neighbor ao

Enables TCP-AO support for BGP neighbors.
Syntax
neighbor { ip-address | ipv6-address | peer-group-name } keychain-name
no neighbor { ip-address | ipv6-address | peer-group-name } keychain-name
Command Default

TCP-AO support is not enabled.

Parameters
ip-address
Specifies the IPv4 address of the neighbor.
ipv6-address
Specifies theIPv6 address of the neighbor.
peer-group-name
Specifies the peer group name configured by the neighbor peer-group command.
keychain-name
Specifies the keychain.
Modes

BGP configuration mode

BGP address-family IPv6 unicast configuration mode

BGP address-family IPv4 unicast VRF configuration mode

BGP address-family IPv6 unicast VRF configuration mode

Usage Guidelines

BGP neighbor sessions must be cleared for the keychain configuration to take effect.

Any configurational change in the TCP-AO keychain used by a BGP neighbor may cause existing sessions to flap. Similarly, removing or replacing the existing keychain configured for a BGP neighbor can also cause the sessions to flap. In the case of key expiry cases, the next best active key is considered. If there are no other active keys present, the expired key is kept until another new active key is configured. The removal of the active key-id or mandatory parameter configurations are considered as key expiry.

The no form of the command disables TCP-AO support for BGP neighbors.

Examples

The following example enables TCP-AO support for a BGP neighbor with the IP address 12.0.0.1.

device# configure terminal
device(config)# router bgp
device(config-bgp-router)# local-as 20
device(config-bgp-router)# neighbor 12.0.0.1 remote-as 10
device(config-bgp-router)# neighbor 12.0.0.1 ao bgp-msdp
History
Release version Command history
09.0.10 This command was introduced.