Search:

Writers' Community!

Article Submission
We Need YOUR Articles!
We'll Promote Them for FREE!

Author Login

New Authors
Register Here


Now Serving 5,475 Authors
46,463 Quality Articles
& 4,649 Current Users Online!
Featured Authors
Mr. Keith (1,766)
Barbara Clark (402)
Ieuan Dolby (1,355)
Sandra E. Graham (1,486)
Jeff Brown (5,324)
Michelle Mackin (5,836)
Dianne Lehmann (2,607)
mogama (17,941)
Joel Hendon (4,270)
April Lorier (6,148)
Beth Tabak (40)
Laura Trahan (32,829)
Susan Thom (8,066)
Mike Fak (3,493)

View All Featured Authors
Most Recent
Cisco CCNA, CCNP, and Security Practice Exam: Frame Relay, NTP, Authentication, And More!

Cisco CCNA, CCNP, And Security Practice Exam: Frame Relay, The IPS, And More!

Cisco CCNA And CCNP Practice Exam: HDLC, PPP, Secure Remote Connections, And More!

Blu-ray Media Format

How to become CCIE certified

Preparing for the CCIE Certification Program

Understanding CCIE

Cisco CCNA, CCNP, Security, And CCENT Practice Exam Questions: Debugging RIP, SDM, And More!

Cisco CCNA, CCNP, and CCENT Questions: SDM, Lily Pad Networks, and More!

CCNA Security Practice Exam: 10 Questions On The IOS Firewall Set

Home » Categories » Computers & Networking » Technical Certification » Cisco CCNP BSCI 642-901 Tutorial: Clear Text OSPF Neighbor Authentication » Printer Friendly

Cisco CCNP BSCI 642-901 Tutorial: Clear Text OSPF Neighbor Authentication

Rated 3.5 out of 5
No Reader Ratings Available ?
Rate It  /  View Comments  /  View All Articles submitted by Chris Bryant CCIE 12933
Submitted Wednesday, January 31, 2007
Submitted by: Chris Bryant CCIE 12933 (13,631)
The Bryant Advantage
Log in to become a member of Chris Bryant CCIE 12933's Fan Club!


An OSPF adjacency can be authenticated with MD5 (Message Digest 5) or with a clear-text password. I’m not much on clear-text passwords, and hopefully you aren’t either! Whether you’re working in the real world or the certification exam room, though, it’s always a good idea to know more than one way to do things. Let’s take a look at how to configure clear-text authentication of an OSPF neighbor relationship.

The commands we’ll use are “ip ospf authentication-key" and “ip ospf authentication". In this example, we have preexisting adjacencies between three routers in an OSPF NBMA network. The hub router (R1) has an adjacency with two spoke routers, R2 and R3.

The password is set by the interface-level command ip ospf authentication-key. While Cisco routers will usually tell you when you’re about to try to do something that you can’t do, this password is a rare exception to the rule. Let’s set a password of passbscitest and then check the router config.

R1(config-if)#ip ospf authentication-key ?

Encryption type (0 for not yet encrypted, 7 for proprietary)

LINE The OSPF password (key)

R1(config-if)#ip ospf authentication-key passbscitest

R1#show config

interface Serial0

ip address 172.12.123.1 255.255.255.0

encapsulation frame-relay

ip ospf authentication-key passbsci

I entered a 12-character password, but only the first eight are showing in the router configuration. The router failed to warn us that this particular password has a limit of eight characters. As of IOS 12.4, the router now warns the admin about this, but there are plenty of routers out there that aren’t running that recent a release!

Clear-text authentication is enabled with the ip ospf authentication command. IOS Help shows there is no specific command for clear-text authentication. (Null and clear-text authentication are not the same thing.)

R1(config)#int serial0

R1(config-if)#ip ospf authentication ?

message-digest Use message-digest authentication

null Use no authentication

To set clear-text authentication, just use the basic command with no options.

R1(config-if)#ip ospf authentication

About two minutes after entering that configuration, the preexisting adjacencies go down:

R1#

00:25:38: %OSPF-5-ADJCHG: Process 1, Nbr 172.12.123.2 on Serial0 from FULL to DOWN, Neighbor Down: Dead timer expired

R1#

00:25:58: %OSPF-5-ADJCHG: Process 1, Nbr 172.12.123.3 on Serial0 from FULL to DOWN, Neighbor Down: Dead timer expired

R1#

Until we configure the spoke routers with the same config, the adjacencies will stay down – so let’s get those spokes configured!

R2(config)#interface serial0

R2(config-if)#ip ospf authentication-key passbsci

R2(config-if)#ip ospf authentication

R3(config)#interface serial0

R3(config-if)#ip ospf authentication-key passbsci

R3(config-if)#ip ospf authentication

On R1, show ip ospf neighbor verifies that the adjacencies are back up.

R1#show ip ospf neighbor

Neighbor ID Pri State Dead Time Address Interface

172.12.123.3 0 FULL/DROTHER 00:01:58 172.12.123.3 Serial0

172.12.123.2 0 FULL/DROTHER 00:01:37 172.12.123.2 Serial0

Now that you know how to configure OSPF neighbor authentication in clear text, you need to learn how to use MD5 authentication, and that just happens to be the subject of my next CCNP BSCI 642-901 exam tutorial! See you then!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of free CCNP and CCNA tutorials, The Ultimate CCNA Study Package, and Ultimate CCNP Study Packages.

You can also join his RSS feed and visit his blog, which is updated several times daily with new Cisco certification articles, free tutorials, and daily CCNA / CCNP exam questions! Details are on the website.

For a FREE copy of his latest e-books, “How To Pass The CCNA" and “How To Pass The CCNP", just visit the website! You can also get FREE CCNA and CCNP exam questions every day!

Get your Microsoft Vista certification with The Bryant Advantage!






Reprint Rights

Log in to become a member of Chris Bryant CCIE 12933's Fan Club!

Comments on this article:
No comments yet.


Was this article helpful to you? Leave a Public Comment or Question:

 

This Article has been viewed 76 times.
Article added to SearchWarp.com on Wednesday, January 31, 2007
View other articles written by Chris Bryant CCIE 12933 (13,631)


If you found this article interesting, you may want to check out:

Disclaimer:  All information on this site is provided for informational purposes only! By no means is any information presented herein intended to substitute for the advice provided to you by any health care or other professional or organization.


Today's Most Popular
Cisco CCNA Exam Tutorial: What's A Collision Domain?

Cisco CCNA Certification Exam Tutorial: Route Summarization

Cisco CCNP / BSCI Exam Tutorial: The BGP MED Attribute

Cisco CCNA Certification: Everything You Need To Know About Telnet!

Cisco CCNA Certification: Showdown At The Transport Layer... TCP vs. UDP !

Cisco CCNA Certification: Defining And Creating Collision Domains

Cisco CCENT / CCNA Certification Exam Tutorial: Logging Synchronous And Exec-Timeout Commands

Cisco Certification: The Definitive Guide To ARP, RARP, IARP, and Proxy ARP

Cisco CCNA Exam Tutorial: Five OSPF Details You Must Know!

CCNA / CCNP / BCMSN Exam Tutorial: VLAN Trunking Basics

Home  |  FAQ's  |  Contact  |  Terms of Service  |  Article Submission Guidelines  |  Writers' Contests  |  Privacy  |  Mission / About
Copyright ? 1999-2008 SearchWarp.com, All Rights Reserved - SearchWarp.com is an IcoLogic, Inc. Company