neighbor ao
neighbor
{
ip-address
|
ipv6-address
|
peer-group-name
}
keychain-nameno neighbor
{
ip-address
|
ipv6-address
|
peer-group-name
}
keychain-nameTCP-AO support is not enabled.
BGP configuration mode
BGP address-family IPv6 unicast configuration mode
BGP address-family IPv4 unicast VRF configuration mode
BGP address-family IPv6 unicast VRF configuration mode
BGP neighbor sessions must be cleared for the keychain configuration to take effect.
Any configurational change in the TCP-AO keychain used by a BGP neighbor may cause existing sessions to flap. Similarly, removing or replacing the existing keychain configured for a BGP neighbor can also cause the sessions to flap. In the case of key expiry cases, the next best active key is considered. If there are no other active keys present, the expired key is kept until another new active key is configured. The removal of the active key-id or mandatory parameter configurations are considered as key expiry.
The no form of the command disables TCP-AO support for BGP
neighbors.
The following example enables TCP-AO support for a BGP neighbor with the IP address 12.0.0.1.
device# configure terminal device(config)# router bgp device(config-bgp-router)# local-as 20 device(config-bgp-router)# neighbor 12.0.0.1 remote-as 10 device(config-bgp-router)# neighbor 12.0.0.1 ao bgp-msdp
| Release version | Command history |
|---|---|
| 09.0.10 | This command was introduced. |