SV-80599r1_rule
V-66109
SRG-NET-000025-RTR-000020
HFFS-RT-000010
CAT II
10
The following example shows how to configure the network device to authenticate OSPF and OSPFv3 packets with its peers.
OSPF configuration:
[HP] ospf 200
[HP-ospf-200] area 0.0.0.0
[HP-ospf-200-area-0.0.0.0] authentication-mode md5 1 cipher *************
[HP-ospf-200-area-0.0.0.0] network 201.6.1.60 0.0.0.3
OSPFv3 Configuration
[HP] ospfv3 200
[HP-ospf-200] area 0.0.0.0
IPsec profile configuration for OSPFv3
[HP] ipsec profile jitc manual
[HP--ipsec-profile-manual-jitc] transform-set jitcipsecprop
[HP--ipsec-profile-manual-jitc] sa spi inbound esp 256
[HP--ipsec-profile-manual-jitc] sa string-key inbound esp simple 2!HPAdmin123123
[HP--ipsec-profile-manual-jitc] sa spi outbound esp 256
[HP--ipsec-profile-manual-jitc] sa string-key outbound esp simple 2!HPAdmin123123
Interface configuration
interface GigabitEthernet0/0
port link-mode route
description R1 ACTIVE
combo enable copper
ip address 201.6.1.62 255.255.255.252
ospf authentication-mode md5 1 cipher $c$3$6v1tbSQA2aWAzrgzm36LZrBbmS+jUeg=
ospfv3 200 area 0.0.0.0
ospfv3 ipsec-profile jitc
ipv6 address 2115:B:1::3E/126
Review the HP FlexFabric Switch configuration; for every protocol that affects the routing or forwarding tables (where information is exchanged between neighbors), verify that neighbor HP FlexFabric Switch authentication is enabled.
If neighbor authentication for all router control plane protocols is not configured, this is a finding.
The information below shows OSPF and OSPFv3 authentication is enabled on interface gigabit ethernet 0/0
[HP] display current-configuration interface GigabitEthernet 0/0
#
interface GigabitEthernet0/0
port link-mode route
description R1 ACTIVE
combo enable copper
ip address 201.6.1.62 255.255.255.252
ospf authentication-mode md5 1 cipher **********
ospfv3 200 area 0.0.0.0
ospfv3 ipsec-profile jitc
ipv6 address 2115:B:1::3E/126
V-66109
False
HFFS-RT-000010
Review the HP FlexFabric Switch configuration; for every protocol that affects the routing or forwarding tables (where information is exchanged between neighbors), verify that neighbor HP FlexFabric Switch authentication is enabled.
If neighbor authentication for all router control plane protocols is not configured, this is a finding.
The information below shows OSPF and OSPFv3 authentication is enabled on interface gigabit ethernet 0/0
[HP] display current-configuration interface GigabitEthernet 0/0
#
interface GigabitEthernet0/0
port link-mode route
description R1 ACTIVE
combo enable copper
ip address 201.6.1.62 255.255.255.252
ospf authentication-mode md5 1 cipher **********
ospfv3 200 area 0.0.0.0
ospfv3 ipsec-profile jitc
ipv6 address 2115:B:1::3E/126
M
2979