Step
2.
Enter interface view.
3.
Apply an MKA policy.
Enabling MKA session logging
Overview
This feature enables the device to generate logs for MKA session changes, such as peer aging and
SAK updates. The logs are sent to the information center of the device. For the logs to be output
correctly, you must also configure the information center on the device. For more information about
information center configuration, see Network Management and Monitoring Configuration Guide.
Configuration restrictions and guidelines
As a best practice, disable this feature to prevent excessive MKA session log output.
Configuration procedure
To enable MKA session logging:
Step
1.
Enter system view.
2.
Enable MKA session logging.
Displaying and maintaining MACsec
Execute display commands in any view and reset commands in user view.
Task
Display MACsec information on ports.
Display MKA session information.
Display MKA policy information.
Display MKA statistics on ports.
Reset MKA sessions on ports.
Clear MKA statistics on ports.
Command
interface interface-type
interface-number
mka apply policy policy-name
Command
system-view
macsec mka-session log
enable
Command
display macsec [ interface interface-type
interface-number ] [ verbose ]
display mka session [ interface interface-type
interface-number | local-sci sci-id ] [ verbose ]
display mka { default-policy | policy [ name
policy-name ] }
display mka statistics [ interface interface-type
interface-number ]
reset mka session [ interface interface-type
interface-number ]
reset mka statistics [ interface interface-type
interface-number ]
576
Remarks
N/A
By default, no MKA policy is
applied to the port.
Remarks
N/A
By default, MKA session logging
is disabled.