685
Usage guidelines
The CAK can be either generated during 802.1X or manually configured at the CLI. The manually
configured CAK takes precedence over the 802.1X-generated key.
When 802.1X is not enabled on MACsec ports, you can execute this command to configure a
preshared key on each MACsec port. Make sure the local port and peer ports are configured with the
same key. If the connected ports are configured with different keys, they cannot successfully
establish MKA sessions.
To delete the configured keys for MKA sessions that have been established, perform the following
tasks:
1.
Execute the
undo mka psk
command on the key server.
2.
Execute the
undo mka psk
command on the non-key server.
The deletion operation deletes the established MKA sessions at the same time.
The MACsec cipher suite supported by the device requires that the configured CKN and CAK each
must be 32 characters long. If the configured CKN or CAK is not 32 characters long, the system
performs the following operations when it runs the cipher suite:
•
Automatically increases the length of the CKN or CAK by zero padding if the CKN or CAK
contains less than 32 characters.
•
Uses only the first 32 characters if the CKN or CAK contains more than 32 characters.
Examples
# Configure the CAK name as
AB
, and set the CAK to
1234
in plain text on Gigabit Ethernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] mka psk ckn AB cak simple 1234
replay-protection enable
Use
replay-protection enable
to enable MACsec replay protection in an MKA policy.
Use
undo replay-protection enable
to disable MACsec replay protection in an MKA policy.
Syntax
replay-protection enable
undo replay-protection enable
Default
MACsec replay protection is enabled in an MKA policy.
Views
MKA policy view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
This feature allows a MACsec port to accept a number of out-of-order or repeated inbound frames.
When an MKA policy is applied to a port, the replay protection configuration in the policy overwrites
the replay protection feature already used by the port.
Examples
# Enable MACsec replay protection in MKA policy
abcd
.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...