macsec replay-protection

Specifies the action to be taken when packets are received out of order, based on their packet number. If replay protection is configured, you can specify the window size within which out-of-order packets are allowed.
Syntax
macsec replay-protection { strict | out-of-order window-size size } [ disable ]
no macsec replay-protection { strict | out-of-order window-size size } [ disable ]
Command Default

Macsec replay protection is enabled in Strict mode by default (no out-of-order packets are allowed).

Parameters
strict
Does not allow out-of-order packets.
out-of-order window-size
Allows out-of-order packets within a specific window size.
size
Specifies the allowable window within which an out-of-order packet can be received. Allowable range is from 0 through 2147483648.
disable
Disables replay protection.
Modes

dot1x-mka-cfg-group mode

Usage Guidelines

MACsec commands are supported only on ICX 7550, ICX 7650, and ICX 7850 devices.

By default, "macsec replay-protection strict" is enabled under any mka-cfg-group; however, the default configuration is not visible in show running-config or show dot1x-mka config command output.

The no form of the command followed by the configured parameters disables MACsec replay protection. The alternative on all supported platforms is to use the macsec replay-protection disable command.

MACsec replay protection must not be enabled when MACsec delay protection is enabled.

Examples

The following example configures group test1 to accept packets in exact sequence only.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1 
device(config-dot1x-mka-group-test1)# macsec replay-protection strict 
device(config-dot1x-mka-group-test1)#

The following example configures group test1 to accept out-of-order MACsec frames within a window size of 2000.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1 
device(config-dot1x-mka-group-test1)# macsec replay-protection out-of-order window-size 2000 
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 The disable option for the macsec replay-protection command was introduced. Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.