macsec cipher-suite

Enables GCM-AES-128 bit encryption or GCM-AES-256 bit integrity checks on MACsec frames transmitted between group members.
Syntax
macsec cipher-suite { gcm-aes-128 | gcm-aes-128 integrity-only | gcm-aes-256 | gcm-aes-256 integrity-only }
no macsec cipher-suite { gcm-aes-128 | gcm-aes-128 integrity-only | gcm-aes-256 | gcm-aes-256 integrity-only }
Command Default

GCM-AES encryption or integrity checking is not enabled. Frames are encrypted starting with the first byte of the data packet, and ICV checking is enabled.

Parameters
gcm-aes-128
Enables GCM-AES-128 bit encryption.
gcm-aes-128 integrity-only
Enables GCM-AES-128 bit integrity checks.
gcm-aes-256
Enables GCM-AES-128 bit encryption.
gcm-aes-256 integrity-only
Enables GCM-AES-128 bit integrity checks.
Modes

dot1x-mka-cfg-group mode

Usage Guidelines

The no form of the command restores the default encryption and integrity checking.

MACsec commands are supported only on ICX 7650 and ICX 7850 devices.

The macsec cipher-suite command can be used in conjunction with an encryption offset configured with the macsec confidentiality-offset command.

Examples

The following example enables GCM-AES-128 encryption on group test1.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1 
device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128 

The following example enables GCM-AES-128 bit integrity checking on test1.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1 
device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128 integrity-only 
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices. The command was also modified to add GCM-AES-256 encryption options.
08.0.90 Support for this command was added on ICX 7850 devices.