Skip to content

[BUG] BGP TCP-AO configuration on Cisco IOS XE #3196

@ipspace

Description

@ipspace

It looks like we need "include other TCP options in HMAC calculation" enabled for TCP-AO to work with other implementations (in particular, Arista EOS). However, that nerd knob seems to be configurable on BGP neighbors, not in the key chain. For Cisco IOS XE documentation:

The include-tcp-options and accept-ao-mismatch commands are not supported when configured under a key chain for BGP. To enable these options for a BGP neighbor or peer group, configure them directly using the neighbor <address | peer-group> ao [include-tcp-options] [accept-ao-mismatch] command in BGP configuration mode.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions