Supported Platforms
Related Documentation
- ACX, M, PTX, QFX, T Series
- Understanding BFD Authentication for BGP
- ACX, M, MX, QFX, T Series
- Example: Configuring BFD for BGP
- EX, M, MX, PTX, SRX, T Series
- bfd-liveness-detection
- Additional Information
- authentication-key-chains statement in the Junos OS System Basics Configuration Guide
- show bfd session command in the Junos OS Operational Mode Commands
Example: Configuring BFD Authentication for BGP
Beginning with Junos OS Release 9.6, you can configure authentication for BFD sessions running over BGP. Only three steps are needed to configure authentication on a BFD session:
- Specify the BFD authentication algorithm for the BGP protocol.
- Associate the authentication keychain with the BGP protocol.
- Configure the related security authentication keychain.
The following sections provide instructions for configuring and viewing BFD authentication on BGP:
Configuring BFD Authentication Parameters
BFD authentication can be configured for the entire BGP protocol, or a specific BGP group, neighbor, or routing instance.
The following example requires you to navigate various levels in the configuration hierarchy. For information about navigating the CLI, see Using the CLI Editor in Configuration Mode in the CLI User Guide.
To configure BFD authentication:
- Specify the algorithm (keyed-md5, keyed-sha-1, meticulous-keyed-md5, meticulous-keyed-sha-1,
or simple-password) to use.[edit]user@host# set protocols bgp bfd-liveness-detection authentication algorithm keyed-sha-1user@host# set protocols bgp group bgp-gr1 bfd-liveness-detection authentication algorithm keyed-sha-1user@host# set protocols bgp group bgp-gr1 neighbor 10.10.10.7 bfd-liveness-detection authentication algorithm keyed-sha-1
Note: Nonstop active routing is not supported with meticulous-keyed-md5 and meticulous-keyed-sha-1 authentication algorithms. BFD sessions using these algorithms might go down after a switchover.
- Specify the keychain to
be used to associate BFD sessions on BGP with the unique security
authentication keychain attributes.
The keychain name you specify must match a keychain name configured at the [edit security authentication key-chains] hierarchy level.
[edit]user@host# set protocols bgp bfd-liveness-detection authentication keychain bfd-bgpuser@host# set protocols bgp group bgp-gr1 bfd-liveness-detection authentication keychain bfd-bgpuser@host# set protocols bgp group bgp-gr1 neighbor 10.10.10.7 bfd-liveness-detection authentication keychain bfd-bgpNote: The algorithm and keychain must be configured on both ends of the BFD session, and they must match. Any mismatch in configuration prevents the BFD session from being created.
- Specify the unique security authentication information
for BFD sessions:
- The matching keychain name as specified in Step 2.
- At least one key, a unique integer between 0 and 63. Creating multiple keys allows multiple clients to use the BFD session.
- The secret data used to allow access to the session.
- The time at which the authentication key becomes active, in the format yyyy-mm-dd.hh:mm:ss.
[edit security]user@host# set authentication-key-chains key-chain bfd-bgp key 53 secret $9$ggaJDmPQ6/tJgF/AtREVsyPsnCtUHm start-time 2009-06-14.10:00:00 - (Optional) Specify loose authentication checking if you
are transitioning from nonauthenticated sessions to authenticated
sessions.[edit]user@host# set protocols bgp bfd-liveness-detection authentication loose-checkuser@host# set protocols bgp group bgp-gr1 bfd-liveness-detection authentication loose-checkuser@host# set protocols bgp group bgp-gr1 neighbor 10.10.10.7 bfd-liveness-detection authentication loose-check
- (Optional) View your configuration using the show bfd session detail or show bfd session extensive command.
- Repeat these steps to configure the other end of the BFD session.
![]() | Note: BFD authentication is only supported in the Canada and United States version of the Junos OS image and is not available in the export version. |
Viewing Authentication Information for BFD Sessions
You can view the existing BFD authentication configuration using the show bfd session detail and show bfd session extensive commands.
The following example shows BFD authentication configured for the bgp-gr1 BGP group. It specifies the keyed SHA-1 authentication algorithm and a keychain name of bfd-bgp. The authentication keychain is configured with two keys. Key 1 contains the secret data “$9$ggaJDmPQ6/tJgF/AtREVsyPsnCtUHm” and a start time of June 1, 2009, at 9:46:02 AM PST. Key 2 contains the secret data “$9$a5jiKW9l.reP38ny.TszF2/9” and a start time of June 1, 2009, at 3:29:20 PM PST.
If you commit these updates to your configuration, you see output similar to the following. In the output for the show bfd session detail command, Authenticate is displayed to indicate that BFD authentication is configured. For more information about the configuration, use the show bfd session extensive command. The output for this command provides the keychain name, the authentication algorithm and mode for each client in the session, and the overall BFD authentication configuration status, keychain name, and authentication algorithm and mode.
show bfd session detail
user@host# show bfd session detail Detect Transmit Address State Interface Time Interval Multiplier 50.0.0.2 Up ge-0/1/5.0 0.900 0.300 3 Client BGP, TX interval 0.300, RX interval 0.300, Authenticate Session up time 3d 00:34 Local diagnostic None, remote diagnostic NbrSignal Remote state Up, version 1 Replicated
show bfd session extensive
user@host# show bfd session extensive Detect Transmit Address State Interface Time Interval Multiplier 50.0.0.2 Up ge-0/1/5.0 0.900 0.300 3 Client BGP, TX interval 0.300, RX interval 0.300, Authenticate keychain bfd-bgp, algo keyed-sha-1, mode strict Session up time 00:04:42 Local diagnostic None, remote diagnostic NbrSignal Remote state Up, version 1 Replicated Min async interval 0.300, min slow interval 1.000 Adaptive async TX interval 0.300, RX interval 0.300 Local min TX interval 0.300, minimum RX interval 0.300, multiplier 3 Remote min TX interval 0.300, min RX interval 0.300, multiplier 3 Local discriminator 2, remote discriminator 2 Echo mode disabled/inactive Authentication enabled/active, keychain bfd-bgp, algo keyed-sha-1, mode strict
Related Documentation
- ACX, M, PTX, QFX, T Series
- Understanding BFD Authentication for BGP
- ACX, M, MX, QFX, T Series
- Example: Configuring BFD for BGP
- EX, M, MX, PTX, SRX, T Series
- bfd-liveness-detection
- Additional Information
- authentication-key-chains statement in the Junos OS System Basics Configuration Guide
- show bfd session command in the Junos OS Operational Mode Commands
Published: 2012-12-08
Supported Platforms
Related Documentation
- ACX, M, PTX, QFX, T Series
- Understanding BFD Authentication for BGP
- ACX, M, MX, QFX, T Series
- Example: Configuring BFD for BGP
- EX, M, MX, PTX, SRX, T Series
- bfd-liveness-detection
- Additional Information
- authentication-key-chains statement in the Junos OS System Basics Configuration Guide
- show bfd session command in the Junos OS Operational Mode Commands