下面是某大學網絡配置安全的RIP協議的過程。安全
一、 將RouterA和RouterB 的相應接口設置爲被動端口。網絡
RouterA(config)#router ripide
RouterA(config-router)#version 2 //必定要開啓版本2模式才能得到加密認證功能。this
RouterA(config-router)#passive-interface FastEthernet 1/0加密
RouterA(config-router)#passive-interface FastEthernet 0/0spa
RouterA(config-router)#passive-interface FastEthernet 0/1orm
RouterB(config)#router riprouter
RouterB(config-router)#version 2blog
RouterB(config-router)#passive-interface FastEthernet 1/0接口
RouterB(config-router)#passive-interface FastEthernet 0/0
RouterB(config-router)#passive-interface FastEthernet 0/1
二、 將路由器A和B設置爲鄰居關係。
RouterA(config-router)#neighbor 172.17.1.1 //RouterB FA0/0接口的IP地址
RouterB(config-router)#neighbor 172.17..1.2 //RouterA FA0/0接口的IP地址
三、 根據時間配置密鑰鏈
RouterA(config-router)#key chain RouterA
RouterA(config-keychain)#key 1
RouterA(config-keychain-key)#key-string cisco
RouterA(config-keychain-key)#accept-lifetime 16:30:00 Nov 28 2004 duration 43200(持續43200秒)
RouterA(config-keychain-key)send-lifetime 16:30:00 Nov 28 2004 duration 43200
RouterA(config-keychain-key)#key 2
RouterA(config-keychain-key)#key-string love
RouterA(config-keychain-key)#accept-lifetime 04:00:00 Nov 29 2004 13:00:00 Apr 15 2005(到期時間)
RouterA(config-keychain-key)#send-lifetime 04:00:00 Nov 29 2004 13:00:00 Apr 15 2005
RouterA(config-keychain-key)#key 3
RouterA(config-keychain-key)#key-string yourcisco
RouterA(config-keychain-key)#accept-lifetime 12:30:00 Apr 15 2005 infinite (永遠)
RouterA(config-keychain-key)#send-lifetime 12:30:00 Apr 15 2005 infinite
RouterB(config)#key chain RouterB
RouterB(config-keychain)#key 1
RouterB(config-keychain-key)#key-string cisco
RouterB(config-keychain-key)#accept-lifetime 16:30:00 Nov 28 2004 duration 43200
RouterB(config-keychain-key)send-lifetime 16:30:00 Nov 28 2004 duration 43200
RouterB(config-keychain-key)#key 2
RouterB(config-keychain-key)#key-string love
RouterB(config-keychain-key)#accept-lifetime 04:00:00 Nov 29 2004 13:00:00 Apr 15 2005
RouterB(config-keychain-key)#send-lifetime 04:00:00 Nov 29 2004 13:00:00 Apr 15 2005
RouterB(config-keychain-key)#key 3
RouterB(config-keychain-key)#key-string yourcisco
RouterB(config-keychain-key)#accept-lifetime 12:30:00 Apr 15 2005 infinite
RouterB(config-keychain-key)#send-lifetime 12:30:00 Apr 15 2005 infinite
四、 將密鑰鏈應用到須要進行認證的網絡接口上。
RouterA(config)#int FastEthernet 0/0
RouterA(config-if)#ip rip authentication key-chain RouterA
RouterA(config)#int FastEthernet 0/1
RouterA(config-if)#ip rip authentication key-chain RouterA
RouterB(config)#int FastEthernet 0/0
RouterB(config-if)#ip rip authentication key-chain RouterB
RouterB(config)#int FastEthernet 0/1
RouterB(config-if)#ip rip authentication key-chain RouterB
五、 定義加密方式爲明文或者MD5加密,這裏使用MD5加密。
RouterA(config-if)#ip rip authentication mode md5
RouterB(config-if)#ip rip authentication mode md5