TCP Keychain Options

Note: TCP keychain authentication is not supported on ICX 8100 and ICX 8200 devices.

The following commands are available only for TCP keychains:

  • authentication-algorithm aes-128-cmac: Configures the AES-128-CMAC algorithm for TCP authentication. The authentication-algorithm hmac-sha-1 command is also supported. The no form of the command removes the configuration.
  • accept-ao-mismatch: Determines whether the ICX device accepts or denies TCP segments received with a mismatch in TCP-AO support between the TCP peers. By default, mismatched segments are accepted. When you use the no form of the command to disable the option, TCP-AO packets with a mismatch are discarded. For example, if the authentication option (AO) is not configured for a particular TCP BGP/MSDP peer connection and the ICX device receives over that connection a segment from a peer with the authentication option set, the ICX device determines how the mismatch is handled based on the command option. If the ICX device has the no accept-ao-mismatch option configured, no session will be established with the peer.
  • include-tcp-options: Determines whether all TCP options are included in the Message Authentication Code (MAC) calculation. By default, all TCP options are included. When the no form of the command is configured, only the TCP-AO option is included in the MAC calculation.

  • send-id: Configures the identifier sent in an outgoing TCP segment. Valid decimal values are 0 through 255. The no form of the command removes the identifier.
  • receive-id: Configures the identifier to be compared with the key identifier received in a TCP segment. Valid decimal values are 0 through 255. The no form of the command removes the identifier.

TCP Keychain Considerations

It is not advisable to change the TCP keychain configuration for active connections.

The TCP keychain can be used in conjunction with routing protocols such as BGP and MSDP.

BGP and MSDP peer sessions must be cleared for the new TCP-AO configuration to take effect. Refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide to configure BGP to use TCP-AO settings. Refer to the RUCKUS FastIron IP Multicast Configuration Guide to configure MSDP to use TCP-AO settings.

TCP Keepalive is enabled for all TCP-AO-enabled connections and cannot be disabled, even if disabled at the global level.

TCP-AO and TCP MD5 cannot be used in the same connection.

In an ICX stack, TCP authentication options are applicable only for the TCP connections created from the active-controller.