Configuring MACsec Frame Validation

You can specify whether incoming frames are checked for MACsec (secTAG) headers and how invalid frames are handled.

Note: Refer to Configuring MACsec for an overview of enabling and configuring MACsec features.

  1. At the MKA group configuration level, enter the macsec frame-validation command, and select an option:
    • disable: Received frames are not checked for a MACsec header.
    • check: If frame validation fails, counters are incremented, but packets are accepted.
    • strict: If frame validation fails, packets are dropped, and counters are incremented.

In the following example, group test1 is configured to validate frames and discard invalid ones.

device# configure terminal
device(config)# dot1x-mka  
device(config-dot1x-mka)# mka-cfg-group test1
device(config-dot1x-mka-group-test1)# macsec frame-validation strict