496
also removes the MKA policy application from the port. However, other parameter settings of the
MKA policy are effective on the port.
If the parameter value in interface view is the same as the value in the MKA policy, your configuration
does not take effect. The policy remains active on the port.
Configuring the MACsec confidentiality offset
The MACsec confidentiality offset specifies the number of bytes starting from the frame header.
MACsec encrypts only the bytes after the offset in a frame.
MACsec uses the confidentiality offset propagated by the key server.
To configure the MACsec confidentiality offset:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Configure the MACsec
confidentiality offset.
macsec confidentiality-offset
offset-value
The default setting is 0, and the
entire frame needs to be
encrypted.
The offset value can be 0, 30, or
50.
Configuring MACsec replay protection
The MACsec replay protection feature allows a MACsec port to accept a number of out-of-order or
repeated inbound frames. The configured replay protection window size is effective only when
MACsec replay protection is enabled.
To configure MACsec replay protection:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Enable MACsec replay
protection.
macsec replay-protection
enable
By default, MACsec replay
protection is enabled on the port.
4.
Configure the MACsec
replay protection window
size.
macsec replay-protection
window-size
size-value
The default setting is 0, and
frames are accepted only in the
correct order.
Configuring the MACsec validation mode
The MACsec validation allows a port to perform integrity check based on the following validation
modes:
•
check
—Performs validation only, and does not drop illegal frames.
•
strict
—Performs validation, and drops illegal frames.
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...