BGP Keychain Authentication

BGP can be configured to authenticate packets using the keychain authentication module. The keychain authentication module provides hitless authentication key rollover, which allows BGP to overcome the limitation of the static configuration in authentication methods that require manual intervention to change the key periodically. For each BGP protocol packet, a key is used to generate and verify a message digest. The key is valid for the entire duration of the protocol without any option to change the key string or authentication algorithm automatically. The keychain authentication module that functions as a container of keys with different attributes such as the authentication algorithm, password, and different lifetimes provides BGP with an option to choose the key that best suits its criteria and automatically change the key ID, password, and cryptographic algorithm without manual intervention.

For more information regarding the keychain authentication module and configuration of keychains, refer to "Keychain module" in the RUCKUS FastIron Security Configuration Guide.

The following example enables TCP-AO support for a BGP neighbor with the IP address 12.0.0.1.

device# configure terminal
device(config)# router bgp
device(config-bgp-router)# local-as 20
device(config-bgp-router)# neighbor 12.0.0.1 remote-as 10
device(config-bgp-router)# neighbor 12.0.0.1 ao bgp-msdp