documentation

Configuring VRRP Authentication (IPv4 Only)

134
Release
Description
13.2
Starting in Junos OS Release 13.2, VRRP nonstop active routing (NSR) is enabled
only when you configure the
routing-options]
routing-options]
Configuring a Logical Interface to Be Tracked for a VRRP Group on page 141
Configuring a Route to Be Tracked for a VRRP Group on page 143
Junos OS Support for VRRPv3 on page 121
Understanding VRRP on page 119
Configuring the Startup Period for VRRP Operations on page 129
Configuring VRRP Authentication (IPv4 Only) on page 134
Configuring the Advertisement Interval for the VRRP Master Router on page 135
Configuring VRRP on page 150
VRRP (IPv4 only) protocol exchanges can be authenticated to guarantee that only trusted
routing platforms participate in routing in an autonomous system (AS). By default, VRRP
authentication is disabled. You can configure one of the following authentication methods.
Each VRRP group must use the same method.
Simple authentication—Uses a text password included in the transmitted packet. The
receiving routing platform uses an authentication key (password) to verify the packet.
Message Digest 5 (MD5) algorithm—Creates the authentication data field in the IP
authentication header. This header is used to encapsulate the VRRP PDU. The receiving
routing platform uses an authentication key (password) to verify the authenticity of
the IP authentication header and VRRP PDU.
To enable authentication and specify an authentication method, include the
statement:
authentication-type
authentication-type
authentication;
can be
authentication
simple
routing platforms in the VRRP group.
You can include this statement at the following hierarchy levels:
[edit interfaces interface-name unit logical-unit-number family inet address address
vrrp-group group-id]
[edit logical-systems logical-system-name interfaces interface-name unit
logical-unit-number family inet address address vrrp-group group-id]
nonstop-routing
[edit logical system logical-system-name
or
hierarchy level.
or
. The authentication type must be the same for all
md5
[edit
statement at the
Copyright © 2017, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

Table of Contents