Configuring Ldp Md5 Authentication; Configuring Ldp Label Filtering - HP 12500 Series Configuration Manual

Mpls, routing switch series
Table of Contents

Advertisement

To do...
Enable loop detection
Set the maximum hop count
Set the maximum path vector
length
NOTE:
The loop detection modes configured on two LDP peers must be the same. Otherwise, the LDP session
cannot be established.
To implement loop detection in an MPLS domain, you must enable loop detection on every LSR in the
MPLS domain.
Configure loop detection before enabling LDP capability on any interface.
All loop detection configurations take effect for only the LSPs established after the configurations.
Changing the loop detection configurations does not affect existing LSPs. You can execute the reset mpls
ldp command in user view, so that the loop detection configurations also take effect for existing LSPs.
LDP loop detection may result in LSP update, which will generate redundant information and consume
many system resources. HP recommends configuring the routing protocol's loop detection mechanism.

Configuring LDP MD5 authentication

LDP sessions are established based on TCP connections. To improve the security of LDP sessions, you can
configure MD5 authentication for the underlying TCP connections, so that the TCP connections can be
established only if the peers have the same authentication password.
To configure LDP MD5 authentication:
To do...
Enter system view
Enter MPLS LDP view
Enable LDP MD5 authentication
and set the password
NOTE:
To establish an LDP session successfully between two LDP peers, make sure that the LDP MD5
authentication configurations on the LDP peers are consistent.

Configuring LDP label filtering

The LDP label filtering feature provides two mechanisms, label acceptance control for controlling which
labels will be accepted and label advertisement control for controlling which labels will be advertised. In
complicated MPLS network environments, LDP label filtering can be used to control which LSPs are to be
established dynamically and prevent devices from accepting and advertising excessive label bindings.
Use the command...
loop-detect
hops-count hop-number
path-vectors pv-number
Use the command...
system-view
mpls ldp
md5-password { cipher | plain }
peer-lsr-id password
17
Remarks
Required
Disabled by default
Optional
32 by default
Optional
32 by default
Remarks
Required
Disabled by default

Advertisement

Table of Contents
loading

Table of Contents