Configuring Replay Protection

MACsec replay protection detects repeated or delayed packets and acts as a safeguard against man-in-the-middle attacks.

When replay protection is configured, MACsec uses a separate replay packet number (PN) counter and gives each Ethernet frame a packet number. As frames are received, packet numbers are monitored.

Two modes of replay protection are supported: strict and out-of-order. In strict mode (the default), packets must be received in the correct incremental sequence. In out-of-order mode, packets are allowed to arrive out of sequence within a defined window.

Note: Refer to Configuring MACsec for an overview of enabling and configuring MACsec features.

  1. At the dot1x-mka group configuration level, enter the macsec replay-protection command with one of the available modes:
    • strict: Frames must be received in exact incremental sequence.
    • out-of-order window size: Frames are accepted out of order within the designated window size. The maximum window size is 4294967295.
    • disable: Frames are not validated.

    Note: The disable option is a duplicate option available on ICX 7450 devices. The no macsec replay-protection command will also disable replay protection.

    In the following example, replay protection is enabled for group test1. Frames must be received in exact order.

    device# configure terminal
    device(config)# dot1x-mka  
    device(config-dot1x-mka)# mka-cfg-group test1
    device(config-dot1x-mka-group-test1)# macsec replay-protection strict
    

    In the following example, replay protection is enabled for group test1. Frames are accepted out of order within the designated window size (100).

    device# configure terminal
    device(config)# dot1x-mka  
    device(config-dot1x-mka)# mka-cfg-group test1
    device(config-dot1x-mka-group-test1)# macsec replay-protection out-of-order window-size 100
    

Once you have configured the desired MKA group settings, these settings can be applied to specific interfaces.