6.3.7 Packet Tracer - Configure OSPF Authentication (Answeers Version)
Tolology:

6.3.7 Packet Tracer - Configure OSPF Authentication
Addressing Table
| Device | Interface | IP Address | Subnet Mask | Default Gateway | Switch Port |
|---|---|---|---|---|---|
| R1 | G0/0/0 | 10.1.1.1 | 255.255.255.252 | N/A | N/A |
| G0/0/1 | 192.168.1.1 | 255.255.255.0 | N/A | S1F0/5 | |
| R2 | G0/0/0 | 10.1.1.2 | 255.255.255.252 | N/A | N/A |
| G0/0/1 | 10.2.2.2 | 255.255.255.252 | N/A | N/A | |
| R3 | G0/0/0 | 10.2.2.1 | 255.255.255.252 | N/A | N/A |
| G0/0/1 | 192.168.3.1 | 255.255.255.0 | N/A | S3F0/5 | |
| PC-A | NIC | 192.168.1.5 | 255.255.255.0 | 192.168.1.1 | S1F0/6 |
| PC-B | NIC | 192.168.1.6 | 255.255.255.0 | 192.168.1.1 | S1F0/18 |
| PC-C | NIC | 192.168.3.5 | 255.255.255.0 | 192.168.3.1 | S3F0/18 |
Objectives
- Configure OSPF MD5 authentication.
Background / Scenario
In this activity, you will configure OSPF MD5 authentication for secure routing updates.
Instructions
Part 1: Configure OSPF MD5 Authentication
Step 1: Test connectivity. All devices should be able to ping all other IP addresses.
Step 2: Configure OSPF MD5 authentication for all the routers in area 0.
Configure OSPF MD5 authentication for all the routers in area 0.
R1(config)# router ospf 1 R1(config-router)# area 0 authentication message-digest
R2(config)# router ospf 1 R2(config-router)# area 0 authentication message-digest
R3(config)# router ospf 1 R3(config-router)# area 0 authentication message-digest
Step 3: Configure the MD5 key for all the routers in area 0.
Configure an MD5 key on the GigabitEthernet interfaces on R1, R2 and R3. Use the password MD5pa55 for key 1.
R1(config)# interface g0/0/0 R1(config-if)# ip ospf message-digest-key 1 md5 MD5pa55
R2(config)# interface g0/0/0 R2(config-if)# ip ospf message-digest-key 1 md5 MD5pa55 R2(config-if)# interface g0/0/1 R2(config-if)# ip ospf message-digest-key 1 md5 MD5pa55
R3(config)# interface g0/0/1 R3(config-if)# ip ospf message-digest-key 1 md5 MD5pa55
Step 4: Verify configurations.
a. Verify the MD5 authentication configurations using the commands show ip ospf interface.
b. Verify end-to-end connectivity.
