MR-G96 发表于 2018-8-10 15:37:09

OSPF认证的问题

OSPF接口认证优先于区域认证?还是区域认证优先于 接口认证?
我做实验时,密文配置了接口认证,然后明文区域认证。发现另一台路由器区域认证不开启好像也可以建立邻居和有路由。
然后重新配置明文接口认证,区域明文认证,另一台还没配置好区域认证无法发现邻居和路由。
还是只要密码一直就行???

locity 发表于 2018-8-10 15:37:10

Not quite sure about your question. Hope this help:

Note: The area authentication command in the configuration enables authentication for all the interfaces of the router in a particular area. You can also use the ip ospf authentication command under the interface to configure plain text authentication for the interface. This command can be used if a different authentication method or no authentication method is configured under the area to which the interface belongs. It overrides the authentication method configured for the area. This is useful if different interfaces that belong to the same area need to use different authentication methods.

https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13697-25.html#authentication

LONGSHIFU 发表于 2018-8-10 17:05:22

这个问题不好解决!

locity 发表于 2018-8-11 10:54:47

Not quite sure about your problem. Hope this help:

Note: The area authentication command in the configuration enables authentication for all the interfaces of the router in a particular area. You can also use the ip ospf authentication command under the interface to configure plain text authentication for the interface. This command can be used if a different authentication method or no authentication method is configured under the area to which the interface belongs. It overrides the authentication method configured for the area. This is useful if different interfaces that belong to the same area need to use different authentication methods.

https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13697-25.html#authentication

Triangel. 发表于 2018-8-17 23:17:51

首先OSPF支持区域认证和接口认证。
R1-----R2-----R3-----R4
上边四台路由器假设都属于OSPF Area 1区域,都开启了OSPF密文区域认证
这个时候R2----R3开启了接口认证(接口明文认证或者接口密文认证也好)这个时候R2和R3的接口认证方式高于前边的区域认证。
cisco有个特点,就是在接口下做的配置要高于在进程下的配置。就打个比方,cisco的OSPF协议network你可以在全局创建OSPF进程进行宣告,也可以在接口下进行宣告
接口下宣告命令:R1(config-if)# ip ospf 100 area 0
页: [1]
查看完整版本: OSPF认证的问题