3.1.2.2 Authenticate BGP Peers Using MD5

Information

The TCP sessions between the two peers can be secured by adding MD5 protection to the TCP sessionheader

Authenticating BGP peers using MD5 ensures that only trusted and authorized devices can establish BGP sessions, protecting the integrity of the routing infrastructure. By adding a cryptographic layer of authentication, MD5 mitigates risks such as session hijacking, spoofed connection attempts, or unauthorized access, ensuring that routing updates are exchanged securely between peers

Solution

The TCP sessions between the two peers can be secured by adding MD5 protection to the TCP sessionheader. The MD5 digest acts like a password between peers. This configuration is done within the BGPconfiguration context, and both peers need to configure the same password either plaintext or ciphertext.

switch(config)# router bgp <ASN>
switch(config-bgp)# neighbor {<IP-ADDR>|<PEER-GROUP-NAME>} password [{ciphertext | plaintext} <PASSWORD>]

Impact:

Using MD5 for BGP peer authentication significantly improves network security by preventing unauthorized devices from establishing BGP sessions. This reduces the risk of malicious activity, such as route injection or disruption of routing operations, ensuring reliable and secure communication between peers while maintaining the stability and trustworthiness of critical routing protocols.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|16.4, CSCv7|16.5

Plugin: ArubaOS

Control ID: b8cd778894db929396e82aaff343af9b8c7805a702f41f416281d2b7f4966107