show dot1x-mka config

Shows the MACsec Key Agreement (MKA) configuration for the device.
Syntax
show dot1x-mka config
Modes

User EXEC configuration mode

The show dot1x-mka config command displays the following information:

Output field Description

dot1x-mka-enable

MACsec is enabled on the device.

enable-mka ethernet device/slot/port

The ethernet interfaces specified are enabled for MACsec.

mka-cfg-group group-name

The configuration details that follow are for the named MACsec MKA group.

key-server-priority value

The key server priority for MACsec transmissions on the named group is set at this value.

macsec cipher-suite gcm-aes-128

or

macsec cipher-suite gcm-aes-128 integrity-only

MACsec encryptions between members of the group are encrypted.

or

ICV checking only is performed, but no encryption is performed.

macsec confidentiality-offset value

The byte offset used for encrypted data is set to the value shown. Allowable values are 0, 30 (the first 30 bytes of data are not encrypted), and 50 (the first 50 bytes of data are not encrypted).

macsec frame-validation { check | discard }

For transmissions between MKA group members, indicates whether the MACsec frame header is checked and what action is taken for invalid frames (counted or discarded).

macsec-replay protection { strict | out-of-order window-size value }

Replay protection is enabled. The type of protection is shown as strict (discard any frame received out of sequence) or as allowing receipt of out-of-sequence frames within the specified window.

key value name value

The pre-shared key is set to this value and name for the MKA configuration group. Both key and name are hexadecimal strings.

enable ethernet device/slot/port

mka-cfg-group name

key hexadecimal value name hexadecimal value

The specified interface is enabled for MACsec. The interface belongs to the named MKA group, and the interface uses the pre-shared key shown to confirm peers with which it can communicate.

Examples

The following example displays MACsec configuration information for a device with MACsec enabled. Two MKA groups, test1 and group1, are configured. Interfaces with either group of parameters applied could form secure channels because the groups have the same pre-shared key.

device(config-dot1x-mka-1/3/2)# show dot1x-mka config

dot1x-mka-enable
 mka-cfg-group test1
  key-server-priority 5
  macsec cipher-suite gcm-aes-128 integrity-only
  macsec confidentiality-offset 30
  macsec frame-validation strict
mka-cfg-group group1
  key-server-priority 20
  macsec cipher-suite gcm-aes-128 
  macsec confidentiality-offset 30
 enable-mka ethernet 1/3/2
  mka-group test1
  pre-shared-key 135bd758 b0ee5c11 c55ff6ab 19fdb199 key-name 96437a93 ccf10d9d fe347846 cce52c7d 
 enable-mka ethernet 1/3/3
  mka-group group1                                                
  pre-shared-key 135bd758 b0ee5c11 c55ff6ab 19fdb199 key-name 96437a93 ccf10d9d fe347846 cce52c7d 
 enable-mka ethernet 1/3/4
  mka-group group1
  pre-shared-key 135bd758 b0ee5c11 c55ff6ab 19fdb199 key-name 96437a93 ccf10d9d fe347846 cce52c7d
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.
09.0.10b This command was modified to add MKA keychain information.