3.3.2.2 Set 'ip ospf message-digest-key md5'

Information

Enable Open Shortest Path First (OSPF) Message Digest 5 (MD5) authentication.

This is part of the OSPF authentication setup

Solution

Configure the appropriate interface(s) for Message Digest authentication

hostname(config)#interface {<em>interface_name</em>}
hostname(config-if)#ip ospf message-digest-key {<em>ospf_md5_key-id</em>} md5 {<em>ospf_md5_key</em>}

Impact:

Organizations should plan and implement enterprise security policies that require rigorous authentication methods for routing protocols. Configuring the proper interface(s) for 'ip ospf message-digest-key md5' enforces these policies by restricting exchanges between network devices.

See Also

https://workbench.cisecurity.org/benchmarks/22550

Item Details

Category: ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-18, 800-53|AC-18(1), 800-53|AC-18(3), 800-53|CA-9, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Cisco

Control ID: b0cf056cc7dcbf4a976c9f77a08ac11c508b75c7ee8845ac4f78b64b16e9c9fa