Avaya Configuring IP Exterior Gateway Protocols (BGP and EGP) Manual do Utilizador Página 107

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 276
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 106
Configuring BGP Peers
308628-15.0 Rev 00
4-25
Verifying MD5 Signatures on Received BGP TCP Packets
Upon receiving a packet, TCP performs three tests.
If a packet passes a test, it proceeds to the next test. When a packet has passed
all three tests, TCP accepts the packet and sends it to BGP.
If a packet fails a test, TCP logs an event, increments the count of TCP
connection errors (wfTcpConnMd5Errors), and discards the packet. The TCP
connection remains open.
Table 4-1
lists the tests and the event message that TCP logs if a test fails.
Configuring BGP-4 Authentication
You can use the BCC or Site Manager to configure BGP-4 authentication.
Table 4-1. MD5 Signature Verification Rules on BGP TCP Packets
Condition Tested Action on Success Failure Event Message
Is the connection configured for MD5
authentication?
Verify that the packet contains
a kind=19 option.
TCP MD5 No Signature
Is MD5 authentication enabled for this
TCP connection?
TCP computes the expected
MD5 signature.*
* For information about signatures, see Generating MD5 Signatures on Transmitted BGP TCP Packets on page 4-24.
TCP MD5 Authentication
Disabled
Does the computed MD5 signature
match the received MD5 signature?
TCP sends the packet to BGP.
TCP MD5 Invalid Signature
Note:
You must use the Technician Interface secure shell to enter the message
encryption key/node protection key (NPK/MEK) value before you set the
MD5 authentication parameters. For information about the Technician
Interface secure shell, see
Configuring IPsec Services
.
Vista de página 106
1 2 ... 102 103 104 105 106 107 108 109 110 111 112 ... 275 276

Comentários a estes Manuais

Sem comentários