cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
482
Views
5
Helpful
6
Replies

OSPF Key Chain - Send Lifetime and Accept Time - Doubt

Othacon
Level 1
Level 1

Hi all,

hope you can help me.

I'm having my mind melted with the Keychain Accept and Lifetimes, basically I'm getting confused from all the info I see. 

Please would it be possible to confirm if the below is correct? 

key chain TEST
key 6
accept-lifetime local 10:00:00 Jun 12 2024 14:00:00 Dec 12 2024
send-lifetime local 11:00:00 Jun 12 2024 13:00:00 Dec 12 2024
key 7
accept-lifetime local 10:00:00 Dec 11 2024 14:00:00 Jun 13 2025
send-lifetime local 11:00:00 Dec 11 2024 13:00:00 Jun 13 2025
key 8
accept-lifetime local 10:00:00 Jun 12 2025 14:00:00 Dec 12 2025
send-lifetime local 11:00:00 Jun 12 2025 13:00:00 Dec 12 2025
key 9
accept-lifetime local 10:00:00 Dec 11 2025 14:00:00 Jun 13 2026
send-lifetime local 11:00:00 Dec 11 2025 13:00:00 Jun 13 2026
key 10
accept-lifetime local 10:00:00 Jun 12 2026 14:00:00 Dec 12 2026
send-lifetime local 11:00:00 Jun 12 2026 13:00:00 Dec 12 2026
key 11
accept-lifetime local 10:00:00 Dec 11 2026 14:00:00 Jun 13 2027
send-lifetime local 11:00:00 Dec 11 2026 13:00:00 Jun 13 2027
key 12
accept-lifetime local 10:00:00 Jun 12 2027 14:00:00 Dec 12 2027
send-lifetime local 11:00:00 Jun 12 2027 13:00:00 Dec 12 2027
key 13
accept-lifetime local 10:00:00 Dec 11 2027 14:00:00 Jun 13 2028
send-lifetime local 11:00:00 Dec 11 2027 13:00:00 Jun 13 2028
key 14
accept-lifetime local 10:00:00 Jun 12 2028 14:00:00 Dec 12 2028
send-lifetime local 11:00:00 Jun 12 2028 13:00:00 Dec 12 2028
key 15
accept-lifetime local 10:00:00 Dec 11 2028 14:00:00 Jun 13 2029
send-lifetime local 11:00:00 Dec 11 2028 13:00:00 Jun 13 2029
key 16
accept-lifetime local 10:00:00 Jun 12 2029 14:00:00 Dec 12 2029
send-lifetime local 11:00:00 Jun 12 2029 13:00:00 Dec 12 2029
key 17
accept-lifetime local 10:00:00 Dec 11 2029 14:00:00 Jun 13 2030
send-lifetime local 11:00:00 Dec 11 2029 13:00:00 Jun 13 2030
key 18
accept-lifetime local 10:00:00 Jun 12 2030 14:00:00 Dec 12 2030
send-lifetime local 11:00:00 Jun 12 2030 13:00:00 Dec 12 2030
key 19
accept-lifetime local 10:00:00 Dec 11 2030 14:00:00 Jun 13 2031
send-lifetime local 11:00:00 Dec 11 2030 13:00:00 Jun 13 2031
key 20
accept-lifetime local 10:00:00 Jun 12 2031 14:00:00 Dec 12 2031
send-lifetime local 11:00:00 Jun 12 2031 13:00:00 Dec 12 2031
key 21
accept-lifetime local 10:00:00 Dec 11 2031 14:00:00 Jun 13 2032
send-lifetime local 11:00:00 Dec 11 2031 13:00:00 Jun 13 2032
key 22
accept-lifetime local 10:00:00 Jun 12 2032 14:00:00 Dec 12 2032
send-lifetime local 11:00:00 Jun 12 2032 13:00:00 Dec 12 2032
key 23
accept-lifetime local 10:00:00 Dec 11 2032 14:00:00 Jun 13 2033
send-lifetime local 11:00:00 Dec 11 2032 13:00:00 Jun 13 2033
key 24
accept-lifetime local 10:00:00 Jun 12 2033 14:00:00 Dec 12 2033
send-lifetime local 11:00:00 Jun 12 2033 13:00:00 Dec 12 2033
key 25
accept-lifetime local 10:00:00 Dec 11 2033 14:00:00 Jun 13 2034
send-lifetime local 11:00:00 Dec 11 2033 13:00:00 Jun 13 2034
key 26
accept-lifetime local 10:00:00 Jun 12 2034 14:00:00 Dec 12 2034
send-lifetime local 11:00:00 Jun 12 2034 13:00:00 Dec 12 2034
key 27
accept-lifetime local 10:00:00 Dec 11 2034 14:00:00 Jun 13 2035
send-lifetime local 11:00:00 Dec 11 2034 13:00:00 Jun 13 2035
key 28
accept-lifetime local 10:00:00 Jun 12 2035 infinite
send-lifetime local 11:00:00 Jun 12 2035 infinite

 

For what I see and understand, there's always a key overlapping by one day, so the data should always be flowing uninterruptedly, but really wanted to be sure, since really don't want the network to drop.  Hope you can advise.

Thank you

2 Accepted Solutions

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

that should as expected- make sure peer also have same timings.

If one authenticated and another one non authentication, neighborship go down, cause network tier down.

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_ospf/configuration/xe-3s/iro-xe-3s-book/iro-ospfv2-crypto-authen-xe.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

Hello


@Othacon wrote:
For what I see and understand, there's always a key overlapping by one day

Correct until it reaches key 28 and then its infinite and no key rolling will occur thereafter


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

View solution in original post

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

that should as expected- make sure peer also have same timings.

If one authenticated and another one non authentication, neighborship go down, cause network tier down.

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_ospf/configuration/xe-3s/iro-xe-3s-book/iro-ospfv2-crypto-authen-xe.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello


@Othacon wrote:
For what I see and understand, there's always a key overlapping by one day

Correct until it reaches key 28 and then its infinite and no key rolling will occur thereafter


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Would also suggest apply some higher security if applicable.
example:
key chain TEST
key x

cryptographic-algorithm hmac-sha-512


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Thank you @paul driver and @balaji.bandi , was going "crazy" just updated the keys. 

The last key was really because IOS wouldn't let me put more keys than the year 2035 so really had to go for infinite. Need to put a new IOS version and try, maybe now has more than the year 2035 has a limit. 

Hello
Note: Once you get into key7 you can at anytime thereafter reuse/modify key6 etc.... as the keys are all based on your switches/rtrs system time.


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

I wait to answer you to see using last key with and without infinite keyword
as I know when router detect it use last key it change the duration to be infinite by default to prevent return to un-auth status 
but I want to be sure before I answer you 
please confirm if you want lab check this status or not 

MHM

Review Cisco Networking for a $25 gift card