HPE FlexNetwork 7500 Series Security Configuration Manual page 501

Table of Contents

Advertisement

Verifying the configuration
# Display MACsec information on GigabitEthernet 1/0/1.
[Device] display macsec interface gigabitethernet 1/0/1 verbose
Interface GigabitEthernet1/0/1
Protect frames
Active MKA policy
Replay protection
Replay window size
Confidentiality offset : 30 bytes
Validation mode
Included SCI
SCI conflict
Cipher suite
Transmit secure channel:
SCI
Elapsed time: 00h:02m:07s
Current SA
Receive secure channels:
SCI
Elapsed time: 00h:02m:03s
Current SA
Previous SA : AN N/A
# Display MKA session information on GigabitEthernet 1/0/1 after a user logs in.
[Device] display mka session interface gigabitethernet 1/0/1 verbose
Interface GigabitEthernet1/0/1
Tx-SCI
: 00E00100000A0006
Priority
: 0
Capability: 3
CKN for participant: 1234
Key server
MI (MN)
Live peers
Potential peers
Principal actor
MKA session status
Confidentiality offset: 30 bytes
Current SAK status
Current SAK AN
Current SAK KI (KN)
Previous SAK status
Previous SAK AN
Previous SAK KI (KN)
Live peer list:
MI
B2CAF896C9BFE2ABFB135E63
: Yes
: pls
: Enabled
: 100 frames
: Strict
: No
: No
: GCM-AES-128
: 00E00100000A0006
: AN 0
PN 1
: 00E0020000000106
: AN 0
LPN 1
LPN N/A
: Yes
: A1E0D2897596817209CD2307 (2509)
: 1
: 0
: Yes
: Secured
: Rx & Tx
: 0
: A1E0D2897596817209CD230700000002 (2)
: N/A
: N/A
: N/A
MN
2512
Priority
Capability
0
3
487
Rx-SCI
00E0020000000106

Advertisement

Table of Contents
loading

Table of Contents