Enter the macsec context
16.0.R1
All
Enter the connectivity-association list instance
16.0.R1
All
Connectivity association name
1 to 32
This element is part of a list key.
16.0.R1
All
Administrative state of the connectivity association
configure macsec connectivity-association string admin-state keyword
disable
enable, disable
16.0.R1
All
Data path encryption algorithm
configure macsec connectivity-association string cipher-suite keyword
gcm-aes-128
gcm-aes-128, gcm-aes-256, gcm-aes-xpn-128, gcm-aes-xpn-256
16.0.R1
All
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Clear tag mode for clear text before the SecTAG
configure macsec connectivity-association string clear-tag-mode keyword
none
none, single-tag, dual-tag
16.0.R1
All
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Enable delay protection
configure macsec connectivity-association string delay-protection boolean
false
20.10.R1
All
Text description
configure macsec connectivity-association string description string
1 to 80
16.0.R1
All
Confidentiality (encryption) offset
configure macsec connectivity-association string encryption-offset number
0 | 30 | 50
0
16.0.R1
All
Encrypt and authenticate all PDUs
configure macsec connectivity-association string macsec-encrypt boolean
true
16.0.R1
All
Discard packet when not within the replay window size
configure macsec connectivity-association string replay-protection boolean
false
16.0.R1
All
Replay protection window size
configure macsec connectivity-association string replay-window-size number
0 to 4294967294
0
16.0.R1
All
Enter the static-cak context
16.0.R1
All
Active pre-shared-key (PSK)
configure macsec connectivity-association string static-cak active-psk number
1 to 2
1
16.0.R1
All
MKA hello interval
configure macsec connectivity-association string static-cak mka-hello-interval keyword
This command configures the interval at which MKA hello packets are sent or received for the connectivity association.
2
1, 2, 3, 4, 5, 6, 500ms
19.5.R1
All
Key server priority used by the MKA protocol
configure macsec connectivity-association string static-cak mka-key-server-priority number
0 to 255
16
16.0.R1
All
Enter the pre-shared-key list instance
configure macsec connectivity-association string static-cak pre-shared-key number
2
16.0.R1
All
Pre-shared-key (PSK) ID
configure macsec connectivity-association string static-cak pre-shared-key number
1 to 2
This element is part of a list key.
16.0.R1
All
Connectivity association key (CAK) for the PSK
configure macsec connectivity-association string static-cak pre-shared-key number cak string
1 to 71
16.0.R1
All
Connectivity Association Key (CAK) name for the PSK
configure macsec connectivity-association string static-cak pre-shared-key number cak-name string
1 to 64
16.0.R1
All
Encryption for authentication of the MKA packet
configure macsec connectivity-association string static-cak pre-shared-key number encryption-type keyword
aes-128-cmac, aes-256-cmac
This element is mandatory.
16.0.R1
All
Enter the mac-policy list instance
configure macsec mac-policy number
16.0.R5
All
MAC address policy ID
configure macsec mac-policy number
This element is part of a list key.
16.0.R5
All
Add a list entry for destination-mac-address
configure macsec mac-policy number destination-mac-address string
5
16.0.R5
All
Destination MAC address added to the MAC policy
configure macsec mac-policy number destination-mac-address string
This element is part of a list key.
16.0.R5
All