Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
11-22
Cisco ASDM User Guide
OL-16647-01
Chapter 11 Configuring Dynamic And Static Routing
Dynamic Routing
Dead Interval—Specifies the interval, in seconds, in which no hello packets are received,
causing neighbors to declare a router down. Valid values range from 1 to 65535. The default
value of this field is four times the interval set by the Hello Interval field.
Modes
The following table shows the modes in which this feature is available:
RIP
RIP is a distance-vector routing protocol that uses hop count as the metric for path selection. When RIP
is enabled on an interface, the interface exchanges RIP broadcasts with neighboring devices to
dynamically learn about and advertise routes.
The security appliance support both RIP version 1 and RIP version 2. RIP version 1 does not send the
subnet mask with the routing update. RIP version 2 sends the subnet mask with the routing update and
supports variable-length subnet masks. Additionally, RIP version 2 supports neighbor authentication
when routing updates are exchanged. This authentication ensures that the security appliance receives
reliable routing information from a trusted source.
Limitations
RIP has the following limitations:
The security appliance cannot pass RIP updates between interfaces.
RIP Version 1 does not support variable-length subnet masks.
RIP has a maximum hop count of 15. A route with a hop count greater than 15 is considered
unreachable.
RIP convergence is relatively slow compared to other routing protocols.
You can only enable a single RIP process on the security appliance.
RIP Version 2 Notes
The following information applies to RIP Version 2 only:
If using neighbor authentication, the authentication key and key ID must be the same on all neighbor
devices that provide RIP version 2 updates to the interface.
With RIP version 2, the security appliance transmits and receives default route updates using the
multicast address 224.0.0.9. In passive mode, it receives route updates at that address.
When RIP version 2 is configured on an interface, the multicast address 224.0.0.9 is registered on
that interface. When a RIP version 2 configuration is removed from an interface, that multicast
address is unregistered.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——