Allied Telesis AT-AR3050S Command Reference Manual page 875

Next-generation firewall
Hide thumbs Also See for AT-AR3050S:
Table of Contents

Advertisement

OSPF
3
IP
6 C
V
FOR
V
OMMANDS
6
IPV
OSPF AUTHENTICATION SPI
Use the null keyword to override existing area authentication. Apply the null
keyword if area authentication is already configured to configure authentication
on an interface.
See the
and examples.
NOTE
with this command, or an OSPFv3 area with the
command.
When you configure authentication for an area, the security policy is applied to all
VLAN interfaces in the area. Allied Telesis recommends a different authentication
security policy is applied to each interface for higher security.
If you apply the ipv6 ospf authentication null command this affects
authentication configured on both the VLAN interface and the OSPFv3 area.
This is due to OSPFv3 hello messages ingressing VLAN interfaces, which are part of area
authentication, not being authenticated. So neighbors time out.
Example
To enable MD5 authentication with a 32 hexadecimal character key for interface
VLAN 2, use the commands:
awplus#
awplus(config)#
awplus(config-if)#
1234567890ABCDEF1234567890ABCDEF
To enable SHA-1 authentication with a 32 hexadecimal character key for interface
VLAN 2, use the commands:
awplus#
awplus(config)#
awplus(config-if)#
1234567890ABCDEF1234567890ABCDEF12345678
To specify no authentication is applied to interface VLAN 2, use the commands:
awplus#
awplus(config)#
awplus(config-if)#
To disable authentication for interface VLAN 2, use the commands:
awplus#
awplus(config)#
awplus(config-if)#
Related
area authentication ipsec spi
Commands
area encryption ipsec spi esp
ipv6 ospf encryption spi esp
show ipv6 ospf interface
C613-50077-01 REV A
OSPFv3 Feature Overview and Configuration Guide
: You can configure an authentication security policy (SPI) on a VLAN interface
configure terminal
interface vlan2
area 1 authentication ipsec spi 1000 md5
configure terminal
interface vlan2
ipv6 ospf authentication ipsec spi 1000 sha1
configure terminal
interface vlan2
ipv6 ospf authentication null
configure terminal
interface vlan2
no ipv6 ospf authentication ipsec spi 1000
Command Reference for AT-AR3050S
AlliedWare Plus™ Operating System - Version 5.4.5-2.x
for more information
area authentication ipsec spi
875

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents