Configuring Generalized Ttl Security Mechanism (Gtsm) For Ospf - Cisco ASR 9000 Series Configuration Manual

Aggregation services router
Hide thumbs Also See for ASR 9000 Series:
Table of Contents

Advertisement

Configuring Generalized TTL Security Mechanism (GTSM) for OSPF

The following example shows output for configured keys that are active:
show key chain ospf_intf_1
Key-chain: ospf_intf_1/ -
Key 1 -- text "0700325C4836100B0314345D"
Key 2 -- text "10411A0903281B051802157A"
Key 3 -- text "06091C314A71001711112D5A"
Key 4 -- text "151D181C0215222A3C350A73"
Key 5 -- text "151D181C0215222A3C350A73"
Configuring Generalized TTL Security Mechanism (GTSM) for OSPF
This task explains how to set the security time-to-live mechanism on an interface for GTSM.
SUMMARY STEPS
1. configure
2. router ospf process-name
3. router-id { router-id }
4. log adjacency changes [ detail | disable ]
5. nsf { cisco [ enforce global ] | ietf [ helper disable ]}
6. timers throttle spf spf-start spf-hold spf-max-wait
7. area area-id
8. interface type interface-path-id
9. security ttl [ disable | hops hop-count ]
10. commit
11. show ospf [ process-name ] [ vrf vrf-name ] [ area-id ] interface [ type interface-path-id ]
Cisco ASR 9000 Series Aggregation Services Router Routing Configuration Guide, Release 5.1.x
406
Next 0(0)/0(0)
Last flood scan length is 2, maximum is 16
Last flood scan time is 0 msec, maximum is 0 msec
Neighbor Count is 1, Adjacent neighbor count is 1
Adjacent with neighbor 1.1.1.1
Suppress hello for 0 neighbor(s)
Keychain-based authentication enabled
Key id used is 3
Multi-area interface Count is 0
cryptographic-algorithm -- MD5
Send lifetime:
11:30:30, 01 May 2007 - (Duration) 600
Accept lifetime: Not configured
cryptographic-algorithm -- MD5
Send lifetime:
11:40:30, 01 May 2007 - (Duration) 600
Accept lifetime: Not configured
cryptographic-algorithm -- MD5
Send lifetime:
11:50:30, 01 May 2007 - (Duration) 600
Accept lifetime: Not configured
cryptographic-algorithm -- MD5
Send lifetime:
12:00:30, 01 May 2007 - (Duration) 600
Accept lifetime: Not configured
cryptographic-algorithm -- MD5
Send lifetime:
12:10:30, 01 May 2007 - (Duration) 600
Accept lifetime: Not configured
(Backup Designated Router)
[Valid now]
Implementing OSPF
OL-30423-03

Advertisement

Table of Contents
loading

Table of Contents