Articles

ISSUES OF ENSURING RIPv2 PROTECTION ON NETWORK DEVICES

Download PDF Article on eLIBRARY.RU

Abstract

The article examines the security issues of RIPv2 routing protocol operation on network devices and focuses on attacks based on route metric spoofing. The relevance of the study is determined by the fact that RIPv2 is still used in educational, corporate and specialized network segments, while its distance-vector logic makes route selection dependent on the advertised hop count. The paper considers an attacker who has access to a common Layer 2 segment and uses Scapy to generate forged RIPv2 packets with artificially reduced metrics. The methodological basis of the research includes analysis of RIP/RIPv2 specifications, vendor documentation and laboratory modelling on Cisco, MikroTik and Eltex equipment. The experimental part compares three operating modes: RIPv2 without authentication, RIPv2 with a plain-text password and RIPv2 with MD5 cryptographic authentication according to RFC 2082. The results show that the absence of authentication and the use of a readable password do not prevent false route injection, because an attacker can reproduce valid-looking updates and influence routing tables. MD5 authentication rejects unauthorised updates and significantly reduces the risk of traffic interception or loss of connectivity, although its effectiveness depends on key secrecy and equipment support. Practical recommendations are proposed for safer RIPv2 deployment, including key-chain management, route filtering, isolation of RIP segments and regular auditing of routing tables and logs.

Online viewer

References

  1. Уймин, А. Г. Применение отечественного сетевого оборудования Eltex и EcoRouter в рамках специальности 09.02.06 «Сетевое и системное администрирование». Вопросы импортозамещения и подготовки квалифицированных кадров в сетевом оборудовании / А. Г. Уймин, И. М. Толмачев // Автоматизация и информатизация ТЭК. – 2025. – № 11(628). – С. 58–62. – EDN DMHQJU.
  2. Convery, D. Network Security Architectures [Электронный ресурс] / D. Convery, J. Choe // Cisco Press. – 2004. – URL: https://www.ciscopress.com/articles/article.asp?p=102157 (дата обращения: 25.11.2025).
  3. Perlman, R. Interconnections: Bridges, Routers, Switches, and Internetworking Protocols / R. Perlman. – 2nd ed. – Reading, Mass. : Addison-Wesley, 2000. – 538 p.
  4. Vyncke, E. LAN Switch Security: What Hackers Know About Your Switches / E. Vyncke. – Indianapolis, IN : Cisco Press, 2008. – 336 p.
  5. Baker, F. RFC 2082: RIP-2 MD5 Authentication / F. Baker, R. Atkinson. – Internet Engineering Task Force, 1997. – URL: https://datatracker.ietf.org/doc/html/rfc2082 (дата обращения: 25.11.2025).
  6. Malkin, G. RFC 2453: RIP Version 2 / G. Malkin. – Internet Engineering Task Force, 1998. – URL: https://datatracker.ietf.org/doc/html/rfc2453 (дата обращения: 25.11.2025).
  7. Красноперов, К. Ю. Отличия между протоколами RIPv1 и RIPv2 / К. Ю. Красноперов // Академическая публицистика. – 2023. – № 10-2. – С. 88–90. – EDN BXFIGT.

License

Copyright (c) 2025 D. G. Galustyan , S. A. Sokolov (Authors)

Keywords