Applying An Mka Policy; Displaying And Maintaining Macsec - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

Step
3.
(Optional.)
MACsec
offset.
4.
(Optional.)
MACsec replay protection.
5.
Configure
validation mode.

Applying an MKA policy

MKA policy provides a centralized method to configure MACsec confidentiality offset, replay
protection, and validation mode. An MKA policy can be applied to a port or multiple ports. When you
apply an MKA policy to a port, follow these restrictions and guidelines:
The MACsec parameter settings configured in the MKA policy overwrite the MACsec
parameters previously configured on the port.
Any modifications to the MKA policy take effect immediately.
When you remove an MKA policy application from the port, the MACsec parameter settings on
the port restore to the default.
When you apply a nonexistent MKA policy to the port, the port automatically uses the default
MKA policy. If you create the policy, the policy will be automatically applied to the port.
To apply an MKA policy to a port:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Apply an MKA policy.

Displaying and maintaining MACsec

Execute display commands in any view and reset commands in user view.
Command
Configure
the
macsec
confidentiality
offset-value
a. Enable MACsec replay
Configure
b. Set the replay protection
the
MACsec
validation
disabled | strict }
Command
system-view
interface
interface-number
mka apply policy policy-name
confidentiality-offset
protection:
replay-protection
enable
window
size:
replay-protection
window-size size-value
mode
{ check |
interface-type
469
Remarks
The settings for parameters in the
default policy are the same as the
default settings for the parameters
on a port.
You cannot delete or modify the
default MKA policy.
You can create multiple MKA
policies.
The default setting is 0.
MACsec uses the confidentiality
offset propagated by the key
server.
By
default,
MACsec
protection is enabled.
The default
replay protection
window size is 0. Frames are
accepted only in the correct order.
In the current software version,
only the strict mode is supported.
Remarks
N/A
N/A
By default, no MKA policy is
applied to the port.
replay

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents