pre-shared-key

Configures the pre-shared MACsec key on the interface.
Syntax
pre-shared-keykey-idkey-namehex-string
no pre-shared-keykey-idkey-namehex-string
Command Default

No pre-shared MACsec key is configured on the interface.

Parameters
key-id
Specifies the 32 hexadecimal value used as the Connectivity Association Key (CAK).
key-namehex-string
Specifies the name for the CAK key. Use from 2 through 64 hexadecimal characters to define the key name. The name must be entered as a multiple of 8 bits.
Modes

dot1x-mka interface mode

Usage Guidelines

The no form of the command removes the pre-shared key from the interface.

MACsec commands are supported only on ICX 7650 and ICX 7850 devices.

The pre-shared key is required for communications between MACsec peers.

Examples

The following example configures MKA group test1 and assigns the MACsec pre-shared key with a name beginning with 96437a93 and with the value shown, to port 2, slot 3 on the first device in the stack.

device(config)#dot1x-mka-enable
device(config-dot1x-mka)# mka-cfg-group test1
device(config-dot1x-mka-group-test1)# key-server-priority 5
device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128
device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 30
device(config-dot1x-mka-group-test1)# exit
device(config-dot1x-mka)# enable-mka ethernet 1/3/2
device(config-dot1x-mka-1/3/2)# mka-group test1
device(config-dot1x-mka-1/3/2)# pre-shared-key 135bd758b0ee5c11c55ff6ab19fdb199 key-name 96437a93ccf10d9dfe347846cce52c7d
History
Release version Command history
08.0.20 This command was introduced.
08.0.30 Support for this command was added on ICX 7450 devices.
08.0.70 Support for this command was added on ICX 7650 devices.
08.0.90 Support for this command was added on ICX 7850 devices.