OSPFv2 Keychain Authentication
OSPFv2 can be configured to authenticate packets using the keychain authentication module. The keychain authentication module provides hitless authentication key rollover, which allows OSPFv2 to overcome the limitation of the static configuration in authentication methods that require manual intervention to change the key periodically. For each OSPFv2 protocol packet, a key is used to generate and verify a message digest. The key is valid for the entire duration of the protocol without any option to change the key string or authentication algorithm automatically. The keychain authentication module that functions as a container of keys with different attributes such as the authentication algorithm, password, and different lifetimes provides OSPFv2 with an option to choose the key that best suits its criteria and automatically change the key ID, password, and cryptographic algorithm without manual intervention.
For more information regarding the keychain authentication module and configuration of keychains, refer to "Keychain module" in the RUCKUS FastIron Security Configuration Guide.
ip ospf hello-interval and
ip ospf dead-interval values are configured appropriately. If these values are set too low, for example
hello-interval (1 second) and dead-interval (4 seconds), it may cause performance
issues and disruption to service during key rollover.