2-752
Catalyst 3750-X and 3560-X Switch Command Reference
OL-29704-01
Chapter 2 Catalyst 3750-X and 3560-X Switch Cisco IOS Commands
show mka statistics
"Distributed SAK"..... 0
"Distributed CAK"..... 0
MKPDUs Transmitted......... 597
"Distributed SAK"..... 32
"Distributed CAK"..... 0
MKA Error Counter Totals
========================
Bring-up Failures.................. 0
Reauthentication Failures.......... 0
SAK Failures
SAK Generation.................. 0
Hash Key Generation............. 0
SAK Encryption/Wrap............. 0
SAK Decryption/Unwrap........... 0
CA Failures
Group CAK Generation............ 0
Group CAK Encryption/Wrap....... 0
Group CAK Decryption/Unwrap..... 0
Pairwise CAK Derivation......... 0
CKN Derivation.................. 0
ICK Derivation.................. 0
KEK Derivation.................. 0
Invalid Peer MACsec Capability.. 2
MACsec Failures
Rx SC Creation................... 0
Tx SC Creation................... 0
Rx SA Installation............... 0
Tx SA Installation............... 0
MKPDU Failures
MKPDU Tx......................... 0
MKPDU Rx Validation.............. 0
MKPDU Rx Bad Peer MN............. 0
MKPDU Rx Non-recent Peerlist MN.. 0
Table 2-43 show mka Global Statistics Output Fields
Field Description
Reauthentications Reauthentications from 802.1x.
Pairwise CAKs Derived Pairwise secure connectivity association keys (CAKs) derived through EAP
authentication.
Pairwise CAK Rekeys Pairwise CAK rekeys after reauthentication.
Group CAKs Generated Generated group CAKs while acting as a key server in a group CA.
Group CAKs Received Received group CAKs while acting as a nonkey server member in a group
CA.
SAK Rekeys Secure association key (SAK) rekeys that have been initiated as key servers
or received as nonkey server members.
SAKs Generated Generated SAKs while acting as a key server in any CA.
SAKs Received Received SAKs while acting as a nonkey server member in any CA.