cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
0
Helpful
0
Replies

ISIS Hello Password Key chain not working

Hej
We are running Cisco 8202 and ASR9903 platforms. We have the below config on both devices but ISIS does not come up while I have below configured on both devices.

We have exact same password and it is 16 characters long exactly. So don't know what is causing the error

Config

Spoiler
key chain isis_hello-nuuday
 key 1
  accept-lifetime 00:00:00 september 01 2021 infinite
  key-string password 052235261273662C
  send-lifetime 00:00:00 september 01 2021 infinite
  cryptographic-algorithm AES-128-CMAC-96
 !
 accept-tolerance infinite
!
router isis CORE
 interface Bundle-Ether1000
  circuit-type level-2-only
  point-to-point
  hello-padding disable
  hello-password keychain isis_hello-nuuday
  address-family ipv4 unicast
   fast-reroute per-prefix level 2
   fast-reroute per-prefix ti-lfa level 2
  !
  address-family ipv6 unicast
   fast-reroute per-prefix level 2
   fast-reroute per-prefix ti-lfa level 2
  !
 !
!

The error

RP/0/RP0/CPU0:Mar 20 10:29:34.305 CET: isis[1005]: %ROUTING-ISIS-5-AUTH_KEY_LENGTH : ISIS (CORE): AES-128-CMAC-96 authentication key-strings must be exactly 16 characters long 

RP/0/RP0/CPU0:Mar 20 10:29:55.555 CET: isis[1005]: %ROUTING-ISIS-5-AUTH_FAILURE_DROP : ISIS (CORE): Dropped P2P IIH from Bundle-Ether1000 SNPA 6879.0973.e0ac due to cryptographic password mismatch 

 

0 Replies 0
Review Cisco Networking for a $25 gift card