EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #481 background imageLoading...
Page #481 background image
468
Configuring MACsec replay protection
The MACsec replay protection feature allows a MACsec port to accept a number of out-of-order or
repeated inbound frames. The configured replay protection window size is effective only when
MACsec replay protection is enabled.
To configure MACsec replay protection:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enter interface view.
interface
interface-type
interface-number
N/A
3.
Enable MACsec replay
protection.
macsec replay-protection
enable
By default,
MACsec replay
protection is enabled on the port.
4. Set the MACsec replay
protection window size.
macsec replay-protection
window-size
size-value
The default setting is 0, and
frames are accepted only in the
correct order.
Configuring the MACsec validation mode
The MACsec validation allows a port to perform integrity check based on the following validation
modes:
• check—Performs validation only, and does not drop illegal frames.
• disabled—Does not perform validation.
• strict—Performs validation, and drops illegal frames.
In the current software version, only the strict mode is supported.
To configure the MACsec validation mode:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enter interface view.
interface
interface-type
interface-number
N/A
3.
Configure the MACsec
validation mode.
macsec validation mode
{
check
|
disabled
|
strict
}
In the current software version,
only the
strict
mode is supported.
Configuring MACsec protection parameters by
MKA policy
Configuring an MKA policy
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2.
Create an MKA policy, and
enter MKA policy view.
mka policy
policy-name
By default, an MKA policy named
default-policy
exists.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals