2-755
Catalyst 3750-X and 3560-X Switch Command Reference
OL-29704-01
Chapter 2 Catalyst 3750-X and 3560-X Switch Cisco IOS Commands
show mka summary
"Distributed CAK"..... 0
MKA Error Counter Totals
========================
Internal Failures................ 0
Session Failures
Failed while Initializing..... 6
Failed while Pending MACsec... 2
Reauthentication Failure...... 0
SAK Failures
SAK Generation................ 0
Hash Key Generation........... 0
SAK Encryption/Wrap........... 0
SAK Decryption/Unwrap......... 0
CA Failures
Group CAK Generation.......... 0
Group CAK Encryption/Wrap..... 0
Group CAK Decryption/Unwrap... 0
Pairwise CAK Derivation....... 0
CKN Derivation................ 0
ICK Derivation................ 0
KEK Derivation................ 0
MACsec Failures
Rx SC Creation................ 2
Tx SC Creation................ 2
Rx SA Installation............ 2
Tx SA Installation............ 0
MKPDU Failures
MKPDU Tx...................... 0
MKPDU Rx Validation........... 13
Bad Peer MN (anti-replay).. 0
Non-recent Peerlist MN..... 0
MKA Policy Summary...
Policy KS Delay Replay Window Conf Interfaces
Name Priority Protect Protect Size Offset Applied
===============================================================================
*DEFAULT POLICY* 0 NO YES 0 0 Gi1/0/26 Gi1/0/29
replay-policy 0 NO YES 300 0 Gi1/0/25
Incredible-59#sh mka policy replay-policy
MKA Policy Summary...
Policy KS Delay Replay Window Conf Interfaces
Name Priority Protect Protect Size Offset Applied
===============================================================================
replay-policy 0 NO YES 300 0 Gi1/0/25
Table 2-44 show mka summary Output Fields
Field Description
Reauthentications Reauthentications from 802.1x.
Pairwise CAKs Derived Pairwise secure connectivity association keys (CAKs) derived through EAP
authentication.
Pairwise CAK Rekeys Pairwise CAK rekeys after reauthentication.
Group CAKs Generated Generated group CAKs while acting as a key server in a group CA.
Group CAKs Received Received group CAKs while acting as a nonkey server member in a group
CA.
SAK Rekeys Secure association key (SAK) rekeys that have been initiated as key servers
or received as a non-key server members.
SAKs Generated Generated SAKs while acting as a key server in any CA.