Keychains / Key Rotation / hmac-sha keys - OSPF Authentication - Practical OSPF

preview_player
Показать описание
How can two routers change the authentication keys they are using without risking a neighbor adjacency going down? That is handled by Key Rotation.

How can we configure more secure hashing algorithms for OSPF authentication like hmac-sha? That is handled by Key Chains.

Both Keychains and Key Rotation are covered in this lesson.

This is lesson 21 of the Practical OSPF series. The full series is available here:

00:00 - Intro
01:33 - Key Rotation using Key IDs
02:42 - GNS3 Topology Introduction
03:37 - Key Rotation Demo -- Key Rollover in progress
10:06 - What happens on the wire during Key Rollover?
13:14 - MD5 sucks - What is SHA? What is HMAC?
14:44 - What are Key Chains?
16:02 - Keychain Demo - backwards compatible using MD5
20:02 - Keychain Demo - hmac-sha
24:06 - Date Based Key Rollover with Keychains
25:12 - Keychain Key Rollover Configuration Example
26:38 - Keychain Key Rotation Demo
29:59 - Keychain Rollover final thoughts
31:17 - Main Takeaways

#ospf #networking #ccnp
================

To learn more about Hashing Algorithms:

To learn more about Data Integrity and HMACs:

================

💬 Join us on Discord:

📜 Studying for the CCNA? Check out these free resources:

Рекомендации по теме
Комментарии
Автор

This is awesome!
Everything you teach is always new, and I often gain understanding. Your material is so good that I have to study in many cycles. At the first attempt, one is often tempted to think it's mastered because you're good at what you do, making complex concepts look easy. Cautiously, I know I have to read, watch, and listen a few times more to make it familiar. You are always my reference point, and I cannot thank you enough for this.

adedejiemmanuel
Автор

1 of the best or maybe even the best explanation i've seen so far regarding auth in ospf. I was not sure about the date rotation of keys, but it is clear now. Thank you.

michalczapnik
Автор

As always, excellent and informative video. Well organized, too.

scottspa
Автор

The content is o rich. I watched the video and helped me a great deal. thanks you are awesome

sayan.rahman
Автор

Learned a lot from this series! Extremely AWESOME. Will you make one for BGP?

sateeshkumar
Автор

Which is the best practice and which method of authenticationis used in real-world? Btw great series keep going

Mindgame
Автор

Your videos are fantastic!
I still have a question though, is there the concept of youngest key in with the key chain? Which key will be chosen if there are multiple key ids without date and time specified?

lucas
Автор

Thank you so very much I have learned more from you and your videos than me School has taught me. I don’t know if I asked this but can you do EIGRP or BGP kinda hard to grasp the concept of them???

JamesJohnson-stwf
Автор

Sir Just make a similar series for BGP as soon as possible.

TheKhidki
Автор

Could you do a video, or small deepdive about STUN protocol one day?

Gurben
Автор

Hey @Ed can you pls tell me what is the purpose of key rotation?

himanshibhambhani
Автор

thank you so much dude you're a god

skeheterammurshed
Автор

I´m not certain this will interest you but, there are 1 billion native Spanish speakers. I´m not one. However, as a Spanish learner, English teacher, I know how super difficult it is to find good voices, and you have one. IF you did becoming interested in expanding your audience by 20 or 30, 000 of an estimate, I do know for a fact that SPAIN, specially Málaga, is rapidly expanding American-based technology and International company business. They are desperate to learn protocols in the language you provide. The only change I would suggest, if you wish to engage is, preventing the drop off of your final syllable in your words. It´s extremely common where we just barely pronounce the last syllable. Secondly, keep an even meter, which mostly you do. Your material could actually save families from poverty and help folks with dreams they never could have realized otherwise. What you do is important!

espartaco
Автор

Dang ospf seems complicated and unpractical. theyre just gonna invent something better and simpler like is-is underlay then overlay using sd access.

justinava