Re: rfc2385 support

From: Lee Johnston (lee_at_wildcard.net.uk)
Date: 05/29/05

  • Next message: timt_at_sharktech.net: "Intel SRCS16"
    Date: Sun, 29 May 2005 12:50:21 +0100
    To: <Mathias@TeleCity.com>, <freebsd-net@freebsd.org>
    
    

    Hi Mathias,

    I've managed to get Quagga + FreeBSD 4.x/5.x to establish BGP sessions with
    Cisco routers with MD5 password authentication.

    You'll need to ensure you build Quagga with MD5 support (the current port
    gives you the option during build), compile your kernel with relevant
    TCP_SIGNATURE and crypto support (options vary depending on if your using
    4.x/5.x), use setkey, and add the usual neighbor x.x.x.x password yyyy to
    Quagga.

    Let me know if you need any more info/help..

    Regards,
    Lee.

    At 11:20 29/05/2005, Mathias@TeleCity.com wrote:

    >Hi guys,
    >
    >I'm trying to find out if any release of FreeBSD supports MD5 as per
    >rfc2385. I will be using it with quagga on BGP session authentication.
    >
    >Regards
    >Mathias,
    >
    >
    >______________________________________________________________________
    >DISCLAIMER
    >This e-mail is intended only for the use of the addressees named above and
    >may be confidential. If you are not an addressee you must not use any
    >information contained in nor copy it nor inform any person other than
    >TeleCity or the addressees of its existence or contents. If you have
    >received this e-mail in error, please contact the TeleCity IT department
    >on +44 (0) 161 232 3220 or by email at techsupport@telecity.com. Internet
    >communications cannot be guaranteed 100% secure, you should therefore take
    >this potential lack of security into consideration when emailing us as we
    >do not accept legal responsibility for the security of the contents of
    >this or other emails. Whilst TeleCity take measures to prevent any virus
    >contamination of our computer systems, recipients of emails should always
    >ensure that they take their own precautions to avoid virus contamination.
    >______________________________________________________________________
    >_______________________________________________
    >freebsd-net@freebsd.org mailing list
    >http://lists.freebsd.org/mailman/listinfo/freebsd-net
    >To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"

    --
    Lee @ Wildcard Internet
    t: (0845) 165 1510
    f: (0845) 165 1511
    m: (07795) 423 617
    e: lee@wildcard.net.uk
    Web Development - Domains - Hosting - Co-location - Dedicated Servers  
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: timt_at_sharktech.net: "Intel SRCS16"

    Relevant Pages

    • Re: quagga 0.99.8 on current, tcpmd5 config confusion
      ... i386 system running quagga. ... madly googled and found that i needed to hack kernel for tcp md5 ... I wasn't 100% happy about how I ended up doing the kernel support, and had to go with what I had working in my tree because of that old demon 'economics', rather than doing things 'the right way': i.e. in the IPSEC Security Policy Database, with the routing daemon loading the keys, rather than the Security Associations Database and keys loaded manually using setkey. ... I remember putting in the SADB lookup failed message to help people track down problems with their configuration. ...
      (freebsd-net)
    • Re: BGP: cant set sockopt TCP_MD5SIG 0 to socket 16
      ... Two router is a Core - each has different version of OS and Quagga ... BGP: can't set sockopt TCP_MD5SIG 0 to socket 16 ... I've already compile quagga with MD5 patch for BGP. ...
      (freebsd-current)
    • quagga 0.99.8 on current, tcpmd5 config confusion
      ... i386 system running quagga. ... slammed by bgp tcpmd5 requirement. ... madly googled and found that i needed to hack kernel for tcp md5 ...
      (freebsd-net)
    • Re: TCP-RST Vulnerability - Doubt
      ... >MD5 clears that problem right up and they're all using MD5 protection already ... MD5 protection on BGP sessions isn't very common yet. ... The "TTL hack" solution is safer. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • rfc2385 support
      ... I'm trying to find out if any release of FreeBSD supports MD5 as per ... I will be using it with quagga on BGP session authentication. ...
      (freebsd-net)