Showing posts with label EIGRP. Show all posts
Showing posts with label EIGRP. Show all posts

Thursday, December 29, 2011

Time-Based Eigrp Authentication

Time-Based Eigrp Authentication:

For example, if we add accept-lifetime command in the key chain configuration like this on 23:01:19.203 UTC Wed Dec 3 2011:

   

key chain AUTH
 key 1
   key-string 123456
   accept-lifetime 16:00:00 Oct 14 2011 14:00:00 Dec 2 2011
   send-lifetime 15:00:00 Oct 15 2011 infinite

After Dec 2 2011, Eigrp neighborship is closed with an error message of:

%DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor 192.168.12.1 (FastEthernet0/0) is down: Auth failure

Because accept-lifetime of key 1 is expired.


Lets do another time based Eigrp Authentication configuration example.

We set the clock manually on both routers at same time:

clock set 22:58:00 Nov 30 2011

Then we configure these key chain configurations on both routers:

key chain AUTH
 key 1
   key-string 123456
   accept-lifetime 16:00:00 Oct 14 2011 14:00:00 Dec 2 2011
   send-lifetime 15:00:00 Oct 15 2011 23:00:00 Nov 30 2011
 key 2
   key-string 123456
   accept-lifetime 22:00:00 Nov 30 2011 infinite
   send-lifetime 22:00:00 Nov 30 2011 infinite

Note: lowest key-id number is always prefered if it is in valid time range.


Then we wait for key-id change after 23:00:00.

Here is the debug eigrp packet outputs:



Nov 30 22:59:55.459: EIGRP: received packet with MD5 authentication, key id = 1
Nov 30 22:59:55.463: EIGRP: Received HELLO on FastEthernet0/0 nbr 192.168.12.2
Nov 30 22:59:55.467:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0 peerQ un/rely 0/0
Nov 30 22:59:57.291: EIGRP: Sending HELLO on FastEthernet0/1
Nov 30 22:59:57.295:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 22:59:57.615: EIGRP: Sending HELLO on Loopback0
Nov 30 22:59:57.619:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 22:59:57.631: EIGRP: Received HELLO on Loopback0 nbr 192.168.0.1
Nov 30 22:59:57.635:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0
Nov 30 22:59:57.635: EIGRP: Packet from ourselves ignored
Nov 30 22:59:57.963: EIGRP: Sending HELLO on FastEthernet0/0
Nov 30 22:59:57.967:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 22:59:58.063: EIGRP: Received HELLO on FastEthernet0/1 nbr 192.168.13.3
Nov 30 22:59:58.067:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0 peerQ un/rely 0/0
Nov 30 23:00:00.199: EIGRP: received packet with MD5 authentication, key id = 1
Nov 30 23:00:00.203: EIGRP: Received HELLO on FastEthernet0/0 nbr 192.168.12.2
Nov 30 23:00:00.207:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0 peerQ un/rely 0/0
Nov 30 23:00:01.763: EIGRP: Sending HELLO on FastEthernet0/1
Nov 30 23:00:01.767:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 23:00:02.231: EIGRP: Sending HELLO on Loopback0
Nov 30 23:00:02.235:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 23:00:02.243: EIGRP: Received HELLO on Loopback0 nbr 192.168.0.1
Nov 30 23:00:02.247:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0
Nov 30 23:00:02.247: EIGRP: Packet from ourselves ignored
Nov 30 23:00:02.443: EIGRP: Sending HELLO on FastEthernet0/0
Nov 30 23:00:02.447:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 23:00:02.779: EIGRP: Received HELLO on FastEthernet0/1 nbr 192.168.13.3
Nov 30 23:00:02.783:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0 peerQ un/rely 0/0
Nov 30 23:00:05.131: EIGRP: received packet with MD5 authentication, key id = 2
Nov 30 23:00:05.135: EIGRP: Received HELLO on FastEthernet0/0 nbr 192.168.12.2
Nov 30 23:00:05.139:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0 peerQ un/rely 0/0
Nov 30 23:00:06.307: EIGRP: Sending HELLO on FastEthernet0/1
Nov 30 23:00:06.311:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 23:00:06.491: EIGRP: Sending HELLO on Loopback0
Nov 30 23:00:06.495:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 23:00:06.495: EIGRP: Received HELLO on Loopback0 nbr 192.168.0.1
Nov 30 23:00:06.495:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0
Nov 30 23:00:06.495: EIGRP: Packet from ourselves ignored
Nov 30 23:00:07.063: EIGRP: Sending HELLO on FastEthernet0/0
Nov 30 23:00:07.067:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0
Nov 30 23:00:07.723: EIGRP: Received HELLO on FastEthernet0/1 nbr 192.168.13.3
Nov 30 23:00:07.723:   AS 1, Flags 0x0, Seq 0/0 idbQ 0/0 iidbQ un/rely 0/0 peerQ un/rely 0/0
Nov 30 23:00:10.091: EIGRP: received packet with MD5 authentication, key id = 2

Key-id changed without clearing the eigrp neighborship.

