[c-nsp] IOS-XR IS-IS authentication

Eric Van Tol eric at atlantech.net
Wed May 27 08:40:00 EDT 2020


On 5/27/20, 8:21 AM, "Saku Ytti" <saku at ytti.fi> wrote:

>  What is the intended behaviour? As far as I know hello packets are
>  covered by the main level authentication. You'd only really want to
>  configure the interface level if you want to ONLY authenticate hellos
>  or if you want to have separate authentication for hellos.

It was a hold-over from when there were separate levels with authenticating hellos and just hasn't changed since transitioning to a single level-2-only area. Irrespective of this, removing the hello-authentication at the interface level doesn't resolve the issue with the key chain not authenticating.

-evt



More information about the cisco-nsp mailing list