Displaying MACsec Configuration Details
- In privileged EXEC, global configuration, or dot1x-mka interface mode, use the
show dot1x-mka configcommand to display MACsec configuration details for the device.In the following example, MACsec parameters are displayed for the device and all groups configured on it. Specific MACsec interfaces are displayed as well as the pre-shared key for each interface.
Note: The pre-shared key is displayed as an encrypted value, not in plain text.device(config)# show dot1x-mka config dot1x-mka-enable mka-cfg-group group1 key-server-priority 20 macsec frame-validation check macsec confidentiality-offset 0 macsec cipher-suite gcm-aes-128 macsec-replay protection out-of-order window-size 100 enable-mka ethernet 1/3/2 mka-cfg-group group1 pre-shared-key xxxxxxxxxxxxxxxxxxxxxxxx key-name 96437a93ccf10d9dfe3478460cce5132 enable-mka ethernet 1/3/6 mka-cfg-group group1 pre-shared-key xxxxxxxxxxxxxxxxxxxxxxxx key-name 96437a93ccf10d9dfe3478460cce51321
- In privileged EXEC, global configuration, or dot1x-mka interface mode, enter the
show dot1x-mka config-groupcommand to display information for all configured groups. Add a group name to the command to narrow the information displayed to one group. - In privileged EXEC, global
configuration, or dot1x-mka interface mode, use the
show keychain mkacommand to display details for configured MACsec keychains. For additional details on a specific keychain, use theshow keychain namecommand.The following example shows that one MKA keychain named "sample" has been configured.
device# show keychain mka Keychain : sample Tolerance : 0 ---------------------------------------------------------------------------- Key-id | Algo | SendActive | SendTimer | AcceptActive | AcceptTimer ---------------------------------------------------------------------------- 100 aes-128-cmac Yes(GMT+00) - No(GMT+00) -
The following example uses the
show keychain namecommand followed by the keychain name displayed in the previous example to display additional details for the specified keychain.device# show keychain name sample Keychain: sample Tolerance: 0 Key-id : 100 AuthAlgorithm: aes-128-cmac Key-String : ******* Send Lifetime:- Start : 02-16-2022 04:05:00 End : Infinite Active : Yes TimeToExpire: Infinite Timezone : GMT+00