Configuring The Macsec Confidentiality Offset; Configuring Macsec Replay Protection; Configuring The Macsec Validation Mode - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

also removes the MKA policy application from the port. However, other parameter settings of the
MKA policy are effective on the port.
If the parameter value in interface view is the same as the value in the MKA policy, your configuration
does not take effect. The policy remains active on the port.

Configuring the MACsec confidentiality offset

The MACsec confidentiality offset specifies the number of bytes starting from the frame header.
MACsec encrypts only the bytes after the offset in a frame.
MACsec uses the confidentiality offset propagated by the key server.
To configure the MACsec confidentiality offset:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure the MACsec
confidentiality offset.

Configuring MACsec replay protection

The MACsec replay protection feature allows a MACsec port to accept a number of out-of-order or
repeated inbound frames. The configured replay protection window size is effective only when
MACsec replay protection is enabled.
To configure MACsec replay protection:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable MACsec replay
protection.
4.
Configure the MACsec
replay protection window
size.

Configuring the MACsec validation mode

The MACsec validation allows a port to perform integrity check based on the following validation
modes:
check—Performs validation only, and does not drop illegal frames.
strict—Performs validation, and drops illegal frames.
Command
system-view
interface interface-type
interface-number
macsec confidentiality-offset
offset-value
Command
system-view
interface interface-type
interface-number
macsec replay-protection
enable
macsec replay-protection
window-size size-value
496
Remarks
N/A
N/A
The default setting is 0, and the
entire frame needs to be
encrypted.
The offset value can be 0, 30, or
50.
Remarks
N/A
N/A
By default, MACsec replay
protection is enabled on the port.
The default setting is 0, and
frames are accepted only in the
correct order.

Advertisement

Table of Contents
loading

Table of Contents