684
Parameters
priority-value
: Specifies the priority value, in the range of 0 to 255. The priority is inversely related to
its value.
Usage guidelines
If you use 802.1 X-generated CAK, the access device port automatically becomes the key server.
If you use a preshared key as the CAK, the port that has higher priority (lower priority value)
becomes the key server. If the port and its peers have the same priority, MACsec compares the SCI
values on the ports. The port with the lowest SCI value becomes the key server.
A port with priority 255 cannot become the key server. For a successful key server selection, make
sure a minimum of one participant's key server priority is not 255.
Examples
# Set the MKA key server priority to 2 on GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] mka priority 2
Related commands
display mka session
mka psk
Use
mka psk
to set a preshared key as the CAK.
Use
undo mka psk
to restore the default.
Syntax
mka psk ckn name cak
{
cipher
|
simple
}
string
undo mka psk
Default
No preshared key exists.
Views
Ethernet interface view
Predefined user roles
network-admin
mdc-admin
Parameters
ckn name
: Specifies the preshared key name, a hexadecimal string with an even number of
case-insensitive characters. The name length is in the range of 2 to 64 characters.
cak
: Specifies the preshared key.
cipher
: Specifies the preshared key in encrypted form.
simple
: Specifies the preshared key in plaintext form. For security purposes, the preshared key
specified in plaintext form will be stored in encrypted form.
string
: Specifies the preshared key. The plaintext form of the key is a hexadecimal string with an
even number of case-insensitive characters, and the key length is in the range of 2 to 64 characters.
The encrypted form of the key is a case-sensitive string of 2 to 117 characters.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...