EasyManuals Logo

Cisco Catalyst 4500 Series Configuration Guide

Cisco Catalyst 4500 Series
1610 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #960 background imageLoading...
Page #960 background image
43-6
Software Configuration Guide—Release IOS XE 3.3.0SG and IOS 15.1(1)SG
OL-25340-01
Chapter 43 Configuring MACsec Encryption
Configuring MACsec and MKA
MKPDU Failures
MKPDU Tx......................... 0
MKPDU Rx Validation.............. 0
MKPDU Rx Bad Peer MN............. 0
MKPDU Rx Non-recent Peerlist MN.. 0
For description of the output fields, see the command reference for this release.
Configuring MACsec and MKA
• Default MACsec MKA Configuration, page 43-6
• Configuring an MKA Policy, page 43-6
• Configuring MACsec on an Interface, page 43-7
Default MACsec MKA Configuration
MACsec is disabled. No MKA policies are configured.
Configuring an MKA Policy
To create an MKA Protocol policy, perform this task. Note that MKA also requires that you enable
802.1X.
This example configures the MKA policy relay-policy:
Switch(config)# mka policy replay-policy
Switch(config-mka-policy)# replay-protection window-size 300
Switch(config-mka-policy)# end
Command Purpose
Step 1
configure terminal
Enters global configuration mode.
Step 2
mka policy policy-name
Identifies an MKA policy, and enter MKA policy configuration mode. The
maximum policy name length is 16 characters.
Step 3
replay-protection window-size
frames
Enables replay protection, and configure the window size in number of
frames. The range is from 0 to 4294967295. The default window size is 0.
Entering a window size of 0 is not the same as entering the no
replay-protection command. Configuring a window size of 0 uses replay
protection with a strict ordering of frames. Entering no replay-protection
turns off MACsec replay-protection.
Step 4
end
Returns to privileged EXEC mode.
Step 5
show mka policy
Verifies your entries.
Step 6
copy running-config startup-config
(Optional) Saves your entries in the configuration file.

Table of Contents

Other manuals for Cisco Catalyst 4500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 4500 Series and is the answer not in the manual?

Cisco Catalyst 4500 Series Specifications

General IconGeneral
SeriesCatalyst 4500 Series
CategorySwitch
Layer SupportLayer 2, Layer 3
Form FactorModular chassis
StackableNo
Chassis Slots3, 6, 7, 10
Power Supply OptionsAC, DC
RedundancyPower supply, Supervisor engine
Network ManagementCisco IOS Software CLI, SNMP, Cisco Prime Infrastructure
FeaturesSecurity, QoS
Port DensityUp to 384 ports per chassis
Security Features802.1X, ACLs, DHCP Snooping, Dynamic ARP Inspection, IP Source Guard
Supervisor Engine8-E

Related product manuals