AdvancedPublished 2026-07-03
EIGRP Lab 7: Securing Adjacencies with MD5
Bundle lab
Harden EIGRP adjacencies with MD5 authentication between two iol-xe routers over a /30 transit, then validate that only trusted peers form neighbors. You will configure a key chain, bind it to the transit interface, and enable EIGRP (AS 100) to exchange two user LANs. Verification includes neighbor state, key chain presence, and end-to-end host reachability.
Learning objectives
- Configure classic EIGRP with a consistent AS (100) and no auto-summary
- Define and apply an MD5 key chain to protect an EIGRP adjacency
- Verify authenticated adjacencies with IOS show commands
- Diagnose adjacency failure from AS, key, or interface participation mismatches
Troubleshooting focus
- If the neighbor never forms, confirm both routers share the same EIGRP AS (100) and matching K-values (defaults).
- Verify the transit interface participates in EIGRP via a precise network statement and that the interface is up/up.
- Check MD5 authentication on both sides: the key chain name, key-id, and key-string must match; ensure the interface has both 'mode md5' and the key-chain applied.
- Inspect for mismatched wildcard masks that accidentally omit the transit from EIGRP.
- Validate reachability with host pings; if routing looks right but pings fail, recheck host default gateways and masks.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.