Configuring MACsec Integrity and Encryption
MACsec adds the ICV to the frame before transmission. The receiving device recalculates the ICV and checks it against the computed value that has been added to the frame. Because the ICV is computed on the entire Ethernet frame, any modifications to the frame can be easily recognized.
By default, both encryption and integrity protection are enabled.
MACsec encrypts traffic between devices at the MAC layer and decrypts frames within participating networked devices. MACsec uses the Galois/Counter Mode Advanced Encryption Standard 128 or 256 (GCM-AES-128 or GCM-AES 256) cipher suite to encrypt data and to compute the ICV for each transmitted and received MACsec frame.
MACsec also encrypts the VLAN tag and the original Ethertype field in the Layer 2 header of the secured data. When initial bytes in a secure data packet must be transparent, a confidentiality offset of 30 or 50 bytes can be applied.
- At the dot1x-mka group configuration level, enter the
macsec cipher-suitecommand with one of the available options:- gcm-aes-128: Enables encryption and integrity checking using the GCM-AES-128 cipher suite.
- gcm-aes-128 integrity-only: Enables integrity checking without encryption.
- gcm-aes-256: Enables encryption
and integrity checking using the GCM-AES-256 cipher suite.
Note: The gcm-aes-256 option is not supported on ICX 7450 devices.
- gcm-aes-256 integrity-only: Enables integrity checking without encryption.
In the following example, MACsec 128-bit encryption has been configured as a group test1 setting. By default, the ICV integrity check is also enabled, no matter which cipher suite you use.
device# configure terminal device(config)# dot1x-mka device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128
- Enter the
macsec confidentiality-offsetcommand if an encryption offset is required:In the following example, the encryption offset is defined as 30 bytes. The first 30 bytes of each data packet carried within the MACsec frame are transmitted without encryption.
device# configure terminal device(config)# dot1x-mka device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 30