Configuring Macsec Protection Parameters In Interface View; Configuring The Macsec Confidentiality Offset - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

In client-oriented mode, the access device port automatically becomes the key server. You do not
have to configure the MKA key server priority.
In device-oriented mode, the port that has higher priority becomes the key server. If a port and its
peers have the same priority, MACsec compares the secure channel identifier (SCI) values on the
ports. The port with the lowest SCI value (a combination of MAC address and port ID) becomes the
key server.
A port with priority 255 cannot become the key server. For a successful key server selection, make
sure a minimum of one participant's key server priority is not 255.
To configure the MKA key server priority:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure
server priority.
Configuring MACsec protection parameters in
interface view
If you configure a parameter in interface view after applying an MKA policy, the configuration in
interface view overwrites the configuration of the parameter in the MKA policy. Your configuration
also removes the MKA policy application from the port. However, other parameter settings of the
MKA policy are effective on the port.
If the parameter value in interface view is the same as the value in the MKA policy, your configuration
does not take effect. The policy remains active on the port.

Configuring the MACsec confidentiality offset

The MACsec confidentiality offset specifies the number of bytes starting from the frame header.
MACsec encrypts only the bytes after the offset in a frame.
MACsec uses the confidentiality offset propagated by the key server.
To configure the MACsec confidentiality offset:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure
confidentiality offset.
Command
system-view
interface
interface-number
the
MKA
key
mka priority priority-value
Command
system-view
interface
interface-number
the
MACsec
macsec
offset-value
interface-type
interface-type
confidentiality-offset
467
Remarks
N/A
N/A
The default setting is 0.
Remarks
N/A
N/A
The default setting is 0, and the
entire
frame
needs
encrypted.
The offset value can be 0, 30, or
50.
to
be

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents