Avaya Configuring IP Exterior Gateway Protocols (BGP and EGP) Manuel d'utilisateur Page 107

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 276
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 106
Configuring BGP Peers
308628-15.0 Rev 00
4-25
Verifying MD5 Signatures on Received BGP TCP Packets
Upon receiving a packet, TCP performs three tests.
If a packet passes a test, it proceeds to the next test. When a packet has passed
all three tests, TCP accepts the packet and sends it to BGP.
If a packet fails a test, TCP logs an event, increments the count of TCP
connection errors (wfTcpConnMd5Errors), and discards the packet. The TCP
connection remains open.
Table 4-1
lists the tests and the event message that TCP logs if a test fails.
Configuring BGP-4 Authentication
You can use the BCC or Site Manager to configure BGP-4 authentication.
Table 4-1. MD5 Signature Verification Rules on BGP TCP Packets
Condition Tested Action on Success Failure Event Message
Is the connection configured for MD5
authentication?
Verify that the packet contains
a kind=19 option.
TCP MD5 No Signature
Is MD5 authentication enabled for this
TCP connection?
TCP computes the expected
MD5 signature.*
* For information about signatures, see Generating MD5 Signatures on Transmitted BGP TCP Packets on page 4-24.
TCP MD5 Authentication
Disabled
Does the computed MD5 signature
match the received MD5 signature?
TCP sends the packet to BGP.
TCP MD5 Invalid Signature
Note:
You must use the Technician Interface secure shell to enter the message
encryption key/node protection key (NPK/MEK) value before you set the
MD5 authentication parameters. For information about the Technician
Interface secure shell, see
Configuring IPsec Services
.
Vue de la page 106
1 2 ... 102 103 104 105 106 107 108 109 110 111 112 ... 275 276

Commentaires sur ces manuels

Pas de commentaire