Enabling and Configuring Group Interfaces for MACsec

After MACsec is enabled for the device, each MACsec interface must be individually enabled, and a configured set of parameters must be applied.
  1. To enable MACsec, at the dot1x-mka configuration level, enter the enable-mka command, and specify the interface as unit/slot/port.

    In the following example, Ethernet port 1 on slot 2 of unit 2 is enabled for MACsec security.

    device# configure terminal
    device(config)# dot1x-mka 
    device(config-dot1x-mka)# enable-mka ethernet 2/2/1
    device(config-dot1x-mka-2/2/1)#

    Note: The following output is displayed if there is no MACsec license present on the device.
    device(config-dot1x-mka)# enable-mka ethernet 2/2/1
    Error: No MACsec License available for the port 2/2/1. Cannot enable MACsec !!!
    Error: MKA cannot be enabled on port 2/2/1
    

  2. At the dot1x-mka interface configuration level, enter the mka-cfg-group command, and specify the MKA group configuration to apply to the interface.
    device(config-dot1x-mka-2/2/1)# mka-cfg-group test1
    
  3. This step is an option to configuring the pre-shared key as described later. At the dot1x-mka interface configuration level, enter the mka-keychain command, and specify the previously configured keychain to apply to the interface.
    device(config-dot1x-mka-2/2/1)# mka-keychain macsec1

In the following example, MACsec options configured for "group test1" and MKA keychain "macsec1" are applied to the enabled interface.

device# configure terminal
device(config)# dot1x-mka  
device (config-dot1x-mka)# enable-mka ethernet 2/2/1
device(config-dot1x-mka-2/2/1)# mka-cfg-group test1
device(config-dot1x-mka-2/2/1)# mka-keychain macsec1
device(config-dot1x-mka-2/2/1)# end
device#