681
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] macsec validation mode strict
Related commands
display macsec
mka apply policy
validation mode
mka apply policy
Use
mka apply policy
to apply an MKA policy to a port.
Use
undo mka apply policy
to remove the MKA policy from a port.
Syntax
mka apply policy
policy-name
undo mka apply policy
Default
No MKA policy is applied to the port.
Views
Ethernet interface view
Predefined user roles
network-admin
mdc-admin
Parameters
policy-name
: Specifies the name of an MKA policy, a case-sensitive string of 1 to 16 characters.
Usage guidelines
An MKA policy defines MACsec parameters, including confidentiality offset, validation mode, replay
protection, and replay protection window size.
When you apply an MKA policy to a port, the MACsec parameter settings in the policy overwrite the
MACsec parameters previously configured on the port. Any modifications to the MKA policy take
effect immediately.
When you remove the MKA policy from a port, the MACsec parameter settings on the port restore to
the default.
When you delete an MKA policy, ports that use the policy automatically use the system-defined MKA
policy
default-policy
.
When you apply a nonexistent MKA policy to a port, the port automatically uses the system-defined
MKA policy
default-policy
. After you create the specified policy, the policy will be automatically
applied to the port.
Examples
# Apply MKA policy
abcd
to GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] mka apply policy abcd
Related commands
confidentiality-offset
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...