enable-mka

Enables MACsec Key Agreement (MKA) to support MACSec licensing functionality on a specified interface, and changes the mode to dot1x-mka-interface mode to allow related parameters to be configured.
Syntax
enable-mka ethernet unit/slot/port
no enable-mka ethernet unit/slot/port
Command Default

MKA is not enabled on an interface.

Parameters
ethernet unit/slot/port
Specifies an Ethernet interface and the number of the device, the slot on the device, and the port on that slot.
Modes

dot1x-mka-interface mode

Usage Guidelines

When the no version of the command is executed, MACSec is removed from the port.

MACsec commands are supported on ICX 7550, ICX 7650, and ICX 7850 devices.

For a MACsec channel to be created between two ports, both ports and devices designated must have MACsec enabled and configured.

The enable-mka ethernet command enables MACSec licensing on the specified interface. If the command is not enabled, MACSec licensing functionality is not supported.

Examples

The following example enables MACsec on port 2, slot 3 of the first device in the stack.

device# configure terminal
device(config)# dot1x-mka-enable
device(config-dot1x-mka)# enable-mka ethernet 1/3/2
device(config-dot1x-mka-1/3/2)#

The following error message is displayed when the MACSec license is not purchased for the device.

device# configure terminal
device(config)# dot1x-mka-enable
device (config-dot1x-mka)# enable-mka ethernet 2/2/1
Error: No MACsec License available for the port 2/2/1. Cannot enable MACsec !!!
Error: MKA cannot be enabled on port 2/2/1
device(config-dot1x-mka)#
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.