[SXP-8] Not able to Configure ISE sxp with default password. Created: 30/Mar/15  Updated: 17/Apr/15  Resolved: 17/Apr/15

Status: Resolved
Project: sxp
Component/s: General
Affects Version/s: unspecified
Fix Version/s: None

Type: Bug
Reporter: bhargav krishnamurthy Assignee: Maros Marsalek
Resolution: Done Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified
Environment:

Operating System: Linux
Platform: All


External issue ID: 2919

 Description   

Issue: Not able to configure ISE to do ether per peer password or default password.
Setup: Standalone ISE with NGWC, 3750,asa or 7k
Simple default password connection

Only Password = None is working rest all it give md5 authentication fail.



 Comments   
Comment by Maros Marsalek [ 13/Apr/15 ]

Proposed fix

https://git.opendaylight.org/gerrit/#/c/18194/

Needs to be verified with ISE and ASA.

Improper detection of connection with higher source IP address is not yet addressed.

Comment by Maros Marsalek [ 14/Apr/15 ]

Testing ISRG2 and ASA with proposed fix:

Setting same password in ODL and in remote device.

Result: connection is not established.

Reason: ISRG2/ASA send TCP SYN without MD5 signature/option -> Act as if no MD5 password was set.

This looks like SXP in ISRG2 and ASA (that I was able to test against) with password for MD5 does not behave as expected (at least during TCP handshake).

My configuration of ASA:

SXP : Enabled
Highest version : 2
Default password : Set
Default local IP : 10.32.251.167
Reconcile period : 120 secs
Retry open period : 120 secs
Retry open timer : Running
Total number of SXP connections: 1
Total number of SXP connections shown: 1
-----------------------------------------------------------
Peer IP : 10.24.234.253
Source IP : 10.32.251.167
Conn status : Off
Conn version : 2
Local mode : Speaker
Ins number : 1
TCP conn password : Default
Reconciliation timer : Not Running
Delete hold down timer : Not Running

Generated at Wed Feb 07 20:39:43 UTC 2024 using Jira 8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d.