Cisco Catalyst 4500 Series Configuration Manual page 491

Ios software configuration guide isco ios xe 3.9.0e and ios 15.2(5)ex
Hide thumbs Also See for Catalyst 4500 Series:
Table of Contents

Advertisement

Chapter 2
mka policy
To configure MACsec Key Agreement policy options, and enter mka-policy configuration mode, use the
mka policy command.
Syntax Description
confideniality-offset
offset-value
default
key-server priority
priority
macsec-cipher-suite
Command Default
None.
Command Modes
Global Configuration
Command History
Release
Cisco IOS XE 3.9.0E This command was introduced on Cisco Catalyst 4500-E with Supervisor
Examples
The following example shows how to configure MKA policy options:
Switch(config)# mka policy policy1
Switch(config-mka-policy)# confidentiality-offset 0
Switch(config-mka-policy)# key-server priority 245
Switch(config-mka-policy)# gcm-aes-128
witch(config-mka-policy)# exit
mka policy policy name [confidentiality-offset| default | key-server priority priority |
macsec-cipher-suite {gcm-aes-128 | gcm-aes-256}]
Identifies a confidentiality (encryption) offset value for the MKA policy.
Valid values are 0, 30, and 50 octets (bytes).
Sets the policy to use the default confidentiality-offset, key-server priority
and cipher suite.
Sets the MKA key-server priority between 0 and 255. Note that 255 is not
used as the key-server.
Configures the cipher suite for SAK derivation.
Modification
Engine 8-E, and on Cisco Catalyst 4500-X series switches.
Catalyst 4500 Series Switch Cisco IOS Command Reference—Release XE 3.9.xE and 15.2(5)Ex
mka policy
2-451

Advertisement

Table of Contents
loading

Table of Contents