Configuring MACsec
Although the MACsec configuration options outlined in this section are always visible,
they cannot be applied unless an active license is present on the device and MACsec
is enabled. MACsec licenses are required on a per-device basis. Each device in a stack
requires a separate MACsec license.
- Enter the dot1x-mka level from the global configuration level, and enable MACsec for the device.
- Configure the MACsec Key Agreement (MKA) group.
- Configure required parameters for the group, including frame validation, confidentiality, replay protection or delay protection, and actions to be taken when MACsec requirements are not met.
- Create and configure an MKA keychain.
- Enable MKA on each participating interface.
- Apply the configured MKA group on the participating interface.
Note: If an MKA group is not applied to an enabled MACsec interface, or if parameters within the applied group have not been configured, default values are applied to the interface. Configured parameters are visible in
showcommand output; default parameters are not always visible. Refer to the RUCKUS FastIron Command Reference Guide for default values for each command. - Apply the previously configured MKA keychain to the MACsec interface.Note: As an alternative, you can configure the Connectivity Association Key (CAK) and Connectivity Association Key Name (CKN) on each interface. However, pre-shared key configuration and MKA keychain configuration are not allowed on the same interface.