Key-Source Key-Chain - Cisco CRS Configuration Manual

Ios xr mpls configuration guide
Hide thumbs Also See for CRS:
Table of Contents

Advertisement

Implementing RSVP for MPLS-TE and MPLS O-UNI
This table shows how to locate the source and destination address keys for an SA that is based on the message
type.
Table 4: Source and Destination Address Locations for Different Message Types
Message Type
Path
PathTear
PathError
Resv
ResvTear
ResvError
ResvConfirm
Ack
Srefresh
Hello
Bundle
Related Topics
Specifying the Keychain for RSVP Neighbor Authentication, on page 142
RSVP Neighbor Authentication: Example, on page 151
Configuring a Lifetime for RSVP Neighbor Authentication, on page 143
RSVP Authentication Global Configuration Mode: Example, on page 150

Key-source Key-chain

The key-source key-chain is used to specify which keys to use.
You configure a list of keys with specific IDs and have different lifetimes so that keys are changed at
predetermined intervals automatically, without any disruption of service. Rollover enhances network security
by minimizing the problems that could result if an untrusted source obtained, deduced, or guessed the current
key.
RSVP handles rollover by using the following key ID types:
• On TX, use the youngest eligible key ID.
• On RX, use the key ID that is received in an integrity object.
Source Address Location
HOP object
HOP object
HOP object
HOP object
HOP object
HOP object
IP header
IP header
IP header
IP header
Cisco IOS XR MPLS Configuration Guide for the Cisco CRS Router, Release 5.1.x
Key-source Key-chain
Destination Address Location
SESSION object
SESSION object
IP header
IP header
IP header
IP header
CONFIRM object
IP header
IP header
IP header
121

Advertisement

Table of Contents
loading

Table of Contents