Configuring MACsec Key-Server Priority
The key-server is elected by comparing key-server priority values during MACsec Key Agreement (MKA) message exchange between peer devices. The elected key-server is the peer with the lowest configured key-server priority, or with the lowest Secure Channel Identifier (SCI) in case of a tie. Key-server priority may be set to a value from 0 through 255. When no priority is configured, the device defaults to a priority of 16, which is not displayed in MACsec configuration details.
Refer to Configuring MACsec for an overview of enabling and configuring MACsec features.
- At the dot1x-mka group configuration level, enter the
key-server-prioritycommand, and specify a value from 0 through 255 to define the key-server priority.device# configure terminal device(config)# dot1x-mka-enable device(config-dot1x-mka)# mka-cfg-group test1 device(config-dot1x-mka-group-test1)# key-server-priority 20
In this example, the key-server priority is set to 20 for the MKA group test1.
Next: Configure MACsec integrity and encryption for the group.