Displaying MACsec Secure Channel Activity for an Interface
You can display currently enforced MACsec capabilities for a specific interface, along
with secure channel statistics.
- In privileged EXEC mode, enter the
clear macsec statisticscommand for the designated interface. - In privileged EXEC, global configuration, or dot1x-mka interface mode, enter the
show macsec statisticscommand to display information on MACsec configuration and secure channel activity for a particular interface.The following
show macsec statisticscommand output is for an ICX 7450 device.device# clear macsec statistics ethernet 10/2/1 device# show macsec statistics ethernet 10/2/1 Interface Statistics: --------------------- rx Untag Pkts : 1 tx Untag Pkts : 0 rx Notag Pkts : 0 tx TooLong Pkts : 0 rx Badtag Pkts : 0 rx Unknownsci Pkts : 0 rx Nosci Pkts : 0 rx Overrun Pkts : 0 Transmit Secure Channels: ------------------------- SA[0] Statistics: Protected Pkts : 0 Encrypted Pkts : 4485 SA[1] Statistics: Protected Pkts : 0 Encrypted Pkts : 0 SA[2] Statistics: Protected Pkts : 0 Encrypted Pkts : 0 SA[3] Statistics: Protected Pkts : 0 Encrypted Pkts : 0 SC Statistics: Protected Octets : 0 Encrypted Octets : 250473 Protected Pkts : 0 Encrypted Pkts : 4485 Receive Secure Channels: ------------------------ SA[0] Statistics: Ok Pkts : 3094 Invalid Pkts : 0 Not using SA Pkts : 0 Unused Pkts : 0 Not Valid Pkts : 0 SA[1] Statistics: Ok Pkts : 0 Invalid Pkts : 0 Not using SA Pkts : 0 Unused Pkts : 0 Not Valid Pkts : 0 SA[2] Statistics: Ok Pkts : 0 Invalid Pkts : 0 Not using SA Pkts : 0 Unused Pkts : 0 Not Valid Pkts : 0 SA[3] Statistics: Ok Pkts : 0 Invalid Pkts : 0 Not using SA Pkts : 0 Unused Pkts : 0 Not Valid Pkts : 0 SC Statistics: OkPkts : 3094 Invalid Pkts : 0 Not using SA Pkts : 0 Unused Pkts : 0 Not Valid Pkts : 0 Unchecked Pkts : 0 Delayed Pkts : 0 Late Pkts : 0 Valid Octets : 0 Decrypted Octets : 157120