OSPFv2 Keychain Authentication

OSPFv2 can be configured to authenticate packets using the keychain authentication module. The keychain authentication module provides hitless authentication key rollover, which allows OSPFv2 to overcome the limitation of the static configuration in authentication methods that require manual intervention to change the key periodically. For each OSPFv2 protocol packet, a key is used to generate and verify a message digest. The key is valid for the entire duration of the protocol without any option to change the key string or authentication algorithm automatically. The keychain authentication module that functions as a container of keys with different attributes such as the authentication algorithm, password, and different lifetimes provides OSPFv2 with an option to choose the key that best suits its criteria and automatically change the key ID, password, and cryptographic algorithm without manual intervention.

For more information regarding the keychain authentication module and configuration of keychains, refer to "Keychain module" in the RUCKUS FastIron Security Configuration Guide.

Note: If multiple OSPFv2 interfaces are deployed within a VRF or Multi-VRF deployment and keychain authentication is implemented, it is necessary to ensure the ip ospf hello-interval and ip ospf dead-interval values are configured appropriately. If these values are set too low, for example hello-interval (1 second) and dead-interval (4 seconds), it may cause performance issues and disruption to service during key rollover.