繁体中文
设为首页
加入收藏
当前位置:技术首页 >> 网络 >> 路由技术 >> OSPF邻居认证实际案例(配图)+详细验证过程

OSPF邻居认证实际案例(配图)+详细验证过程

2008-04-08 21:53:04  作者:IT动力源  来源:IT动力源收集整理  浏览次数:38  文字大小:【】【】【
关键字:cisco技术
邻居认证使得路由器确认每次所收到的路由更新的源。如果关键字不匹配,就会拒绝路由更新。   Cisco使用两种类型的邻居认证:纯文本和MD5。   纯文本认证发一个关键字,这个关键字是明文传输,可被非法用户所窃取,所以不推荐使用。   MD5认证发一个报文摘要,而不是关键字。MD5被用来生成一个关键字的散列。这个散列是被发送的对象。MD5方式不易被非法用户所窃取。   这个案例中,我们在R1与R2之间使用明文认证,在R2与R3之间使用MD5认证。     // R1 // int e0/0   ip ad 192.1.1.1 255.255.255.0   ip ospf authentication-key cisco    //明文认证,关键字为cisco   router os 1   network 192.1.1.1 0.0.0.0 area 0   area 0 authentication     // R2 // int e0/0   ip ad 192.1.1.2 255.255.255.0   ip ospf authentication-key cisco    //明文认证,关键字为cisco   int e1/0   ip ad 193.1.1.2 255.255.255.0   ip ospf message-digest-key 1 md5 cracker   router os 1   network 192.1.1.2 0.0.0.0 area 0   network 193.1.1.2 0.0.0.0 area 1   area 0 authentication   area 1 authentication message-digest     // R3 // int e1/0   ip ad 193.1.1.3 255.255.255.0   ip ospf message-digest-key 1 md5 cracker   router os 1   network 193.1.1.3 0.0.0.0 a 1   area 1 authentication message-digest       验证过程: r1#sh ip os int e0/0
Ethernet0/0 is up, line protocol is up
  Internet Address 192.1.1.1/24, Area 0
  Process ID 1, Router ID 192.1.1.1, Network Type BROADCAST, Cost: 10
  Transmit Delay is 1 sec, State BDR, Priority 1
  Designated Router (ID) 193.1.1.2, Interface address 192.1.1.2
  Backup Designated router (ID) 192.1.1.1, Interface address 192.1.1.1
  Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5
    Hello due in 00:00:06
  Index 1/1, flood queue length 0
  Next 0x0(0)/0x0(0)
  Last flood scan length is 1, maximum is 1
  Last flood scan time is 0 msec, maximum is 0 msec
  Neighbor Count is 1, Adjacent neighbor count is 1
    Adjacent with neighbor 193.1.1.2  (Designated Router)
  Suppress hello for 0 neighbor(s)
  Simple password authentication enabled   r2#sh ip os int e0/0
Ethernet0/0 is up, line protocol is up
  Internet Address 192.1.1.2/24, Area 0
  Process ID 1, Router ID 193.1.1.2, Network Type BROADCAST, Cost: 10
  Transmit Delay is 1 sec, State DR, Priority 1
  Designated Router (ID) 193.1.1.2, Interface address 192.1.1.2
  Backup Designated router (ID) 192.1.1.1, Interface address 192.1.1.1
  Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5
    Hello due in 00:00:04
  Index 1/1, flood queue length 0
  Next 0x0(0)/0x0(0)
  Last flood scan length is 1, maximum is 2
  Last flood scan time is 0 msec, maximum is 0 msec
  Neighbor Count is 1, Adjacent neighbor count is 1
    Adjacent with neighbor 192.1.1.1  (Backup Designated Router)
  Suppress hello for 0 neighbor(s)
  Simple password authentication enabled   r2#sh ip os int e1/0
Ethernet1/0 is up, line protocol is up
  Internet Address 193.1.1.2/24, Area 1
  Process ID 1, Router ID 193.1.1.2, Network Type BROADCAST, Cost: 10
  Transmit Delay is 1 sec, State DR, Priority 1
  Designated Router (ID) 193.1.1.2, Interface address 193.1.1.2
  Backup Designated router (ID) 193.1.1.3, Interface address 193.1.1.3
  Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5
    Hello due in 00:00:03
  Index 1/2, flood queue length 0
  Next 0x0(0)/0x0(0)
  Last flood scan length is 2, maximum is 2
  Last flood scan time is 0 msec, maximum is 0 msec
  Neighbor Count is 1, Adjacent neighbor count is 1
    Adjacent with neighbor 193.1.1.3  (Backup Designated Router)
  Suppress hello for 0 neighbor(s)
  Message digest authentication enabled
    Youngest key id is 1
  r3#sh ip os int e1/0
Ethernet1/0 is up, line protocol is up
  Internet Address 193.1.1.3/24, Area 1
  Process ID 1, Router ID 193.1.1.3, Network Type BROADCAST, Cost: 10
  Transmit Delay is 1 sec, State BDR, Priority 1
  Designated Router (ID) 193.1.1.2, Interface address 193.1.1.2
  Backup Designated router (ID) 193.1.1.3, Interface address 193.1.1.3
  Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5
    Hello due in 00:00:04
  Index 1/1, flood queue length 0
  Next 0x0(0)/0x0(0)
  Last flood scan length is 1, maximum is 2
  Last flood scan time is 0 msec, maximum is 0 msec
  Neighbor Count is 1, Adjacent neighbor count is 1
    Adjacent with neighbor 193.1.1.2  (Designated Router)
  Suppress hello for 0 neighbor(s)
  Message digest authentication enabled
    Youngest key id is 1
      为了更进一步理解认证过程,我们可以打开DEBUG,并将R3的MD5认证key改为5: // R3 // debug ip ospf adj   int e1/0   ip ospf message-digest-key 5 md5 cracker   r3#
01:16:03: OSPF: Rcv pkt from 193.1.1.2, Ethernet1/0 : Mismatch Authentication Key - No message digest key 1 on interface
01:16:09: OSPF: Send with youngest Key 5     r3#show ip ospf neighbor    //观察结果无法发现邻居。   //认证未通过,无法与R2建立起邻居关系。   当我们把MD5认证KEY改回1后,认证通过。     第二步实验,我们把关键字进行修改: // R3 // debug ip ospf adj   int e1/0   ip ospf message-digest-key 1 md5 cuijian   01:21:33: OSPF: Rcv pkt from 193.1.1.2, Ethernet1/0 : Mismatch Authentication Key - Message Digest Key 1
01:21:40: OSPF: Send with youngest Key 1   我们要在实际工作中学会使用debug这个思科排错的利器。

