Sample MACsec Configuration
The following example shows how to enable
MACsec, configure general parameters, enable and configure interfaces, and create
and assign
a keychain module to an interface. The keychain module must also be assigned to peer
interfaces.
device# configure terminal device(config)# dot1x-mka-enable device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# key-server-priority 5 device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128 device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 0 device(config-dot1x-mka-group-test1)# macsec frame-validation strict device(config-dot1x-mka-group-test1)# macsec replay-protection strict device(config-dot1x-mka-group-test1)# exit device(config-dot1x-mka)# exit device(config)# keychain macsec1 mka device(config-keychain-mka-macsec1)# key-id 1 device(config-keychain-mka-macsec1-key-1)# password ........ device(config-keychain-mka-macsec1-key-1)# authentication-algorithm aes-256-cmac device(config-keychain-mka-macsec1-key-1)# send-lifetime start 02-14-2022 01:01:01 end 03-14-2022 06:59:00 device(config-keychain-mka-macsec1-key-1)# end device# configure terminal device(config)# dot1x-mka device(config-dot1x-mka)# enable-mka ethernet 1/3/2 device(config-dot1x-mka-1/3/2)# mka-cfg-group test1 device(config-dot1x-mka-1/3/2)# mka-keychain macsec1 device(config-dot1x-mka-1/3/2)# end device#