OSPFv2 Authentication

OSFPv2 can be configured to authenticate packets using one of the following authentication algorithms:
  • Plain text
  • Message Digest 5 (MD5)
  • Hashed Message Authentication Code-Secure Hash Algorithm 1 (HMAC-SHA-1)
  • Hashed Message Authentication Code-Secure Hash Algorithm 256 (HMAC-SHA-256)

The authentication algorithms provide varying levels of security and must be configured depending on your security requirements, including any regulatory requirements such as FIPS compliance.

Authentication is implemented as detailed in RFC 2328 and RFC 5709.

Algorithms HMAC-SHA-1 and HMAC-SHA-256 are supported in FIPS-compliant deployments. MD5 and plain text are not supported in FIPS deployments.

Note: OSPFv2 packets are not authenticated by default. You must configure OSPFv2 authentication as required.

OSPFv2 authentication can be enabled on each interface of virtual link.

In addition to the other authentication methods, you can configure keychain authentication. For more information regarding the keychain authentication module and configuration of keychains, refer to "Keychain module" in the RUCKUS FastIron Security Configuration Guide.

Note: If multiple OSPFv2 are stacked and authentication is enabled, the OSPFv2 non-stop routing (NSR) feature must be enabled explicitly. NSR is not enabled by default. If NSR is not enabled, there may be disruption to service upon stack switchover.