• Learn how to protect your VRRP group from rogue routers and calculate failover timing.

    A rogue router can join your VRRP group and try to become Master.
    Authentication stops that: only routers with the right key can join.

    Types of Authentication

    IOS supports two types: plaintext and MD5.
    Plaintext sends the key in clear text, so anyone capturing the Advertisements can read it.
    Always use MD5 in production.

    Configuring MD5

    Configure MD5 authentication on R1:

    R1# conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    R1(config)# int g0/0
    R1(config-if)# vrrp 1 authentication md5 key-string PINGMYNETWORK_SECRET
    R1(config-if)# end

    R1 now requires the key on every Advertisement.
    R2 doesn't have the key yet, so it rejects R1's Advertisements.

    With mismatched keys, each router ignores the other and both end up as Master for the same VIP.

    Configure the same key on R2:

    R2# conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    R2(config)# int g0/0
    R2(config-if)# vrrp 1 authentication md5 key-string PINGMYNETWORK_SECRET
    R2(config-if)# end

    Verify on R1 with the usual command:

    R1# show vrrp
    GigabitEthernet0/0 - Group 1
      State is Master
      Virtual IP address is 192.168.10.3
      Virtual MAC address is 0000.5e00.0101
      Advertisement interval is 1.000 sec
      Preemption enabled
      Priority is 110
      Authentication MD5, key-string
      Master Router is 192.168.10.1 (local), priority is 110
      Master Advertisement interval is 1.000 sec
      Master Down interval is 3.570 sec
    • The new Authentication MD5, key-string line confirms the group now requires the shared secret.

    Answer the question below

    What happens to an Advertisement whose authentication key does not match?