ETExamTower
Q5Layer 3 Technologies

Which protocol must use MD-5 authentication across the MPLS cloud to stop hackers from adding bogus routers?

← → navigate · a answer
Community votes
C
75% (3)
D
25% (1)
A
0% (0)
B
0% (0)
Discussion · 5
C 8
Selected Answer: C The Label Distribution Protocol (LDP) can also be secured with MD-5 authentication across the MPLS cloud. That stops hackers from adding bogus routers, which would take part in the LDP. https://www.cisco.com/c/en/us/td/docs/net_mgmt/vpn_solutions_center/2-0/mpls/provisioning/guide/PGmpls1.html
5
I changed my mind after reading on the cisco site that refers exactly to this question: All routing protocols should be configured with the corresponding authentication option toward the CEs and toward any Internet connection. Specifically: BGP, OSPF, and RIP2. All peering relationships in the network need to be secured this way: •CE-PE link: use BGP MD-5 authentication •PE-P link: use LDP MD5 authentication •P-P This prevents attackers from spoofing a peer router and inserting bogus routing information. Secure management is particularly important regarding configuration files, which often contain shared secrets in clear text (for example for routing protocol authentication). LDP Authentication: The Label Distribution Protocol (LDP) can also be secured with MD-5 authentication across the MPLS cloud. This prevents hackers from introducing bogus routers, which would participate in the LDP. So, the answer is C .
D 2
Selected Answer: D The correct answer is D. Since the aim is to stop fake routers, i.e. hackers, from pretending to be the CE, I think you have to use BGP MD-5 authentication on the PE. LDP is used for protection between PE and P, which makes it harder for hackers to impersonate PE or P.
C 1
Selected Answer: C yes, the give anwser is correct
1
I also think the answer is D (MP-BGP)