Configuring Data-Delay Protection
Each MACsec peer uses the MACsec Key Agreement (MKA) Protocol Data Unit (MKPDU) to communicate the lowest acceptable packet number. When a peer receives MACsec data with a packet number value less than the lowest acceptable packet number, MACsec increments the Delay Packet counters.
By default, the data-delay protection feature is disabled. Configuring the
macsec delay-protection command under MKA group settings and
attaching the group to a MACsec interface enables the data-delay protection feature
on that interface.
- At the dot1x-mka group
configuration level, enter the
macsec delay-protectioncommand.In the following example, data-delay protection is enabled for group test1. Frames are protected when they are received with a delay of two seconds or less.