White Papers

Table Of Contents
The bold lines in the example show the change on the interface. The change is reflected in the OSPF configuration.
Enabling OSPFv2 Authentication
To enable or change various OSPF authentication parameters, use the following commands.
Set a clear text authentication scheme on the interface.
CONFIG-INTERFACE mode
ip ospf authentication-key key
Configure a key that is a text string no longer than eight characters.
All neighboring routers must share password to exchange OSPF information.
Set the authentication change wait time in seconds between 0 and 300 for the interface.
CONFIG-INTERFACE mode
ip ospf auth-change-wait-time seconds
This setting is the amount of time OSPF has available to change its interface authentication type.
When you configure the auth-change-wait-time, OSPF sends out only the old authentication scheme until the
wait timer expires. After the wait timer expires, OSPF sends only the new authentication scheme. However, the new
authentication scheme does not take effect immediately after the authentication change wait timer expires; OSPF accepts
both the old as well as new authentication schemes for a time period that is equal to two times the configured
authentication change wait timer. After this time period, OSPF accepts only the new authentication scheme.
This transmission stops when the period ends.
The default is 0 seconds.
Configuring Virtual Links
Areas within OSPF must be connected to the backbone area (Area ID 0.0.0.0).
If an OSPF area does not have a direct connection to the backbone, at least one virtual link is required. Configure virtual links on
an ABR connected to the backbone.
hello-interval help packet
retransmit-interval LSA retransmit interval
transmit-delay LSA transmission delay
dead-interval dead router detection time
authentication-key authentication key
message-digest-key MD5 authentication key
To configure virtual links, use the following command.
Configure the optional parameters of a virtual link.
CONFIG-ROUTEROSPF- id mode
area area-id virtual-link router-id [hello-interval seconds | retransmit-interval seconds
| transmit-delay seconds | dead-interval seconds | authentication-key key | message-
digest-key keyid md5 key]
area ID: assigned earlier (the range is from 0 to 65535 or A.B.C.D).
router ID: IP address associated with the virtual link neighbor.
hello interval seconds: the range is from 1 to 8192 (the default is 10).
retransmit interval seconds: the range is from 1 to 3600 (the default is 5).
transmit delay seconds: the range is from 1 to 3600 (the default is 1).
dead interval seconds: the range is from 1 to 8192 (the default is 40).
authentication key: eight characters.
message digest key keyid: the range is from 1 to 255.
md5 key: 16 characters.
If you do not enter other parameters, the defaults are used.
Only the area ID and router ID require configuration to create a virtual link.
Use EITHER the Authentication Key or the Message Digest (MD5) key.
574
Open Shortest Path First (OSPFv2 and OSPFv3)