[j-nsp] [Q]Junos isis md5 authentification

Hannes Gredler hannes at juniper.net
Thu Dec 11 18:06:18 EST 2003


On Fri, Nov 07, 2003 at 09:21:45AM +0900, ±èÈ£±¹ wrote:
| 
| Hi,
| 
| I would like to ask you that each vendor has different IS-IS MD5
| authentication running?
| 
| I am going to tell why I ask this.
| 
| When Juniper authenticates IS-IS MD5, it disconnects neightbor in case
| of wrong key value.
| 
| However, it doesn't happen to Cisco, Procket, Vivace etc and
| it ignore the wrong key value packet.
| 
| That's why I am asking this matter to you.
| 
| Thanks in advance.


JUNOS per-level authentication authenticates and requires authenticatied
IIH, SNP and LSP PDUs;

the two other mentioned implementations authenticate LSPs only and some [depending
on SW version] also SNPs;

since JUNOS 5.4 the

  no-hello-authentication,
  no-csnp-authentication and
  no-psnp-authentication

knobs are provided to adapt to any enviroment;


/hannes


More information about the juniper-nsp mailing list