498
Applying an MKA policy
MKA policy provides a centralized method to configure MACsec confidentiality offset, replay
protection, and validation mode. An MKA policy can be applied to a port or multiple ports. When you
apply an MKA policy to a port, follow these restrictions and guidelines:
•
The MACsec parameter settings configured in the MKA policy overwrite the MACsec
parameters previously configured on the port.
•
Any modifications to the MKA policy take effect immediately.
•
When you remove an MKA policy application from the port, the MACsec parameter settings on
the port restore to the default.
•
When you apply a nonexistent MKA policy to the port, the port automatically uses the default
MKA policy. If you create the policy, the policy will be automatically applied to the port.
To apply an MKA policy to a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Apply an MKA policy.
mka apply policy
policy-name
By default, no MKA policy is
applied to the port.
Displaying and maintaining MACsec
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display MACsec information on ports.
display macsec
[
interface
interface-type
interface-number
] [
verbose
]
Display MKA session information.
display mka session
[
interface
interface-type
interface-number
|
local-sci
sci-id
] [
verbose
]
Display MKA policy information.
display mka
{
default-policy
|
policy
[
name
policy-name
] }
Display MKA statistics on ports.
display mka statistics
[
interface
interface-type
interface-number
]
Reset MKA sessions on ports.
reset mka session
[
interface
interface-type
interface-number
]
Clear MKA statistics on ports.
reset mka statistics
[
interface
interface-type
interface-number
]
Device-oriented MACsec configuration example
Network requirements
As shown in
, Device A is the MACsec key server.
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...