macsec replay-protection
macsec replay-protection
{
strict
|
out-of-order
window-size
size
}
[
disable
] no macsec replay-protection
{
strict
|
out-of-order
window-size
size
}
[
disable
]Macsec replay protection is enabled in Strict mode by default (no out-of-order packets are allowed).
dot1x-mka-cfg-group mode
MACsec commands are supported only on ICX 7550, ICX 7650, and ICX 7850 devices.
By default, "macsec replay-protection strict" is enabled under any mka-cfg-group;
however, the default configuration is not visible in show
running-config or show dot1x-mka config command
output.
The no form of the command
followed by the configured parameters disables MACsec replay protection. The
alternative on all supported platforms is to use the macsec replay-protection
disable command.
MACsec replay protection must not be enabled when MACsec delay protection is enabled.
The following example configures group test1 to accept packets in exact sequence only.
device(config)# dot1x-mka-enable device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# macsec replay-protection strict device(config-dot1x-mka-group-test1)#