Prev | Current Page 283 | Next

Stephen McQuerry

"Interconnecting Cisco Network Devices, Part 2 (ICND2): (CCNA Exam 640-802 and ICND exam 640-816) (3rd Edition)"

This key can also be
used when packets are sent from 4:00 a.m. (0400) on January 1, 2006, onward, as speci?¬?ed in the
send-lifetime 04:00:00 Jan 1 2006 in?¬?nite command.
Therefore, Router X accepts and attempts to verify the MD5 digest of any EIGRP packets with a
key ID equal to 1. Router X will also accept a packet with a key ID equal to 2. All other MD5
packets are dropped. Router X sends all EIGRP packets using key 2 because key 1 is no longer
valid for use in sending packets.
Example 5-7 shows the con?¬?guration of EIGRP MD5 authentication for Router Y in Figure 5-7.
send-lifetime 04:00:00 Jan 1 2006 infinite

!
interface Serial0/0/1
bandwidth 64
ip address 192.168.1.101 255.255.255.224
ip authentication mode eigrp 100 md5
ip authentication key-chain eigrp 100 RouterXchain
Example 5-7 Con?¬?guring EIGRP MD5 Authentication on Router Y
RouterY

key chain RouterYchain
key 1
key-string firstkey
accept-lifetime 04:00:00 Jan 1 2006 infinite
send-lifetime 04:00:00 Jan 1 2006 infinite
Example 5-6 Con?¬?guring EIGRP MD5 Authentication on Router X (Continued)
continues
190 Chapter 5: Implementing EIGRP
MD5 authentication is con?¬?gured on the Serial 0/0/1 interface with the ip authentication mode
eigrp 100 md5 command.


Pages:
271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295