cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
701
Views
0
Helpful
4
Replies
arriejones
Beginner

No HSRP Version 2 authentication after XR 4.3.0??

Hi all.  I see there is no more authentication option for HSRP after the 4.3.0 release.  This is a feature we require and I'm wondering why Cisco did this and if they had another solution that I don't know about.

Thanks!!

Arrie

1 ACCEPTED SOLUTION

Accepted Solutions

Yes for HSRPv2 authentication was removed. There are several problems with the security of HSRPv2 which led to its removal.Section 9 of RFC5798 gives a good overview of the security issues for VRRP (similar applies to HSRP) https://tools.ietf.org/html/rfc5798#section-9 Sam

View solution in original post

4 REPLIES 4
smilstea
Cisco Employee

Hi Arrie,

The syntax changed in 4.2.0 to 'authentication'.

http://www.cisco.com/c/en/us/td/docs/routers/asr9000/software/addr_serv/command/reference/b-ipaddr-cr-asr9k/b-ipaddr-cr-asr9k_chapter_0110.html#wp1918271281

Thanks,

Sam

See the note in this confg guide for ASR9K 5.3.2.  It says it’s not supported.  Wondering why and if there is another method of authentication I should be looking at.  Pretty new to XR.

 

http://www.cisco.com/c/en/us/td/docs/routers/asr9000/software/asr9k_r5-3/addr-serv/configuration/guide/b-ipaddr-cg53asr9k/b-ipaddr-cg53asr9k_chapter_0111.html#p

 

HSRP version 2 authentication is not supported from release 4.3.x onwards.

 

Yes for HSRPv2 authentication was removed. There are several problems with the security of HSRPv2 which led to its removal.Section 9 of RFC5798 gives a good overview of the security issues for VRRP (similar applies to HSRP) https://tools.ietf.org/html/rfc5798#section-9 Sam

View solution in original post

Thank you Sam!

Content for Community-Ad