macsec replay-protection

Specifies the action to be taken when packets are received out of order, based on their packet number. If replay protection is configured, you can specify the window size within which out-of-order packets are allowed.
Syntax
macsec replay-protection {strict |out-of-order|window-sizesize}[disable]
no macsec replay-protection {strict|out-of-order window-sizesize}[disable]
Command Default
Macsec replay protection is enabled in Strict mode (no out-of-order packets are allowed).
Parameters
strict
Does not allow out-of-order packets.
out-of-orderwindow-size
Allows out-of-order packets within a specific window size.
size
Specifies the allowable window within which an out-of-order packet can be received. Allowable range is from 0 through 2147483648.
disable
Available only for the ICX 7450. Disables replay protection.
Modes

dot1x-mka-cfg-group mode

Usage Guidelines

This command is supported only on ICX 7450, ICX 7650, and ICX 7850 devices.

The no form of the command disables macsec replay protection.

Examples

The following example configures group test1 to accept packets in exact sequence only.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1 
device(config-dot1x-mka-group-test1)# macsec replay-protection strict 
device(config-dot1x-mka-group-test1)#

The following example configures group test1 to accept out-of-order MACsec frames within a window size of 2000.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1 
device(config-dot1x-mka-group-test1)# macsec replay-protection out-of-order window-size 2000 
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 The disable option for the macsec replay-protection command was introduced. Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.