TCP AO configuration on Cisco, Juniper and Nokia SR - Interop Configuration
TCP-AO is a new authentication method proposed through RFC5925, The TCP Authentication Option to enhance the security and authenticity of TCP segments exchanged during BGP. It supports both IPv4 and IPv6 traffic Benefits of TCP-AO Support multiple stronger algorithms, such as HMAC-SHA1 and AES-128 to create an internal traffic key and message digest. Add a new user-configured key to re-generate internal traffic keys for an established connection and a mechanism to synchronize key change between BGP peers Nokia Configuration /configure system security keychain "aes-128-cmac-96-keychain" tcp-option-number send tcp-ao receive tcp-ao exit direction ...