Configuring Ldp Md5 Authentication; Configuring An Lsp Generation Policy - HP 10500 Series Configuration Manual

Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

The LDP backoff mechanism can mitigate this problem by using an initial delay timer and a maximum
delay timer. After LDP fails to establish a session with a peer LSR for the first time, LDP does not start an
attempt until the initial delay timer expires. If the session setup fails again, LDP waits for two times the
initial delay before the next attempt, and so forth until the maximum delay time is reached. After that, the
maximum delay time will always take effect.
To configure LDP backoff:
Step
1.
Enter system view.
2.
Enter LDP view or enter
LDP-VPN instance view.
3.
Configure the initial delay
time and maximum delay
time.

Configuring LDP MD5 authentication

To improve security for LDP sessions, you can configure MD5 authentication for the underlying TCP
connections to check the integrity of LDP messages.
For two LDP peers to establish an LDP session successfully, make sure the LDP MD5 authentication
configurations on the LDP peers are consistent.
To configure LDP MD5 authentication:
Step
1.
Enter system view.
2.
Enter LDP view or enter
LDP-VPN instance view.
3.
Enable LDP MD5
authentication.

Configuring an LSP generation policy

An LSP generation policy controls the number of LSPs generated by LDP in one of the following ways:
Use all routes to establish LSPs.
Use the routes permitted by an IP prefix list to establish LSPs. For information about IP prefix list
configuration, see Layer 3—IP Routing Configuration Guide.
Command
system-view
Enter LDP view:
mpls ldp
Enter LDP-VPN instance view:
a.
mpls ldp
b.
vpn-instance
vpn-instance-name
backoff initial initial-time maximum
maximum-time
Command
system-view
Enter LDP view:
mpls ldp
Enter LDP-VPN instance view:
a.
mpls ldp
b.
vpn-instance vpn-instance-name
md5-authentication peer-lsr-id { cipher |
plain } password
67
Remarks
N/A
N/A
By default, the initial delay time is
15 seconds and the maximum
delay time is 120 seconds.
Remarks
N/A
N/A
By default, LDP MD5
authentication is disabled.

Advertisement

Table of Contents
loading

Table of Contents