CR16与第三方设备直连,其接口加了OSPFv3认证后邻居down,去掉之后邻居UP。
报错:
%Aug 27 02:04:31:385 2021 NMHH_PAA_H3CCR16010F_Route01 OSPFV3/5/OSPFv3_NBR_CHG: OSPFv3 1 Neighbor 10.234.81.2(Vlan-interface650) received InactivityTimer and its state changed from FULL to DOWN.
%Aug 27 02:04:31:384 2021 NMHH_PAA_H3CCR16010F_Route01 OSPFV3/6/OSPFv3_LAST_NBR_DOWN: OSPFv3 1 Last neighbor down event: Router ID: 10.234.81.2 Local interface ID: 8971 Remote interface ID: 8968 Reason: DeadInterval timer expired.
配置:
keychain ospfv3 mode absolute
key 1
key-string cipher $c$3$jK2BmkUtS7KOQre1RKF8J1mrMY0Jh40yTYU=
authentication-algorithm hmac-md5
send-lifetime utc 00:00:00 2000/01/01 duration infinite
accept-lifetime utc 00:00:00 2000/01/01 duration infinite
配置OSPFv3验证后,OSPFv3路由器建立邻居关系时,在发送的报文中会携带验证字段,在接收报文时会进行验证,只有通过验证的报文才能接收,否则将不会接收报文,不能正常建立邻居。
当前客户配置的认证算法是hmac-md5,而目前CR16设备OSPFv3仅支持HMAC-SHA-256和HMAC-SM3认证算法,从而导致报文校验失败,
将authentication-algorithm 改为HMAC-SHA-256或者HMAC-SM3后认证正常。
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作