Glbp Authentication - Cisco Nexus 7000 Series Configuration Manual

Nx-os unicast routing configuration
Hide thumbs Also See for Nexus 7000 Series:
Table of Contents

Advertisement

Information About GLBP
S e n d d o c u m e n t c o m m e n t s t o n e x u s 7 k - d o c f e e d b a c k @ c i s c o . c o m .
Figure 18-1
Default gateway:
Gateway MAC:
If router A becomes unavailable, client 1 does not lose access to the WAN because router B assumes
responsibility for forwarding packets sent to the virtual MAC address of router A and for responding to
packets sent to its own virtual MAC address. Router B also assumes the role of the AVG for the entire
GLBP group. Communication for the GLBP members continues despite the failure of a router in the
GLBP group.

GLBP Authentication

GLBP has three authentication types:
MD5 authentication provides greater security than plain text authentication. MD5 authentication allows
each GLBP group member to use a secret key to generate a keyed MD5 hash that is part of the outgoing
packet. At the receiving end, a keyed hash of an incoming packet is generated. If the hash within the
incoming packet does not match the generated hash, the packet is ignored. The key for the MD5 hash
can either be given directly in the configuration using a key string or supplied indirectly through a key
chain.
You can also choose to use a simple password in plain text to authenticate GLBP packets, or choose no
authentication for GLBP.
GLBP rejects packets in any of the following cases:
Cisco Nexus 7000 Series NX-OS Unicast Routing Configuration Guide, Release 4.x
18-4
GLBP Topology
Virtual IP address 192.0.2.1
Virtual MAC 0007.b400.0101
Client 1
Virtual IP address 192.0.2.1
Virtual MAC 0007.b400.0101
MD5 authentication
Plain text authentication
No authentication
The authentication schemes differ on the router and in the incoming packet.
MD5 digests differ on the router and in the incoming packet.
Text authentication strings differ on the router and in the incoming packet.
WAN Link1
Router A
AVG 1
AVF 1.1
Virtual IP address 192.0.2.1
Virtual MAC 0007.b400.0102
Chapter 18
Configuring GLBP
WAN Link2
Router B
AVF 1.2
Virtual MAC 0007.b400.0102
AVG = active virtual gateway
AVF = active virtual forwarder
Client 2
OL-20002-02

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents