Configuring the Pre-shared Key

MACsec security is based on a pre-shared key, the Connectivity Association Key (CAK), which you define and name. Only MACsec-enabled interfaces that are configured with the same key can communicate over secure MACsec channels.

Note: Refer to Configuring MACsec for an overview of enabling and configuring MACsec features.

  1. At the dot1x-mka-interface configuration level, enter the pre-shared-key command followed by the key-id, the keyword key-name, and a hex string to define and name the pre-shared key.
    The requirements for the parameters are as follows:
    • key-id: Define the key ID value using 32 hexadecimal characters.
    • key-name hex string: Give the key a name using from 2 through 64 hexadecimal characters.

In the following example, the pre-shared key with the hex value beginning with "135bd758b" and the key name beginning with "96437a93" are applied to interface 1/3/2.

device# configure terminal
device(config)# dot1x-mka  
device (config-dot1x-mka)# enable-mka ethernet 1/3/2
device(config-dot1x-mka-1/3/2)# pre-shared-key 135bd758b0ee5c11c55ff6ab19fdb199 key-name 96437a93ccf10d9dfe347846cce52c7d

Enable and configure each MACsec interface. Configure the same pre-shared key (CAK) on the interfaces between which a secure channel can be established.