HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 3 - IP Routing Confi - Page 40

Configuring RIPv2 message authentication, Specifying a RIP neighbor

Page 40 highlights

To enable source IP address check on incoming RIP updates: Step 1. Enter system view. 2. Enter RIP view. 3. Enable source IP address check on incoming RIP messages. Command system-view rip [ process-id ] [ vpn-instance vpn-instance-name ] validate-source-address Remarks N/A N/A Optional. Enabled by default. Configuring RIPv2 message authentication In a network requiring high security, configure this task to implement RIPv2 message validity check and authentication. This feature does not apply to RIPv1 because RIPv1 does not support authentication. Although you can specify an authentication mode for RIPv1 in interface view, the configuration does not take effect. RIPv2 supports simple authentication and MD5 authentication. To configure RIPv2 message authentication: Step 1. Enter system view. 2. Enter interface view. 3. Configure RIPv2 authentication. Command system-view interface interface-type interface-number rip authentication-mode { md5 { rfc2082 [ cipher ] key-string key-id | rfc2453 [ cipher ] key-string } | simple [ cipher ] password } Specifying a RIP neighbor Usually, RIP sends messages to broadcast or multicast addresses. On non-broadcast or multicast links, you must manually specify RIP neighbors. Follow these guidelines when you specify a RIP neighbor: • Do not use the peer ip-address command when the neighbor is directly connected because the neighbor may receive both the unicast and multicast (or broadcast) of the same routing information. • If a specified neighbor is not directly connected, then disable the source address check on incoming updates. To specify a RIP neighbor: Step Command 1. Enter system view. system-view 2. Enter RIP view. rip [ process-id ] [ vpn-instance vpn-instance-name ] 3. Specify a RIP neighbor. peer ip-address 4. Disable source address check on incoming RIP updates. undo validate-source-address Remarks N/A N/A N/A Not disabled by default. 30

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312

30
To enable source IP address check on incoming RIP updates:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RIP view.
rip
[
process-id
] [
vpn-instance
vpn-instance-name
]
N/A
3.
Enable source IP address
check on incoming RIP
messages.
validate-source-address
Optional.
Enabled by default.
Configuring RIPv2 message authentication
In a network requiring high security, configure this task to implement RIPv2 message validity check and
authentication. This feature does not apply to RIPv1 because RIPv1 does not support authentication.
Although you can specify an authentication mode for RIPv1 in interface view, the configuration does not
take effect.
RIPv2 supports simple authentication and MD5 authentication.
To configure RIPv2 message authentication:
Step
Command
1.
Enter system view.
system-view
2.
Enter interface view.
interface
interface-type interface-number
3.
Configure RIPv2
authentication.
rip authentication-mode
{
md5
{
rfc2082
[
cipher
]
key-string
key-id
|
rfc2453
[
cipher
]
key-string
} |
simple
[
cipher
]
password
}
Specifying a RIP neighbor
Usually, RIP sends messages to broadcast or multicast addresses. On non-broadcast or multicast links,
you must manually specify RIP neighbors.
Follow these guidelines when you specify a RIP neighbor:
Do not use the
peer
ip-address
command when the neighbor is directly connected because the
neighbor may receive both the unicast and multicast (or broadcast) of the same routing information.
If a specified neighbor is not directly connected, then disable the source address check on incoming
updates.
To specify a RIP neighbor:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RIP view.
rip
[
process-id
] [
vpn-instance
vpn-instance-name
]
N/A
3.
Specify a RIP neighbor.
peer
ip-address
N/A
4.
Disable source address check
on incoming RIP updates.
undo validate-source-address
Not disabled by default.