Configuring Security Parameters on a VSRP-Aware Device

VSRP-aware security parameters protect against unauthorized VSRP Hello packets.
As a prerequisite, VSRP must already be configured on the device.
Without VSRP-aware security, a VSRP-aware device passively learns the authentication method conveyed by the received VSRP Hello packet. The VSRP-aware device then stores the authentication method until it ages out with the VRID-record entry.
  1. From global configuration mode, configure a VLAN by assigning an ID to the VLAN.
    device(config)# vlan 200
  2. Specify an authentication string for VSRP Hello packets.
    device(config-vlan-200)# vsrp-aware vrid 3 simple-text-auth pri-key 
  3. Configure the device to flush MAC addresses at the VLAN level instead of at the port level. MAC addresses will be flushed for every topology change received on the VSRP-aware ports.
    This configuration should be used in networks in which the RUCKUS switch operates as the VSRP-aware device connecting to another device configured as a VSRP Master.
    device(config-vlan-200)# vsrp-aware vrid 3 tc-vlan-flush
  4. Verify the configuration using the show vsrp-aware vlan command.
    device(config-vlan-200)# vsrp-aware vrid 1 tc-vlan-flush
    device(config-vlan-200)# show vsrp aware vlan 200
    Aware Port Listing
    VLAN ID VRID Last Port    Auth         Type        Mac-Flush   Age
    200     1    N/A          no-auth      Configured  Enabled     00:00:00.0
    200     3    N/A          pri-key      Configured  Enabled     00:00:00.0
    
  5. Optionally, display active VRID interfaces.
    device# show vsrp aware
    Aware Port Listing
    VLAN ID VRID Last Port    Auth         Type        Mac-Flush   Age
    200     1    N/A          no-auth      Configured  Enabled     00:00:00.0
    200     3    N/A          pri-key      Configured  Enabled     00:00:00.0