EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #479 background imageLoading...
Page #479 background image
466
• A minimum of one participant is enabled with MACsec desire.
To enable MACsec desire:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enter interface view.
interface
interface-type
interface-number
N/A
3. Enable MACsec desire.
macsec desire
By default, the port
does not
expect MACsec protection for
outbound frames.
Configuring a preshared key
In device-oriented mode, configure a preshared key as the CAK to be used during MKA negotiation.
To successfully establish an MKA session between two devices, make sure the connected MACsec
ports are configured with the same preshared key.
A user-configured preshared key has higher priority than the 802.1X-generated CAK. To ensure a
successful MKA session establishment, do not configure a preshared key in client-oriented mode.
To configure a preshared key:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enter interface view.
interface
interface-type
interface-number
N/A
3. Configure a preshared key.
mka psk ckn
name
cak simple
value
By default, no MKA preshared key
exists on the port.
The MACsec c
ipher suite
supported by HPE devices
requires that the CKN and CAK
each must be 32 characters long.
If the configured CKN or CAK is
not 32 characters long
, the
system performs the following
operations when it runs the cipher
suite:
•
Automatically increases the
length of the CKN or CAK by
zero padding if the CKN or
CAK contains less than 32
characters.
•
Uses only the first 32
characters if the CKN or CAK
contains more than 32
characters.
Configuring the MKA key server priority
Configure an MKA key server priority for key server selection. The lower the priority value, the higher
the priority.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals