@noIPv6 Btw, OSPFv3 offers the option to use IPsec within its own configuration to secure its own keys when OSPFAuthentication is enabled . We do not need to build external IPsec tรบnel.
@noIPv6 Because we can use IPsec to easily encrypt our OSPF keys within our OSPFv3 domains when I say the option is there I mean that is available for you to use it or not. The example I posted was to demonstrate that we have that option as well.
@noIPv6 Yeah, good catchโฆ I wanted to say that OSPFv3 (for ipv6) we can configure it with IPsec when we want to use OSPF Authentication between routers.
4. Other considerations to be secured are:
> Set as "Passive Interface" none OSPF interfaces / User interfaces and such.
> By enabling OSPF authentication we prevent rogue routers form full adjacency with ours.
>IPv6 uses IPsec for Auth, meaning the keys are encrypted already.
#PaloAlto Firewall commands can be long sometimes but there are some short ones really useful to always keep in mind.
Use: "Show routing route" - to check the routing table.
On the image shows some #OSPF routes I used for the lab.
#networkengineer#networksecurity#PCNSA
My favorite part of being a Network Engineer is when I tell and prove the rest of the teams that is not a network issue. #NetEng#networking#networksecurity