ip authentication key-chain eigrp

To enable authentication for the Enhanced Interior Gateway Routing Protocol (EIGRP) packets and to specify the set of keys that can be used on an interface, use the ip authentication key-chain eigrp command. To prevent authentication, use the no form of this command.

ip authentication key-chain eigrp instance-tag name-of-chain

no ip authentication key-chain eigrp instance-tag name-of-chain

Syntax Description


Name of the EIGRP instance. The instance-tag can be any case-sensitive, alphanumeric string up to 20 characters.


Group of keys that are valid.

Command Default

No authentication is provided for EIGRP packets.

Command Modes

Interface configuration mode

Command History



This command was introduced.

Usage Guidelines

You must set the authentication mode using the ip authentication mode eigrp command in interface configuration mode. You must separately configure a key chain using the key-chain command to complete the authentication configuration for an interface.

This command requires the LAN Base Services license.


This example shows how to configure the interface to accept and send any key that belongs to the key-chain trees:

switch(config)# router eigrp 209
switch(config-router)# interface ethernet 1/2
switch(config-if)# no switchport
switch(config-if)# ip authentication key-chain eigrp 209 trees

Related Commands


ip authentication mode eigrp

Sets the authentication mode for EIGRP on an interface.


Creates a set of keys that can be used by an authentication method.

show ip eigrp interfaces

Displays information about EIGRP interfaces.