3.3.1.9 Set 'ip authentication mode eigrp'

Information

Configure authentication to prevent unapproved sources from introducing unauthorized or false routing messages.

Rationale:

This is part of the EIGRP authentication configuration

Solution

Configure the interface with the EIGRP authentication mode.


hostname(config)#interface {interface_name}
hostname(config-if)#ip authentication mode eigrp {<span>eigrp_as-number</span><span>}</span> md5

Impact:

Organizations should plan and implement enterprise security policies that require rigorous authentication methods for routing protocols. Configuring the interface with 'ip authentication mode' for EIGRP by number and mode enforces these policies by restricting the exchanges between network devices.

Default Value:

Not set







References:

http://www.cisco.com/en/US/docs/ios-xml/ios/interface/command/ir-i1.html#GUID-0D6BDFCD-3FBB-4D26-A274-C1221F8592DF

http://www.cisco.com/en/US/docs/ios-xml/ios/iproute_eigrp/command/ire-i1.html#GUID-8D1B0697-8E96-4D8A-BD20-536956D68506

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1), CSCv6|11

Plugin: Cisco

Control ID: bf611e0b633762d9fb8b8dabad832772d056fe6e838afa5835aa13d47adc0957