28. macsec Commands

configure
macsec
— apply-groups reference
— apply-groups-exclude reference
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
cipher-suite keyword
clear-tag-mode keyword
delay-protection boolean
description string
encryption-offset number
macsec-encrypt boolean
replay-protection boolean
replay-window-size number
active-psk number
— apply-groups reference
— apply-groups-exclude reference
mka-hello-interval keyword
pre-shared-key number
— apply-groups reference
— apply-groups-exclude reference
cak string
cak-name string
encryption-type keyword
mac-policy number
— apply-groups reference
— apply-groups-exclude reference

28.1. macsec Command Descriptions

macsec

Synopsis

Enter the macsec context

Context
Tree
Introduced

16.0.R1

Platforms

All

connectivity-association [ca-name] string

Synopsis

Enter the connectivity-association list instance

Introduced

16.0.R1

Platforms

All

[ca-name] string

Synopsis

Connectivity association name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the connectivity association

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

cipher-suite keyword

Synopsis

Data path encryption algorithm

Default

gcm-aes-128

Options

gcm-aes-128, gcm-aes-256, gcm-aes-xpn-128, gcm-aes-xpn-256

Introduced

16.0.R1

Platforms

All

clear-tag-mode keyword

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Clear tag mode for clear text before the SecTAG

Default

none

Options

none, single-tag, dual-tag

Introduced

16.0.R1

Platforms

All

delay-protection boolean

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enable delay protection

Default

false

Introduced

20.10.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

encryption-offset number

Synopsis

Confidentiality (encryption) offset

Range

0 | 30 | 50

Default

0

Introduced

16.0.R1

Platforms

All

macsec-encrypt boolean

Synopsis

Encrypt and authenticate all PDUs

Default

true

Introduced

16.0.R1

Platforms

All

replay-protection boolean

Synopsis

Discard packet when not within the replay window size

Default

false

Introduced

16.0.R1

Platforms

All

replay-window-size number

Synopsis

Replay protection window size

Range

0 to 4294967294

Default

0

Introduced

16.0.R1

Platforms

All

static-cak

Synopsis

Enter the static-cak context

Introduced

16.0.R1

Platforms

All

active-psk number

Synopsis

Active pre-shared-key (PSK)

Range

1 to 2

Default

1

Introduced

16.0.R1

Platforms

All

mka-hello-interval keyword

Synopsis

MKA hello interval

Description

This command configures the interval at which MKA hello packets are sent or received for the connectivity association.

Default

2

Options

1, 2, 3, 4, 5, 6, 500ms

Introduced

19.5.R1

Platforms

All

mka-key-server-priority number

Synopsis

Key server priority used by the MKA protocol

Range

0 to 255

Default

16

Introduced

16.0.R1

Platforms

All

pre-shared-key [psk-id] number

Synopsis

Enter the pre-shared-key list instance

Max. Elements

2

Introduced

16.0.R1

Platforms

All

[psk-id] number

Synopsis

Pre-shared-key (PSK) ID

Range

1 to 2

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

cak string

Synopsis

Connectivity association key (CAK) for the PSK

Tree
String Length

1 to 71

Introduced

16.0.R1

Platforms

All

cak-name string

Synopsis

Connectivity Association Key (CAK) name for the PSK

Tree
String Length

1 to 64

Introduced

16.0.R1

Platforms

All

encryption-type keyword

Synopsis

Encryption for authentication of the MKA packet

Options

aes-128-cmac, aes-256-cmac

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

mac-policy [mac-policy-id] number

Synopsis

Enter the mac-policy list instance

Context
Introduced

16.0.R5

Platforms

All

[mac-policy-id] number

Synopsis

MAC address policy ID

Context
Notes

This element is part of a list key.

Introduced

16.0.R5

Platforms

All

destination-mac-address [dest-mac-addr] string

Synopsis

Add a list entry for destination-mac-address

Max. Elements

5

Introduced

16.0.R5

Platforms

All

[dest-mac-addr] string

Synopsis

Destination MAC address added to the MAC policy

Notes

This element is part of a list key.

Introduced

16.0.R5

Platforms

All