Information
The TCP sessions between the two peers can be secured by adding MD5 protection to the TCP sessionheader
Authenticating BGP peers using MD5 ensures that only trusted and authorized devices can establish BGP sessions, protecting the integrity of the routing infrastructure. By adding a cryptographic layer of authentication, MD5 mitigates risks such as session hijacking, spoofed connection attempts, or unauthorized access, ensuring that routing updates are exchanged securely between peers
Solution
The TCP sessions between the two peers can be secured by adding MD5 protection to the TCP sessionheader. The MD5 digest acts like a password between peers. This configuration is done within the BGPconfiguration context, and both peers need to configure the same password either plaintext or ciphertext.
switch(config)# router bgp <ASN>
switch(config-bgp)# neighbor {<IP-ADDR>|<PEER-GROUP-NAME>} password [{ciphertext | plaintext} <PASSWORD>]
Impact:
Using MD5 for BGP peer authentication significantly improves network security by preventing unauthorized devices from establishing BGP sessions. This reduces the risk of malicious activity, such as route injection or disruption of routing operations, ensuring reliable and secure communication between peers while maintaining the stability and trustworthiness of critical routing protocols.
Item Details
Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION
References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|16.4, CSCv7|16.5
Control ID: b8cd778894db929396e82aaff343af9b8c7805a702f41f416281d2b7f4966107