Configuring MACsec over VXLAN

Complete the following steps to configure MACsec over VXLAN.

  1. Configure MACsec for a loopback interface (p2 in MACsec over VXLAN Packet Flow, where ports p1 and p2 are part of the same VLAN).
    1. Enable MACsec on the device.
      device(config)# dot1x-mka-enable
    2. Enable MACsec Key Agreement (MKA) to support the MACsec licensing functionality on a specific interface (loopback interface p2 in this case).
      device(config-dot1x-mka)# enable-mka ethernet 1/3/1
      device(config-dot1x-mka-1/3/1)# pre-shared-key abcdeabcdeabcdeabcde111111111111 key-name abc2
  2. Configure the VXLAN tunnel with cross-connect VNI mapping (port p3 is an untagged member of the extended VLAN).
    1. Configure a VXLAN gateway record.
      device# configure terminal
      device(config)# overlay-gateway gate1
    2. Set the VXLAN gateway type as a Layer 2 extension.
      device(config-overlay-gw-gate1)# type layer2-extension
    3. Specify the loopback interface with the IP address that will be used as the source IP address for VXLAN tunnels.
      device(config-overlay-gw-gate1)# ip interface loopback 1
      You must use a loopback interface, rather than an explicit IPv4 address, as the source address.
    4. Map the VLAN with an untagged member as the loopback interface (port p3) to the cross-connect VNI.
      device(config-overlay-gw-gate1)# map vlan 2 to vni 3 cross-connect
      The default VLAN (typically, VLAN 1) cannot be mapped to a VNI or extended over a VXLAN segment.
    5. Create a remote site (VXLAN tunnel) and configure the IP address for the site.
      device(config-overlay-gw-gate1)# site site1
      device(config-overlay-gw-gate1-site1)# ip address 67.67.67.1
    6. Extend the mapped VLAN to the remote site.
      device(config-overlay-gw-gate1-site1)# extend vlan add 2

    The following example configures overlay gateway gate1 and maps VLAN 2 to cross-connect VNI 3. A VXLAN tunnel is configured by creating a remote site (site1) and configuring its IP address (67.67.67.1) as the destination address. Finally, the VLAN (VLAN 2) is extended over the overlay gateway.

    device# configure terminal
    device(config)# overlay-gateway gate1
    device(config-overlay-gw-gate1)# type layer2-extension
    device(config-overlay-gw-gate1)# ip interface loopback 1
    device(config-overlay-gw-gate1)# map vlan 2 to vni 3 cross-connect
    device(config-overlay-gw-gate1)# site site1
    device(config-overlay-gw-gate1-site1)# ip address 67.67.67.1
    device(config-overlay-gw-gate1-site1)# extend vlan add 2
    device(config-overlay-gw-gate1-site1)# end