Device Configs - Final
ROUTER R1
! ============================================================== !--- 6.3.7 Packet Tracer - Configure OSPF Authentication !--- ANSWER SCRIPT FOR ROUTER R1 !--- Usage: copy this whole file and paste it into the R1 terminal (start at the R1> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Configure the OSPF MD5 Key on WAN Interfaces. ! -------------------------------------------------------------- !--- Configure the MD5 key on the link to R2 (10.1.1.0/30) so hellos on this segment can be authenticated. Use password MD5pa55 for key 1. interface gigabitethernet 0/0/0 ip ospf message-digest-key 1 md5 MD5pa55 exit ! -------------------------------------------------------------- !--- Part 2: Enable OSPF Area 0 MD5 Authentication. ! -------------------------------------------------------------- !--- Turn on MD5 authentication for every OSPF interface in area 0. router ospf 1 area 0 authentication message-digest exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show ip ospf interface g0/0/0 -> confirms "Message digest authentication enabled", Youngest key id 1 !--- show ip ospf neighbor -> confirms the adjacency with R2 stays FULL after authentication is enabled !--- ping 10.1.1.2 -> confirms Layer 3 reachability to R2 (OSPF auth doesn't affect plain IP) !--- ping 192.168.3.5 -> confirms end-to-end reachability to PC-C, proving routes learned via the now-authenticated OSPF session are still valid !--- Note: G0/0/1 (the LAN side, facing S1) is deliberately left without a message-digest-key. "area 0 !--- authentication message-digest" applies to the whole area, but only interfaces with an active OSPF !--- neighbor need a matching key to form an adjacency — no other router sits on the 192.168.1.0/24 segment. ! ==============================================================
ROUTER R2
! ============================================================== !--- 6.3.7 Packet Tracer - Configure OSPF Authentication !--- ANSWER SCRIPT FOR ROUTER R2 !--- Usage: copy this whole file and paste it into the R2 terminal (start at the R2> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Configure the OSPF MD5 Key on WAN Interfaces. ! -------------------------------------------------------------- !--- Configure the MD5 key on the link to R1 (10.1.1.0/30). Use password MD5pa55 for key 1. interface gigabitethernet 0/0/0 ip ospf message-digest-key 1 md5 MD5pa55 exit !--- Configure the MD5 key on the link to R3 (10.2.2.0/30). Use password MD5pa55 for key 1. interface gigabitethernet 0/0/1 ip ospf message-digest-key 1 md5 MD5pa55 exit ! -------------------------------------------------------------- !--- Part 2: Enable OSPF Area 0 MD5 Authentication. ! -------------------------------------------------------------- !--- Turn on MD5 authentication for every OSPF interface in area 0. router ospf 1 area 0 authentication message-digest exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show ip ospf interface brief -> confirms both G0/0/0 and G0/0/1 show OSPF running with message-digest auth !--- show ip ospf neighbor -> confirms adjacencies with both R1 and R3 stay FULL after authentication is enabled !--- ping 10.1.1.1 -> confirms Layer 3 reachability to R1 !--- ping 10.2.2.1 -> confirms Layer 3 reachability to R3 !--- Note: R2 has no directly attached LAN in this topology, so both of its GigabitEthernet interfaces !--- sit on router-to-router links and both need the message-digest-key — unlike R1/R3, which each have !--- one WAN interface (keyed) and one LAN interface (not keyed, no OSPF neighbor there). ! ==============================================================
ROUTER R3
! ============================================================== !--- 6.3.7 Packet Tracer - Configure OSPF Authentication !--- ANSWER SCRIPT FOR ROUTER R3 !--- Usage: copy this whole file and paste it into the R3 terminal (start at the R3> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Configure the OSPF MD5 Key on WAN Interfaces. ! -------------------------------------------------------------- !--- Configure the MD5 key on the link to R2 (10.2.2.0/30) so hellos on this segment can be authenticated. Use password MD5pa55 for key 1. interface gigabitethernet 0/0/0 ip ospf message-digest-key 1 md5 MD5pa55 exit ! -------------------------------------------------------------- !--- Part 2: Enable OSPF Area 0 MD5 Authentication. ! -------------------------------------------------------------- !--- Turn on MD5 authentication for every OSPF interface in area 0. router ospf 1 area 0 authentication message-digest exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show ip ospf interface g0/0/0 -> confirms "Message digest authentication enabled", key id 1 !--- show ip ospf neighbor -> confirms the adjacency with R2 stays FULL after authentication is enabled !--- ping 10.2.2.2 -> confirms Layer 3 reachability to R2 !--- ping 192.168.1.5 -> confirms end-to-end reachability to PC-A, proving routes learned via the now-authenticated OSPF session are still valid !--- Note: G0/0/1 (the LAN side, facing S3) is deliberately left without a message-digest-key, for the !--- same reason as R1's LAN interface — no other router sits on the 192.168.3.0/24 segment. ! ==============================================================




