Macsec; Configure A Macsec Tunnel - Digi IX40 User Manual

Table of Contents

Advertisement

Virtual Private Networks (VPN)
>
3. To display details about a specific tunnel:
> show l2tpeth name /vpn/l2tpeth/test/session/test
test/session/test Tunnel Session Status
---------------------------------------
Enabled
Status
Local IP
Remote IP
Tunnel ID
Peer Tunnel ID
Session ID
Peer Session ID
Lifetime (Actual)
Device
RX Packets
RX Bytes
TX Packets
TX Byptes
>
4. Type exit to exit the Admin CLI.
Depending on your device configuration, you may be presented with an Access selection
menu. Type quit to disconnect from the device.

MACsec

MACsec (Media Access Control Security) is a 802.1ae (Layer2) VPN protocol that can be used to create
a secure MACsec tunnel over a wired Ethernet LAN. The MACsec uses keys to provide multiple
authentications between hosts in a network.
A MACsec tunnel must be tied to a physical interface. You cannot create a MACsec tunnel for a bridge.
Security modes
Two security modes are available for a MACsec tunnel.
n
Automatic: Uses a pre-shared key to generate association key information, which is
periodically rotated through using 802.1x.
Manual: Uses connectivity association key information that is manually entered in the CAK and
n
CKN fields.

Configure a MACsec tunnel

Your IX40 device supports MACsec (Layer 2 Tunneling Protocol).
IX40 User Guide
: true
: up
: 4.3.2.1
: 10.10.10.1
: modem
: 10.10.10.1 === 4.3.2.1
: 255
: 1476
: 600
: le_test_test
: 2,102
: 462
: 2,787
: 3,120
MACsec
499

Advertisement

Table of Contents
loading

Table of Contents