由於驗證不相符錯誤,鄰近裝置和Cisco安全防火牆威脅防禦(FTD)之間會發生開放最短路徑優先(OSPF)鄰接失敗。OSPF會話會特別失敗,因為OSPF消息摘要演算法5(MD5)身份驗證不匹配。在故障排除期間,您必須驗證FTD中的OSPF MD5身份驗證金鑰是否與相鄰裝置上配置的金鑰匹配。
firepower# debug ip ospf adjacency
OSPF adjacency events debugging is on
OSPF: Send with youngest Key 1
OSPF: Send with youngest Key 1
OSPF: Rcv pkt from 10.X.X.9, OT-Zone2 : Mismatch Authentication type. Input packet specified type 2, we use type 0
OSPF: Rcv pkt from 10.X.X.1, OT-Zone : Mismatch Authentication type. Input packet specified type 2, we use type 0
OSPF: Rcv pkt from 10.X.X.9 : Mismatched Authentication key - ID 1
OSPF: Rcv pkt from 10.X.X.1 : Mismatched Authentication key - ID 1
OSPF: Send with youngest Key 1
OSPF: Rcv pkt from 10.X.X.9, OT-Zone2 : Mismatch Authentication type. Input packet specified type 2, we use type 0
OSPF: Send with youngest Key 1
OSPF: Rcv pkt from 10.X.X.9 : Mismatched Authentication key - ID 1
OSPF: Rcv pkt from 10.X.X.1, OT-Zone : Mismatch Authentication type. Input packet specified type 2, we use type 0u
OSPF: Rcv pkt from 10.X.X.1 : Mismatched Authentication key - ID 1
由防火牆管理中心(FMC)管理的Cisco Secure Firepower(所有版本)
通過MD5身份驗證的相鄰網路裝置OSPF連線
1. — 執行這些命令以顯示OSPF MD5身份驗證配置。此命令顯示應用於介面的OSPF MD5身份驗證設定。
firepower# more system:running-config | inc md5
2. — 使用前面的輸出比較FTD和相鄰裝置之間的MD5身份驗證金鑰配置。
3. — 導航到Devices > Device Management > Edit Device > Routing > OSPF > Interface > Authentication。更新MD5身份驗證金鑰以匹配相鄰端的配置,然後將策略部署到FTD。否則,請設定鄰近裝置,以便與FTD MD5相符。
附註:出於安全原因,OSPF MD5金鑰在Cisco平台上不可以明文形式檢索。本節所述的驗證方法顯示有效配置,但不以明文格式顯示實際金鑰值。
由於相鄰Cisco網路裝置和FTD介面配置之間的OSPF MD5身份驗證金鑰不匹配,OSPF鄰接失敗。雖然設計時無法以明文檢視金鑰,但對FTD的驗證確認有效的MD5配置,從而可識別並協調不匹配。
| 修訂 | 發佈日期 | 意見 |
|---|---|---|
1.0 |
11-Sep-2026
|
初始版本 |