mka-cfg-group

Creates and names a MACsec Key Agreement (MKA) configuration group.
Syntax
mka-cfg-group group-name
no mka-cfg-groupgroup-name
Command Default

No MACsec options are configured for an MKA configuration group. All related parameters retain their default settings.

Parameters
group-name
Provides a name for an MKA configuration group that can be applied to ports.
Modes

dot1x-mka configuration mode

dot1x-mka-interface configuration mode

Usage Guidelines

MACsec commands are supported only on ICX 7650 and ICX 7850 devices.

The no form of this command deletes the MKA configuration group. MACSec is disabled on the ports where the group is configured.

The dot1x-mka-enable command must be executed before the mka-cfg-group command can be used.

After the MACsec Key Agreement (MKA) configuration group is created, you can apply the configured group and its settings to an interface being configured using the mka-cfg-group command in the dot1x-mka-interface configuration mode.

Examples

The following example creates the MKA configuration group test1.


device(config)# dot1x-mka
  dot1x-mka-enable              Enable MACsec
device(config)# dot1x-mka-enable
device(config-dot1x-mka)#
device(config-dot1x-mka)# mka-cfg-group 
  ASCII string   Name for this group
device(config-dot1x-mka)# mka-cfg-group test1
device(config-dot1x-mka-group-test1)#

device(config-dot1x-mka-group-test1)# key-server-priority 
  DECIMAL   Priority of the Key Server. Valid values should be between 0 and 255
device(config-dot1x-mka-group-test1)# key-server-priority 5
device(config-dot1x-mka-group-test1)#

device(config-dot1x-mka-group-test1)# macsec cipher-suite 
  gcm-aes-128   GCM-AES-128 Cipher suite
device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128 
device(config-dot1x-mka-group-test1)#

device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 
  30   Confidentiality offset of 30
  50   Confidentiality offset of 50
device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 30
device(config-dot1x-mka-group-test1)#

device(config-dot1x-mka-group-test1)# macsec frame-validation 
  check     Validate frames with secTAG and accept frames without secTAG
  disable   Disable frame validation
  strict    Validate frames with secTAG and discard frames without secTAG
device(config-dot1x-mka-group-test1)# macsec frame-validation strict
device(config-dot1x-mka-group-test1)#

device(config-dot1x-mka-group-test1)# macsec replay-protection 
  out-of-order   Validate MACsec frames arrive in the given window size
  strict         Validate MACsec frames arrive in a sequence
device(config-dot1x-mka-group-test1)# macsec replay-protection strict 
device(config-dot1x-mka-group-test1)#

The following example applies the previously configured MKA group test1 to ethernet interface 1/3/3.

device(config)# dot1x-mka-enable
device(config-dot1x-mka)# enable-mka ethernet 1/3/3
device(config-dot1x-mka-1/3/3)# mka-cfg-group test1

History
Release version Command history
08.0.20 This command was introduced.
08.0.20a This command was expanded to support the association of a configured MKA group and its settings to an interface at the interface configuration level. The mka-group command was deprecated as part of this change.
08.0.30 Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.