See the first figure in VRRP Topology for the topology in this example. You can configure VRRP text authentication to authenticate VRRP packets. An advertisement packet will get discarded if the authentication key in the packet does not match with the locally configured value.
SEFOS# configure terminal SEFOS(config)# router vrrp SEFOS(config-vrrp)# interface vlan 2 SEFOS(config-vrrp-if)# vrrp 1 text-authentication text1 SEFOS(config-vrrp-if)# end
SEFOS# show vrrp interface vlan 2 detail vlan2 - vrID 1 --------------- State is Master Virtual IP address is 12.0.0.5 Virtual MAC address is 00:00:5e:00:01:01 Master router is 12.0.0.5 Associated IpAddresses : ---------------------- 12.0.0.5 12.0.0.6 Advertise time is 1 secs Current priority is 200 Configured priority is 200, may preempt Configured Authentication Authentication key is text1 Accept Mode Disabled
SEFOS# show vrrp interface vlan 2 detail vlan2 - vrID 1 --------------- State is Backup Virtual IP address is 12.0.0.5 Virtual MAC address is 00:00:5e:00:01:01 Master router is 12.0.0.5 Associated IpAddresses : ---------------------- 12.0.0.5 12.0.0.6 Advertise time is 1 secs Current priority is 150 Configured priority is 150, may preempt Configured Authentication Authentication key is text1 Accept Mode Disabled