KEK Derivation................... 0
Invalid Peer MACsec Capability... 0
MACsec Failures
Rx SA Installation............... 12
Tx SA Installation............... 0
This example shows how to display the MKA summary:
switch# show macsec mka summary
Interface Status Cipher Key-Server MACSEC-policy CKN
Keychain
-------------- -------- ---------------- ------------ --------------
---------------------------------------------------------------- ---------
Ethernet11/25 Secured GCM-AES-XPN-128 No p1
0100000000000000000000000000000000000000000000000000000000000000 k1
Ethernet11/31 Secured GCM-AES-XPN-128 Yes p1
0300000000000000000000000000000000000000000000000000000000000000 k3
Related Commands
DescriptionCommand
Configures the cipher suite for encrypting traffic with
MACsec.
cipher suite
Configures the confidentiality offset for MKA
encryption.
conf-offset
Enables the MKA feature.feature mka
Creates a key or enters the configuration mode of an
existing key.
key
Creates a keychain or enters the configuration mode
of an existing keychain.
key chain keychain-name
Configures the text for a MACsec key.key-octet-string
Configures the preference for a device to serve as the
key server for MKA encryption.
key-server-priority
Configures the MACsec keychain policy.macsec keychain policy
Configures the MACsec policy.macsec policy
Sets an expiry time for a force SAK rekey.
sak-expiry-time time
Displays the configuration of the specified keychain.show key chain
Displays all the MACsec policies in the system.show macsec policy
Displays the status of MKA.show run mka
Cisco Nexus 7000 Series Security Command Reference
841
Show Commands
show macsec mka