点击收藏到

责任编辑:hefei

本文引用地址: http://tech.itzero.com/2008/0408/36553.html 请粘贴到你的QQ/MSN上推荐给你的好友

相关文章
/31位掩码实验演示
解决广播风暴的方法:storm-control
IPSec VPN(对不同的数据流进行不同的加密和认证)
BGP后门链路(Backdoor)实际案例(配图+详细验证过程)
OSPF虚链路(virtual-link)配置实例 + 详细验证过程
ASA配置笔记
EzVPN Client 完整配置
操作BGP路由过滤(基于路由条目)实际案例(配图+详细验证过程)
Cisco网络管理的35个常见问题及解答
路由器实例 关于CE1/PRI接口配置命令说明
 

最新文章

更多

· 路由器问题故障排除方法
· 图解交换机与路由器组网...
· 提高城域网路由器网络层...
· 常见宽带路由器设置方法...
· 常见宽带路由器设置方法...
· 深入了解路由器与交换机...
· 深入了解路由器与交换机...
· 阻挡入侵狙击攻略 配置安...
· 如何实现两条DDN专线相互...
· 不配置回指路由 多网段网...

热点文章

更多

· 通过路由器实现用户定时...
· Cisco高档路由器故障排除...
· 调教路由器 让网络管理效...
· 从路由器底层入手 深度透...
· 最新路由交换测试技术介绍
· 如何提高企业路由器性能
· 专家称网真应用需要升级...
· 路由器密码、原有配置轻...
· 不配置回指路由 多网段网...
· 如何实现两条DDN专线相互...

其它推荐