Hej We are running Cisco 8202 and ASR9903 platforms. We have the below config on both devices but ISIS does not come up while I have below configured on both devices.
We have exact same password and it is 16 characters long exactly. So don't know what is causing the error
Config
Spoiler (Highlight to read) key chain isis_hello-nuuday
key 1
accept-lifetime 00:00:00 september 01 2021 infinite
key-string password 052235261273662C
send-lifetime 00:00:00 september 01 2021 infinite
cryptographic-algorithm AES-128-CMAC-96
!
accept-tolerance infinite
!
router isis CORE
interface Bundle-Ether1000
circuit-type level-2-only
point-to-point
hello-padding disable
hello-password keychain isis_hello-nuuday
address-family ipv4 unicast
fast-reroute per-prefix level 2
fast-reroute per-prefix ti-lfa level 2
!
address-family ipv6 unicast
fast-reroute per-prefix level 2
fast-reroute per-prefix ti-lfa level 2
!
!
!
key chain isis_hello-nuuday
key 1
accept-lifetime 00:00:00 september 01 2021 infinite
key-string password 052235261273662C
send-lifetime 00:00:00 september 01 2021 infinite
cryptographic-algorithm AES-128-CMAC-96
!
accept-tolerance infinite
!
router isis CORE
interface Bundle-Ether1000
circuit-type level-2-only
point-to-point
hello-padding disable
hello-password keychain isis_hello-nuuday
address-family ipv4 unicast
fast-reroute per-prefix level 2
fast-reroute per-prefix ti-lfa level 2
!
address-family ipv6 unicast
fast-reroute per-prefix level 2
fast-reroute per-prefix ti-lfa level 2
!
!
!
The error
RP/0/RP0/CPU0:Mar 20 10:29:34.305 CET: isis[1005]: %ROUTING-ISIS-5-AUTH_KEY_LENGTH : ISIS (CORE): AES-128-CMAC-96 authentication key-strings must be exactly 16 characters long
RP/0/RP0/CPU0:Mar 20 10:29:55.555 CET: isis[1005]: %ROUTING-ISIS-5-AUTH_FAILURE_DROP : ISIS (CORE): Dropped P2P IIH from Bundle-Ether1000 SNPA 6879.0973.e0ac due to cryptographic password mismatch