Got it

OSPF Authentification

Created: Nov 16, 2021 17:38:58Latest reply: Nov 17, 2021 01:02:23 298 6 1 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi Everyone,


I'm preparing for the HCIA datacom certification by following the iLearning course (Datacom 1.0), In the mock exam I got a question (choose the statement that is false) about OSPF authentification which wasn't covered in the online course .I want to know the difference between Area authentification and Interface authentification ,and how are they related to each other.


Thanks in advance !

    

Featured Answers

Best answer

Recommended answer

jason_hu
Admin Created Nov 17, 2021 01:02:23

Hi friend!


Basic principles of OSPF authentication


If authentication is configured on an interface, interface-based authentication is used. If the interface-based authentication is null, the interface-based authentication is not performed. If no authentication is configured on the interface (null indicates that no authentication is configured), the authentication configured in the area is used. If no authentication is configured in the area, no authentication is performed.


The difference between interface authentication and area authentication is as follows: OSPF authentication specifies only the authentication type, including 0, 1, 2, NULL, plain and cipher. The early OSPF implementation supports only area authentication. When area authentication is enabled, it means that all OSPF protocol messages sent and received by interfaces in this area need to contain authentication fields. Therefore, OSPF messages on all interfaces need to be authenticated. This is obviously not flexible. Many vendors have implemented interface-based authentication in the future. This greatly improves the flexibility of OSPF authentication. That is, OSPF authentication can be based on interfaces or areas.


Hope this helps!

View more
  • x
  • convention:

smileymind
smileymind Created Nov 17, 2021 05:21:55 (0) (0)
 
hich_liebert
hich_liebert Created Nov 19, 2021 17:59:28 (0) (0)
Thank you for the clear explanation !  
All Answers
BAZ
BAZ MVE Author Created Nov 16, 2021 17:48:35

The basic principles of OSPF authentication are as follows:

If authentication is configured on the interface, use the authentication on the interface. If null is configured on the interface, no authentication is performed on the interface.


If no authentication is performed on the interface (Null does not mean that no authentication is configured), the authentication configured on the area is used. If no authentication is configured on the area, either, no authentication will be performed.


Authentication commands in the area view:

authentication-mode simple [ plain plain-text | [ cipher ] cipher-text ]
authentication-mode { md5 | hmac-md5 | hmac-sha256 } [ key-id { plain plain-text | [ cipher ] cipher-text } ]
authentication-mode keychain keychain-name

Authentication commands on a common OSPF interface:

ospf authentication-mode simple [ plain plain-text | [ cipher ] cipher-text ]
ospf authentication-mode { md5 | hmac-md5 | hmac-sha256 } [ key-id { plain plain-text | [ cipher ] cipher-text } ]
ospf authentication-mode null
ospf authentication-mode keychain keychain-name


View more
  • x
  • convention:

smileymind
smileymind Created Nov 17, 2021 05:22:00 (0) (0)
 
hich_liebert
hich_liebert Created Nov 19, 2021 17:59:45 (0) (0)
Thank you for your answer !  

Hi friend!


Basic principles of OSPF authentication


If authentication is configured on an interface, interface-based authentication is used. If the interface-based authentication is null, the interface-based authentication is not performed. If no authentication is configured on the interface (null indicates that no authentication is configured), the authentication configured in the area is used. If no authentication is configured in the area, no authentication is performed.


The difference between interface authentication and area authentication is as follows: OSPF authentication specifies only the authentication type, including 0, 1, 2, NULL, plain and cipher. The early OSPF implementation supports only area authentication. When area authentication is enabled, it means that all OSPF protocol messages sent and received by interfaces in this area need to contain authentication fields. Therefore, OSPF messages on all interfaces need to be authenticated. This is obviously not flexible. Many vendors have implemented interface-based authentication in the future. This greatly improves the flexibility of OSPF authentication. That is, OSPF authentication can be based on interfaces or areas.


Hope this helps!

View more
  • x
  • convention:

smileymind
smileymind Created Nov 17, 2021 05:21:55 (0) (0)
 
hich_liebert
hich_liebert Created Nov 19, 2021 17:59:28 (0) (0)
Thank you for the clear explanation !  

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.