Configuring Data-Delay Protection

MACsec data-delay protection allows MKA participants to ensure that the data frames protected by MACsec are not delayed by more than two seconds.

Each MACsec peer uses the MACsec Key Agreement (MKA) Protocol Data Unit (MKPDU) to communicate the lowest acceptable packet number. When a peer receives MACsec data with a packet number value less than the lowest acceptable packet number, MACsec increments the Delay Packet counters.

By default, the data-delay protection feature is disabled. Configuring the macsec delay-protection command under MKA group settings and attaching the group to a MACsec interface enables the data-delay protection feature on that interface.

Note: MACsec replay protection must be disabled when MACsec data-delay protection is configured.

Note: Refer to Configuring MACsec for an overview of enabling and configuring MACsec features.

  1. At the dot1x-mka group configuration level, enter the macsec delay-protection command.
    In the following example, data-delay protection is enabled for group test1. Frames are protected when they are received with a delay of two seconds or less.
    device# configure terminal
    device(config)# dot1x-mka  
    device(config-dot1x-mka)# mka-cfg-group test1
    device(config-dot1x-mka)# macsec replay-protection disable
    device(config-dot1x-mka-group-test1)# macsec delay-protection
Once you have configured the desired MKA group settings, these settings can be applied to specific interfaces.