Learn how to protect your VRRP group from rogue routers and calculate failover timing.
A rogue router can join your VRRP group and try to become Master.
Authentication stops that: only routers with the right key can join.Types of Authentication
IOS supports two types: plaintext and MD5.
Plaintext sends the key in clear text, so anyone capturing the Advertisements can read it.
Always use MD5 in production.Configuring MD5
Configure MD5 authentication on R1:
R1# conf t Enter configuration commands, one per line. End with CNTL/Z. R1(config)# int g0/0 R1(config-if)# vrrp 1 authentication md5 key-string PINGMYNETWORK_SECRET R1(config-if)# endR1 now requires the key on every Advertisement.
R2 doesn't have the key yet, so it rejects R1's Advertisements.With mismatched keys, each router ignores the other and both end up as Master for the same VIP.
Configure the same key on R2:
R2# conf t Enter configuration commands, one per line. End with CNTL/Z. R2(config)# int g0/0 R2(config-if)# vrrp 1 authentication md5 key-string PINGMYNETWORK_SECRET R2(config-if)# endVerify on R1 with the usual command:
R1# show vrrp GigabitEthernet0/0 - Group 1 State is Master Virtual IP address is 192.168.10.3 Virtual MAC address is 0000.5e00.0101 Advertisement interval is 1.000 sec Preemption enabled Priority is 110 Authentication MD5, key-string Master Router is 192.168.10.1 (local), priority is 110 Master Advertisement interval is 1.000 sec Master Down interval is 3.570 secThe new Authentication MD5, key-string line confirms the group now requires the shared secret.
Answer the question below
What happens to an Advertisement whose authentication key does not match?
You secured the group.
Now see what happens when the Master fails: how fast does the group notice, and what happens next?40 % Complete: you’re making great progress
Ready to pass your CCNP exam?