EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #478 background imageLoading...
Page #478 background image
465
MACsec configuration task list
In device-oriented mode, the MACsec configuration takes effect on Layer 2 and Layer 3 Ethernet
ports. In client-oriented mode, the MACsec configuration takes effect only on 802.1X-enabled ports.
To configure MACsec, perform the following tasks:
Tasks at a glance
Remarks
(Required.)
Enabling MKA
N/A
(Optional.) Enabling MACsec desire
N/A
(Optional.) Configuring a preshared key
This task is required in
device-oriented mode.
(Optional.) Configuring the MKA key server priority N/A
(Optional.) Use one of the following methods to configure MACsec
protection parameters:
• Configuring MACsec protection parameters in interface view:
ï‚¡ Configuring the MACsec confidentiality offset
ï‚¡ Configuring MACsec replay protection
ï‚¡ Configuring the MACsec validation mode
• Configuring MACsec protection parameters by MKA policy:
ï‚¡ Configuring an MKA policy
ï‚¡ Applying an MKA policy
N/A
Enabling MKA
MKA establishes and manages MACsec secure channels on a port. It also negotiates keys used by
MACsec.
You cannot enable MKA on a MACsec-incapable port.
To enable MKA:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enter interface view.
interface
interface-type
interface-number
N/A
3. Enable MKA.
mka enable
By default, MKA is disabled on the
port.
Enabling MACsec desire
The MACsec desire feature expects MACsec protection for outbound frames. The key server
determines whether MACsec protects the outbound frames.
MACsec protects the outbound frames of a port when the following requirements are met:
• The key server is MACsec capable.
• Both the local participant and its peer are MACsec capable.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals