670
Table 102 Command output
Field
Description
Protect frames
Status of MACsec desire on the port:
•
Yes
.
•
No
.
If the port does not have an MKA principal actor, this field displays
N/A
.
Active MKA policy
MKA policy applied to the port.
This field displays
N/A
if the port is not enabled with MACsec desire.
This field is not available if the port is enabled with MACsec desire but is not
applied an MKA policy.
Replay protection
Status of replay protection on the port:
•
Enabled
.
•
Disabled
.
If the port is not enabled with MACsec desire, this field displays
N/A
.
Replay window size
Replay protection window size in number of frames.
This field displays
N/A
in the following situations:
•
The port is not enabled with MACsec desire.
•
The port is not enabled with replay protection.
Confidentiality offset
Confidentiality offset in bytes.
If the port is not enabled with MACsec desire, this field displays
N/A
.
Validation mode
Validation mode:
•
Check
.
•
Strict
.
If the port is not enabled with MACsec desire, this field displays
N/A
.
Included SCI
Whether the frame includes SCI tag:
•
Yes
.
•
No
.
If the port is not enabled with MACsec desire, this field displays
N/A
.
SCI conflict
Whether the SCI in the received MKA packets is the same as the local SCI:
•
Yes
—The SCI in the received MKA packets is the same as the local SCI.
•
No
—No MKA packet is received, or the SCI in the received MKA
packets is different from the local SCI.
Cipher suite
If the port is not enabled with MACsec desire, this field displays
N/A
.
Transmit secure channel
Information about the secure channel for outbound traffic.
This field is not available if the port is not enabled with MACsec desire.
Receive secure channel
Information about the secure channel for inbound traffic.
This field is not available if the port is not enabled with MACsec desire.
Elapsed time
Lifetime of the secure channel.
SCI
A hexadecimal string that contains the MAC address and port ID.
Current SA
Current SA used by the secure channel.
If no current SA is available, each of the AN, PN, and LPN fields for the
current SA displays
N/A
.
Previous SA
Previous SA used by the secure channel.
If no previous SA is available, each of the AN and LPN fields for the previous
SA displays
N/A
.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...