Authenticate Cisco RIP version 2 (RIPv2) Routers

Contributor Icon Contributed by Al Banks  
Tag Icon Tagged: Cisco router  

MD5 authentication for RIPv2 routers


For this example, two routers, A and B, are directly connected with their serial0/0 ports. IP network is 192.168.0.0/30. 10.1.1.0/24 and 10.2.2.0/24 are the FastEthernet networks on each end.

Enter the appropriate passwords, then enter configuration mode:conf t

Address the interfaces.

Router A:interface FastEthernet 0/0
ip address 10.1.1.1 255.255.255.0
interface serial 0/0
ip address 192.168.0.1 255.255.255.252

Router B:interface FastEthernet 0/0
ip address 10.1.1.2 255.255.255.0
interface serial 0/0
ip address 192.168.0.2 255.255.255.252

Configure RIP (same on both routers):router rip
network 10.0.0.0
network 192.168.0.0
version 2

Then, create keychains in both routers.

Router A:key chain rtrA
key 1
key-string 123
exit
key 2
key-string abc

Router B:key chain rtrB
key 1
key-string 123
exit
key 2
key-string abc

Now, configure authentication.

Router A:interface serial 0/0
ip rip authentication mode md5
ip rip authentication key-chain rtrA

Router B:interface serial 0/0
ip rip authentication mode md5
ip rip authentication key-chain rtrB

Now the routers should be verifying the MD5 hash of RIP routing update packets, dropping any that do not pass the verification.

For compatibility, the “ip rip authentication mode md5″ can be omitted, which will cause authentication to occur with plain text.

 

4 Comments -


  1. sherif said on December 7, 2008

    well i dont know why i cant create a key chain in the router configuration in the packet tracer
    every time i try to write the KEY CHAIN command this msg appear (Invalid input detected at ‘^’ marker.)
    anybody have explanation plz contact

  2. Anonymous said on April 9, 2009

    It’s likely your IOS version or feature set. I just verified this command is in a 2811 using 12.4-22T SP Services code.

  3. Bappa_chatterjee1122 said on September 20, 2010

    Could be the problem with IOS or S/w . u can try to download another version or better if u can try it on GNS ..

  4. ansar said on February 4, 2012

    thank

 

RSS feed for comments on this post. TrackBack URL

Leave a comment -