show macsec statistics

Displays status information and secure channel statistics for the designated MACsec interface.
Syntax
show macsec statistics ethernet device / slot / port
Parameters
device/slot/port
Interface for which MACsec status information is to be displayed. The interface is designated by device number in stack/slot on the device/interface on the slot.
brief
Specifies brief output for all MACsec interfaces.
Modes

User EXEC mode

Privileged EXEC mode

Global configuration mode

dot1x-mka configuration mode

dot1x-mka-interface configuration mode

Usage Guidelines

MACsec commands are supported only on ICX 7450, ICX 7650, and ICX 7850 devices.

It is recommended that you use the clear macsec command to clear previous results for the show macsec statistics command before re-executing it.

The show macsec statistics command displays the following information:

Output field Description
Interface (Device/slot/port) The information that follows describes the designated interface.
Replay Protection (Enabled, Disabled) Indicates whether replay protection is applied on the interface.
Replay Window (0 through 127) If out-of-order packets are allowed, indicates allowable window within which an out-of-order packet can be received.
Frame Validation (Enabled, Disabled) Indicates whether MACsec frame headers are checked.
Secure Channel Statistics: The fields that follow describe activity on a secure channel established over the designated interface.
TxPktProtectedOnly Number of transmitted packets with integrity protection only.
TxOctetProtectedOnly Number of bytes transmitted in packets with integrity protection only.
TxPktEncrypted Number of transmitted packets that are encrypted.
TxOctetEncrypted Number of bytes transmitted in encrypted packets.
TxPktMiss Number of transmitted packets that are neither encrypted nor protected by integrity check.
TxOctetMiss Number of bytes transmitted in packets that are neither encrypted nor protected by integrity checking.
TxPktDrop Number of packets dropped at transmission because SAK has been exhausted.
TxPktBad Number of transmitted packets marked as bad.
RxPktDecryptedAuth Number of packets received, decrypted, and checked for integrity protection.
RxOctetTotal Number of bytes received.
RxOctetAuthOnly Number of bytes received with Integrity protection only.
RxOctetDecrypted Number of bytes received and decrypted.
RxPktFailReplayCheck Number of packets received out of order.
RxPktFailICVCheck Number of packets received that failed Integrity checking.
RxPktNoMACsecTag Number of packets received without a MACSec Tag.
RxPktFrameValFail Number of packets received that failed MACsec frame validation.
RxPktMiss Number of packets received that did not find a key for decryption.
RxOctetMiss Number of bytes received that did not find a key for decryption.
RxPktDrop Number of received packets that were dropped.
Examples

The following example shows output for an ICX 7450 device.

device(config)# clear macsec ethernet 10/2/1
device(config)# show macsec statistics ethernet 10/2/1
device(config)#
Interface Statistics:
---------------------
rx Untag Pkts             : 1                   tx Untag Pkts             : 0                   
rx Notag Pkts             : 0                   tx TooLong Pkts           : 0                   
rx Badtag Pkts            : 0                   
rx Unknownsci Pkts        : 0                   
rx Nosci Pkts             : 0                   
rx Overrun Pkts           : 0                   

Transmit Secure Channels:
-------------------------

SA[0] Statistics:
Protected Pkts            : 0                   
Encrypted Pkts            : 2436337             

SA[1] Statistics:
Protected Pkts            : 0                   
Encrypted Pkts            : 0                   

SA[2] Statistics:
Protected Pkts            : 0                   
Encrypted Pkts            : 0                   

SA[3] Statistics:
Protected Pkts            : 0                   
Encrypted Pkts            : 0                   

SC Statistics:
Protected Octets          : 0                   Encrypted Octets          : 134830107           
Protected Pkts            : 0                   Encrypted Pkts            : 2436337             

Receive Secure Channels:
------------------------

SA[0] Statistics:
Ok Pkts                   : 1949642             Invalid Pkts              : 0                   
Not using SA Pkts         : 0                   Unused Pkts               : 0                   
Not Valid Pkts            : 0                   

SA[1] Statistics:
Ok Pkts                   : 0                   Invalid Pkts              : 0                   
Not using SA Pkts         : 0                   Unused Pkts               : 0                   
Not Valid Pkts            : 0                   

SA[2] Statistics:
Ok Pkts                   : 0                   Invalid Pkts              : 0                   
Not using SA Pkts         : 0                   Unused Pkts               : 0                   
Not Valid Pkts            : 0                   

SA[3] Statistics:
Ok Pkts                   : 0                   Invalid Pkts              : 0                   
Not using SA Pkts         : 0                   Unused Pkts               : 0                   
Not Valid Pkts            : 0                   

SC Statistics:
OkPkts                    : 1949642             Invalid Pkts              : 0                   
Not using SA Pkts         : 0                   Unused Pkts               : 0                   
Not Valid Pkts            : 0                   Unchecked Pkts            : 0                   
Delayed Pkts              : 0                   Late Pkts                 : 0                   
Valid Octets              : 0                   Decrypted Octets          : 97743896            
device(config)#  
History
Release version Command history
08.0.20 This command was introduced.
08.0.20a This command was modified. The show macsec command name was changed to show macsec statistics.
08.0.30 Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.