Configure OSPF as shown in Figure 5-3.
Configure simple authentication for all areas.
Tricky question for Area 3. The problem is you cannot configure Area 2 as a virtual link area.
The workaround is to configure a GRE tunnel between R3 and R5 and advertise it in Area 0. This way, you are extending Area 0 to R3, and Area 3 converges without configuring a virtual link.
This solution is very common when you have to address discontiguous Area 0s and you want to merge them:
! <snip from R5> interface Tunnel1 ip address 10.1.1.1 255.255.255.0 ip ospf authentication-key cisco tunnel source Serial1/1 tunnel destination 188.8.131.52 ! interface Serial1/0 ip address 184.108.40.206 255.255.255.128 encapsulation frame-relay ...