data:image/s3,"s3://crabby-images/f6e28/f6e28dfefa0173c78ab923683043d939e26b7b62" alt=""
IP Routing Features
Configuring OSPF
12. Optional: Configuring OSPF Interface
Authentication
OSPF supports two methods of authentication for each VLAN or subnet—
simple password and MD5. In addition, the value can be disabled, meaning no
authentication is performed. Only one method of authentication can be active
on a VLAN or subnet at a time, and if one method is configured on an interface,
then configuring the alternative method on the same interface automatically
overwrites the first method used. In the default configuration, OSPF authen-
tication is disabled. All interfaces in the same network or subnet must have
the same authentication method (password or MD5 key chain) and creden-
tials.
OSPF Password Authentication.
Syntax: ip ospf [ ip-address ] authentication-key < octet-string >
no ip ospf [ ip-address ] authentication
Used in the VLAN interface context to configure password
authentication for all interfaces in the VLAN or for a specific
subnet. The password takes effect immediately, and all OSPF
packets transmitted on the interface contain this password.
All OSPF packets received on the interface are checked for the
password. If it is not present, then the packet is dropped. To
disable password authentication on an interface, use the no
form of the command.
[ ip-address ]: Used in subnetted VLAN contexts where you want
to assign or remove a password associated with a specific
subnet. Omit this option when you want the command to apply
to all interfaces configured in the VLAN.
< octet-string >: An alphanumeric string of one to eight
characters. (Spaces are not allowed.) To change the password,
re-execute the command with the new password.
Use show ip ospf interface < ip-address > to view the current
authentication setting. (Refer to pages 5-102 and 5-104.)
Note: To replace the password method with the MD5 method
on a given interface, overwrite the password configuration by
using the MD5 form of the command shown in the next syntax
description. (It is not necessary to disable the currently
configured OSPF password.)
Default: Disabled
5-86