macsec delay-protection

MACsec data-delay protection allows MKA participants to ensure that the data frames protected by MACsec are not delayed by more than two seconds.
Syntax
macsec delay-protection
no macsec delay-protection
Command Default

By default, MACsec data-delay protection is not configured.

Modes

dot1x-mka group configuration mode

Usage Guidelines

The no form of the command disables the feature.

MACsec replay protection must not be enabled when data-delay protection is enabled.

Configuring the macsec delay-protection command under MKA group settings and attaching the group to a MACsec interface enables the data-delay protection feature on that interface.

Examples

The following example configures data-delay protection for group test1 and applies group test1 configuration to a MACsec-enabled interface. On the interface, frames are protected when they are received with a delay of two seconds or less. The keychain macsec1 is also applied to the interface.

device# configure terminal
device(config)# dot1x-mka
device(config-dot1x-mka)# mka-cfg-group test1
device(config-dot1x-mka-group-test1)# macsec delay-protection
device(config-dot1x-mka-group-test1)# macsec replay-protection disable
device(config-dot1x-mka-group-test1)# exit
device(config-dot1x-mka)# enable-mka ethernet 2/2/1
device(config-dot1x-mka-2/2/1)# mka-cfg-group test1
device(config-dot1x-mka-2/2/1)# mka-keychain macsec1
device(config-dot1x-mka-2/2/1)# end
device#
History
Release version Command history
09.0.10c This command was introduced.