mka-keychain

Applies a pre-defined MKA keychain to MACsec transmissions on a specific interface.
Syntax
mka-keychain { name }
no mka-keychain { name }
Command Default

By default, no MKA keychain is defined or applied.

Parameters
name
The name of the MKA keychain
Modes

dot1x-mka-interface configuration mode

Usage Guidelines

The no form of the command removes the MKA keychain from the interface and adminstratively brings the interface down.

An MKA keychain is allowed as part of interface configuration when a pre-shared key is not configured on the interface.

Use the keychain name mka command to define the keychain.

Use the show keychain mka command to display all configured keychains for MACsec.

MACsec must be configured and enabled globally before the interface configuration is enabled. Refer to the RUCKUS FastIron Security Configuration Guide.

Examples

The following example applies MKA-cfg-group 4 and MKA keychain "fi-msec" (both previously defined) to port 2/1/23.

device# configure terminal
device(config)# enable-mka ethernet 2/1/23
device(config-dot1x-mka-2/1/23)# mka-cfg-group 4
device(config-dot1x-mka-2/1/23)# mka-keychain fi-msec
device(config-dot1x-mka-2/1/23)# end
device#
History
Release version Command history
09.0.10b This command was introduced.