Configuring MACsec Integrity and Encryption
MACsec adds the ICV to the frame before transmission. The receiving device recalculates the ICV and checks it against the computed value that has been added to the frame. Because the ICV is computed on the entire Ethernet frame, any modifications to the frame can be easily recognized.
By default, both encryption and integrity protection are enabled.
MACsec encrypts traffic between devices at the MAC layer and decrypts frames within participating networked devices. AES-CMAC is used for handshake in the control plane, and AES-GCM is used for encryption or decryption in the data plane.
MACsec also encrypts the VLAN tag and the original Ethertype field in the Layer 2 header of the secured data. When initial bytes in a secure data packet must be transparent, a confidentiality offset of 30 or 50 bytes can be applied.
- At the dot1x-mka group
configuration level, enter the
macsec cipher-suitecommand with one of the available options. This configuration applies to both the dataplane and control plane for a pre-shared key-based MACsec session. Both planes utilize the bit size configured here for encryption and decryption. The dataplane employs GCM cipher, while the control plane uses CMAC cipher.- gcm-aes-128: Enables encryption and integrity checking using the GCM-AES-128 cipher suite.
- gcm-aes-128 integrity-only: Enables integrity checking without encryption.
- gcm-aes-256: Enables encryption and integrity checking using the GCM-AES-256 cipher suite.
- gcm-aes-256 integrity-only: Enables integrity checking without encryption.
In the following example, MACsec 128-bit encryption has been configured as a group test1 setting. By default, the ICV integrity check is also enabled, no matter which cipher suite you use.
device# configure terminal device(config)# dot1x-mka device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128
- Enter the
macsec confidentiality-offsetcommand if an encryption offset is required:In the following example, the encryption offset is defined as 30 bytes. The first 30 bytes of each data packet carried within the MACsec frame are transmitted without encryption.
device# configure terminal device(config)# dot1x-mka device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 30