macsec frame-validation

Enables validation checks for frames with MACsec headers and configures the validation mode (strict or not strict).
Syntax
macsec frame-validation{disable|check|strict}
no macsec frame-validation{disable|check|strict}
Command Default

MACsec frame validation is disabled (not visible in configuration).

Parameters
disable
Disables validation checks for frames with MACsec headers.
check
Enables validation checks for frames with MACsec headers and configures non-strict validation mode. If frame validation fails, counters are incremented but packets are accepted.
strict
Enables validation checks for frames with MACsec headers and configures strict validation mode. If frame validation fails, counters are incremented and packets are dropped.
Modes

dot1x-mka-cfg-group mode

Usage Guidelines

MACsec commands are supported only on ICX 7650 and ICX 7850 devices.

The no form of the restores the default (validation checks for frames with MACsec headers is disabled).

Examples

The following example enables validation checks for frames with MACsec headers on group test1 and configures strict validation mode.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1
device(config-dot1x-mka-group-test1)# macsec frame-validation strict
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.