macsec replay-protection
Specifies the action to be taken when packets are received out of order, based on
their packet number. If replay protection is configured, you can specify the window
size within which out-of-order packets are allowed.
Syntax
macsec replay-protection
{strict
|out-of-order|window-sizesize}[disable] no macsec replay-protection
{strict|out-of-order
window-sizesize}[disable]Command Default
Macsec replay protection is enabled in Strict mode (no out-of-order packets are allowed).
Parameters
Modes
dot1x-mka-cfg-group mode
Usage Guidelines
This command is supported only on ICX 7450, ICX 7650, and ICX 7850 devices.
The
no form of the command disables macsec replay protection.
Examples
The following example configures group test1 to accept packets in exact sequence only.
device(config)# dot1x-mka-enable device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# macsec replay-protection strict device(config-dot1x-mka-group-test1)#
History