Sample MACsec Configuration

The following example shows how to enable MACsec, configure general parameters, enable and configure interfaces, and create and assign a keychain module to an interface. The keychain module must also be assigned to peer interfaces.

device# configure terminal
device(config)# dot1x-mka-enable

device(config-dot1x-mka)# mka-cfg-group test1
device(config-dot1x-mka-group-test1)# key-server-priority 5
device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128 
device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 0
device(config-dot1x-mka-group-test1)# macsec frame-validation strict
device(config-dot1x-mka-group-test1)# macsec replay-protection strict
device(config-dot1x-mka-group-test1)# exit
device(config-dot1x-mka)# exit

device(config)# keychain macsec1 mka
device(config-keychain-mka-macsec1)# key-id 1
device(config-keychain-mka-macsec1-key-1)# password ........
device(config-keychain-mka-macsec1-key-1)# authentication-algorithm aes-256-cmac
device(config-keychain-mka-macsec1-key-1)# send-lifetime start 02-14-2022 01:01:01 end 03-14-2022 06:59:00
device(config-keychain-mka-macsec1-key-1)# end

device# configure terminal
device(config)# dot1x-mka 
device(config-dot1x-mka)# enable-mka ethernet 1/3/2

device(config-dot1x-mka-1/3/2)# mka-cfg-group test1
device(config-dot1x-mka-1/3/2)# mka-keychain macsec1
device(config-dot1x-mka-1/3/2)# end
device#