# How to Configure OSPF Plain Text Authentication

**URL:** https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940
**Category:** Lessons Discussion
**Created:** [December 24, 2016, 6:14pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940 "2016-12-24T18:14:19Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 24, 2016, 6:14pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/1 "2016-12-24T18:14:19Z")

</div>

This topic is to discuss the following lesson:

> **[OSPF Plain Text Authentication](https://networklessons.com/ospf/how-to-configure-ospf-plain-text-authentication)**
>
> OSPF can be configured for plain text or MD5 authentication. In this lesson, you will learn how to configure plain text authentication.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [April 12, 2013, 5:08pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/2 "2013-04-12T17:08:17Z")

</div>

If you run a Wireshark cap you can see the plain-text passphrase of MYPASS in one of the OSPF header packets

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [August 2, 2014, 12:22pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/3 "2014-08-02T12:22:19Z")

</div>

why you didn’t configure a password under area 0 authentication command?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [August 4, 2014, 3:16pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/4 "2014-08-04T15:16:41Z")

</div>

The password is configured on the interface, not under the OSPF process.

---

<div class="post-metadata">

### Author: ![chris.m.chavez](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/c/58f4c7/32.png) [@chris.m.chavez](https://forum.networklessons.com/u/chris.m.chavez)
#### Post date: [July 2, 2015, 10:41am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/5 "2015-07-02T10:41:12Z")

</div>

So you have to enter a authentication-key on every interface?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 2, 2015, 10:44am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/6 "2015-07-02T10:44:17Z")

</div>

Hi Chris,

That’s right, the key is always per interface.

Rene

---

<div class="post-metadata">

### Author: ![chris.m.chavez](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/c/58f4c7/32.png) [@chris.m.chavez](https://forum.networklessons.com/u/chris.m.chavez)
#### Post date: [July 2, 2015, 11:23am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/7 "2015-07-02T11:23:22Z")

</div>

Thanks for the quick response, great lesson again!

---

<div class="post-metadata">

### Author: ![sudeshalcatel](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/a4c791/32.png) [@sudeshalcatel](https://forum.networklessons.com/u/sudeshalcatel)
#### Post date: [June 17, 2016, 10:18am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/8 "2016-06-17T10:18:53Z")

</div>

Can we use either one for plain text authentication under interfaces or ospf process, Lets say we dont configure authentication under interfaces and configure authentication under area only then what should be the authentication credentials.

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [June 21, 2016, 9:45am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/9 "2016-06-21T09:45:51Z")

</div>

Hi Sudej,

If you enable authentication for the entire area then you still have to configure the password on the interface.

Rene

---

<div class="post-metadata">

### Author: ![florianl](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/f/b3f665/32.png) [@florianl](https://forum.networklessons.com/u/florianl)
#### Post date: [October 8, 2016, 2:16pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/10 "2016-10-08T14:16:10Z")

</div>

Hi Rene,

if we configure plain text authentication does that mean that the key is send with the hello packet and then compared to the key configured on the other routers interface, and if we use MD5 authentication that with the key a MD5 hash is created and on the other site the router tries to create the same hash value with its key, but the key itself is not send??

so with plain text key is send and with MD5 no key is send?

thanks

florian

---

<div class="post-metadata">

### Author: ![andrew](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/andrew/32/645_2.png) [@andrew](https://forum.networklessons.com/u/andrew)
#### Post date: [October 9, 2016, 8:54pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/11 "2016-10-09T20:54:52Z")

</div>

Florian,  
You are correct. Plain text = key sent, MD5 = hash sent.

---

<div class="post-metadata">

### Author: ![florianl](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/f/b3f665/32.png) [@florianl](https://forum.networklessons.com/u/florianl)
#### Post date: [October 11, 2016, 4:29pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/12 "2016-10-11T16:29:36Z")

</div>

Hi Andrew,

thanks for your reply!

Regards

Florian

---

<div class="post-metadata">

### Author: ![wilder7bc](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/wilder7bc/32/1187_2.png) [@wilder7bc](https://forum.networklessons.com/u/wilder7bc)
#### Post date: [September 20, 2017, 3:55pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/13 "2017-09-20T15:55:41Z")

</div>

HI Rene,

This seems like bad design by Cisco or ignorance on my part. Why enable authentication at the area to save work but still have to go into each interface to add the key?

I can only think they know something I don’t or they would have made it where you can do both at the global level.. anyway thanks for clarifying!

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [September 23, 2017, 8:31am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/14 "2017-09-23T08:31:48Z")

</div>

Hello Brian

The reason the key must be configured on the interface is because each link between two OSPF routers can have a different key. The keys are not global but are specific to the interfaces being connected.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![farazmultani](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/farazmultani/32/1245_2.png) [@farazmultani](https://forum.networklessons.com/u/farazmultani)
#### Post date: [October 4, 2018, 4:39pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/15 "2018-10-04T16:39:16Z")

</div>

There is very short theory concept about this topic, but practically very explained, you configured many few things on the router, i want to know this is completely configuration of ospf plain text authantiction in CCNP Ospf ?

---

<div class="post-metadata">

### Author: ![farazmultani](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/farazmultani/32/1245_2.png) [@farazmultani](https://forum.networklessons.com/u/farazmultani)
#### Post date: [October 5, 2018, 1:11pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/16 "2018-10-05T13:11:45Z")

</div>

please do reply , i m waiting for your valuable response.

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [October 11, 2018, 9:42am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/17 "2018-10-11T09:42:47Z")

</div>

Hello Faraz

Sorry for the late reply. Yes, this lesson covers everything that has to do with OSPF plain text authentication. There is nothing more concerning plain text authentication in the CCNP exam. The only other issues with authentication for OSPF has to do with [MD5 authentication](https://networklessons.com/ospf/how-to-configure-ospf-md5-authentication/), [SHA-HMAC authentication](https://networklessons.com/ospf/ospf-hmac-sha-extended-authentication/) and [TTL security check](https://networklessons.com/ospf/ospf-ttl-security-check/).

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![pradyumnayadavgla](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/p/f9ae1b/32.png) [@pradyumnayadavgla](https://forum.networklessons.com/u/pradyumnayadavgla)
#### Post date: [August 15, 2020, 10:25pm UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/18 "2020-08-15T22:25:34Z")

</div>

Hi Laz,

If we are configuring authentication area wise then is need to configure password if yes then where and how b/c it is not given in this post?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [August 18, 2020, 8:02am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/19 "2020-08-18T08:02:08Z")

</div>

Hello Pradyumna

The following command will enable authentication on all interfaces participating in Area 0 of the OSPF instance:

```
R1(config)#router ospf 1
R1(config-router)#area 0 authentication

```

This command simply replaces the `ip ospf authentication` command on the interfaces themselves. It does not replace the `ip ospf authentication-key` interface command. Even when you enable authentication on the whole area, **you still have to implement the password on each interface**.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![pradyumnayadavgla](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/p/f9ae1b/32.png) [@pradyumnayadavgla](https://forum.networklessons.com/u/pradyumnayadavgla)
#### Post date: [August 30, 2020, 8:31am UTC](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940/20 "2020-08-30T08:31:20Z")

</div>

Thanks Laz understood.

[Next page](https://forum.networklessons.com/t/how-to-configure-ospf-plain-text-authentication/940.md?page=2)