R2#show key chain
Key-chain AUTH:
    key 1 -- text "123456"
        accept lifetime (16:00:00 UTC Oct 14 2011) - (14:00:00 UTC Dec 2 2011) [valid now]
        send lifetime (15:00:00 UTC Oct 15 2011) - (23:00:00 UTC Nov 30 2011)
    key 2 -- text "123456"
        accept lifetime (22:00:00 UTC Nov 30 2011) - (infinite) [valid now]
        send lifetime (22:00:00 UTC Nov 30 2011) - (infinite) [valid now]

Eigrp Authentication

Eigrp Authentication

- Eigrp Authentication must be enabled on both routers.
- Key-id and key-string must match on both routers.

These configurations should be added to both Eigrp neighboring routers for Eigrp Authentication :

key chain AUTH
 key 10
   key-string 123456

interface FastEthernet0/0
 ip authentication mode eigrp 1 md5
 ip authentication key-chain eigrp 1 AUTH


If we enable Eigrp Authentication one of them, we can get these type of log messages, when “debug eigrp packet” command is active:

* EIGRP: FastEthernet0/0: ignored packet from 192.168.12.2, opcode = 5 (missing authentication)

If the key id and key-string does not match, we can get these type of log messages, when “debug eigrp packet” command is active:

*EIGRP: FastEthernet0/0: ignored packet from 192.168.12.2, opcode = 5 (invalid authentication)



Basic Eigrp Configuration

Basic Eigrp Configuration

After EIGRP process is configured on the router, the router starts to exchange EIGRP hello packets over the multicast address 224.0.0.10.Eigrp neighborships form between routers after they get each other's hello packet.

Some rules for these neighborships:

-      The receiving router compares the source address of the hello packet with the IP address of the interface where the packet was received.These IP addresses must be in same subnet.
-      The routers compares the K constant values of each other.These K values must match.
-      The routers must use the same AS number for Eigrp.

Basic Eigrp configuration between two  routers:

Router1:

interface Loopback0
 ip address 192.168.0.1 255.255.255.255
!
interface FastEthernet0/0
 ip address 192.168.12.1 255.255.255.0

router eigrp 1
 network 192.168.0.0 0.0.255.255
 no auto-summary

Here is the basic Eigrp configuration for Router2

interface Loopback0
 ip address 192.168.0.2 255.255.255.255
!
interface FastEthernet0/0
 ip address 192.168.12.2 255.255.255.0

router eigrp 1
 network 192.168.0.0 0.0.255.255
 no auto-summary


Verification:

R1#show ip eigrp neighbors
IP-EIGRP neighbors for process 1
H   Address                 Interface       Hold Uptime   SRTT   RTO  Q  Seq
                                            (sec)         (ms)       Cnt Num
0   192.168.12.2            Fa0/0             13 00:25:40  286  1716  0  36

The explanations of the “show ip eigrp neighbors” command output:

H— The list of the neighbors.

Address— The IP address of the neighbors.

Interface— The interface that the router communicate with the neighbor.

Hold— The hold timer for the neighbor. If this timer reaches 0, the neighbor relationship becomes down

Uptime— shows the how long this neighbor has been established.

SRTT (Smooth Round Trip Time)— The average time interval for EIGRP packet is sent and received.

RTO (Round Trip Timeout)— How long the router will wait to retransmit the EIGRP reliable packet if acknowledgment is not received.

Q Count— The number of EIGRP packets waiting to
 be sent to the neighbor.

Sequence Number— The sequence number of the last EIGRP reliable packets being
received from the neighbor.

Eigrp Metric Calculation

EIGRP Metric Calculation:
Eigrp Metric=256x[(10.000.000/ min bw in kbps along the path)+(total delay in tens of microseconds along the path)]

Lets do an example for Eigrp Metric Calculation:
For example, We have an EIGRP topology entry like this:

R1#show ip eigrp topology 192.168.0.2/32
IP-EIGRP (AS 1): Topology entry for 192.168.0.2/32
  State is Passive, Query origin flag is 1, 1 Successor(s), FD is 409600
  Routing Descriptor Blocks:
  192.168.12.2 (FastEthernet0/0), from 192.168.12.2, Send flag is 0x0
      Composite metric is (409600/128256), Route is Internal
      Vector metric:
        Minimum bandwidth is 10000 Kbit
        Total delay is 6000 microseconds
        Reliability is 255/255
        Load is 1/255
        Minimum MTU is 1500
        Hop count is 1

Formula is:
Eigrp Metric=256x[(10.000.000/ min bw in kbps along the path)+(total delay in tens of microseconds along the path)]
So;
256x[(10000000/10000)+(6000/10)]=256x1600=409600 is the Eigrp metric for this route.