Packet Formats - Alcatel-Lucent 7450 System Management Manual

Ethernet service switch
Hide thumbs Also See for 7450:
Table of Contents

Advertisement

TCP Enhanced Authentication Option
The TCP Enhanced Authentication Option is a TCP extension that enhances security for BGP,
LDP and other TCP-based protocols. This includes the ability to change keys in a BGP or LDP
session seamlessly without tearing down the session. It is intended for applications where
secure administrative access to both the end-points of the TCP connection is normally
available.
TCP peers can use this extension to authenticate messages passed between one another. This
strategy improves upon current practice, which is described in RFC 2385, Protection of BGP
Sessions via the TCP MD5 Signature Option. Using this new strategy, TCP peers can update
authentication keys during the lifetime of a TCP connection. TCP peers can also use stronger
authentication algorithms to authenticate routing messages.

Packet Formats

0
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Option Syntax
Page 60
1
Kind
| Length
Authentication Data |
| // |
Kind: 8 bits
The Kind field identifies the TCP Enhanced Authentication Option. This value will be
assigned by IANA.
Length: 8 bits
The Length field specifies the length of the TCP Enhanced Authentication Option, in
octets. This count includes two octets representing the Kind and Length fields.
The valid range for this field is from 4 to 40 octets, inclusive.
For all algorithms specified in this memo the value will be 16 octets.
T-Bit: 1 bit
The T-bit specifies whether TCP Options were omitted from the TCP header for the
purpose of MAC calculation. A value of 1 indicates that all TCP options other than the
Extended Authentication Option were omitted. A value of 0 indicates that TCP
options were included.
The default value is 0.
K-Bit: 1 bit
This bit is reserved for future enhancement. Its value MUST be equal to zero.
Alg ID: 6 bits
The Alg ID field identifies the MAC algorithm.
2
|T|K|
Alg ID|Res|
7450 ESS System Mangement Guide
3
Key ID |

Advertisement

Table of Contents
loading

Table of Contents