Mailing List Archive

[Q]Junos isis md5 authentification
Hi,


I would like to ask you that each vendor has different IS-IS MD5
authentication running?

I am going to tell why I ask this.

When Juniper authenticates IS-IS MD5, it disconnects neightbor in case
of wrong key value.

However, it doesn't happen to Cisco, Procket, Vivace etc and
it ignore the wrong key value packet.

That's why I am asking this matter to you.



Thanks in advance.



Warmest Regards



/Cook




_____



<http://intra.icraft.com/mail/recv_date_exe.asp?uid=S-0311070921451447E7
EE-3370514.eml>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://puck.nether.net/pipermail/juniper-nsp/attachments/20031107/138bfd5f/attachment.html
[Q]Junos isis md5 authentification [ In reply to ]
On Fri, Nov 07, 2003 at 09:21:45AM +0900, ?????? wrote:
|
| Hi,
|
| I would like to ask you that each vendor has different IS-IS MD5
| authentication running?
|
| I am going to tell why I ask this.
|
| When Juniper authenticates IS-IS MD5, it disconnects neightbor in case
| of wrong key value.
|
| However, it doesn't happen to Cisco, Procket, Vivace etc and
| it ignore the?wrong key value packet.
|
| That's why I am asking this matter to you.
|
| Thanks in advance.


JUNOS per-level authentication authenticates and requires authenticatied
IIH, SNP and LSP PDUs;

the two other mentioned implementations authenticate LSPs only and some [depending
on SW version] also SNPs;

since JUNOS 5.4 the

no-hello-authentication,
no-csnp-authentication and
no-psnp-authentication

knobs are provided to adapt to any enviroment;


/hannes