macsec confidentiality-offset

Configures the offset size for MACsec encryption.
Syntax
macsec confidentiality-offset size
no macsec confidentiality-offset size
Command Default

The default value for the MACsec encryption offset size is zero (0).

Parameters
size
Determines where encryption begins. Valid values are:
  • 30: Encryption begins at byte 31 of the data packet.
  • 50: Encryption begins at byte 51 of the data packet.
Modes

dot1x-mka-cfg-group mode

Usage Guidelines

MACsec commands are supported only on ICX 7650 and ICX 7850 devices.

The no form of the command disables encryption offset on all interfaces in the MACsec MKA group.

This command is only meaningful when encryption is enabled for the MACsec group using the macsec cipher-suite command.

Examples

The following example configures a 30-byte offset on encrypted transmissions as part of group test1 parameters.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1
device(config-dot1x-mka)# macsec cipher-suite gcm-aes-128
device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 30
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 Support for this command was added on the ICX 7450 device.
08.0.70 Support for this command was added on ICX 7650 devices. The command was also modified to add GCM-AES-256 encryption options.
08.0.90 Support for this command was added on ICX 7850 devices.