<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how configure Encryption with MACsec switch to switch without AC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962461#M7488</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, if using Manual Mode, would I still need to setup trustsec credentials on the switch or is that something only used with 802.1x authentication? Sorry, I'm new to this! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jul 2012 23:23:18 GMT</pubDate>
    <dc:creator>michael.lorincz</dc:creator>
    <dc:date>2012-07-17T23:23:18Z</dc:date>
    <item>
      <title>how configure Encryption with MACsec switch to switch without ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962455#M7482</link>
      <description>&lt;P&gt;to whom it may concern:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem, i would like todo MACSEC betwwen two switches cisco catalyst 3560-x but I know that for this operation i needed ACS server 5.1 is it possible to encryp dataflow without ACS server and if you have the configuration please send to me &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962455#M7482</guid>
      <dc:creator>Liberth Frank Torrez Rivera</dc:creator>
      <dc:date>2020-02-21T18:27:24Z</dc:date>
    </item>
    <item>
      <title>how configure Encryption with MACsec switch to switch without AC</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962456#M7483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure switch to switch encryption without an ACS server using (CTS manual) on the interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done this on 3750-X using the MacSec module, not sure if it can be done on the 3560-X.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE #23340 (Security)&lt;/P&gt;&lt;P&gt;Jon Humphries&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 13:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962456#M7483</guid>
      <dc:creator>jon.humphries</dc:creator>
      <dc:date>2012-07-02T13:39:04Z</dc:date>
    </item>
    <item>
      <title>how configure Encryption with MACsec switch to switch without AC</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962457#M7484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the answer, I don't know how to see if my switch 3560-x has this MacSec module, do you have a print screen or a document to show me what kiind of show can i put in CLI comands to see this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you very much,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;liberth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 14:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962457#M7484</guid>
      <dc:creator>Liberth Frank Torrez Rivera</dc:creator>
      <dc:date>2012-07-02T14:28:05Z</dc:date>
    </item>
    <item>
      <title>how configure Encryption with MACsec switch to switch without AC</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962458#M7485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frank, the macsec module is a separate hardware module/card that supposedly performs line rate macsec in hw. I think you can see it via show inv or show ver. The product code is C3KX-SM-10G.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm also having the exact problem above. I have 2 x 3650-X connected via fiber on their service modules (macsec module). I am trying to configure L2 encryption (macsec/trustsec) without an ACS server. I assume I need to configure in CTS manual mode, which I have done. When I do a "show cts" I can see sap session sucessful but nothing for authentication or accounting. Running a wireshark capture I can see all traffic i.e. no encryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone clarify the configuration needed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running c3560e-universalk9-mz.150-1.SE3.bin with ipbase licence. Do I need a different type of licence? I found this on Cisco website:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"If you select GCM as the SAP operating mode, you must have a MACsec Encryption software license from Cisco. If you select GCM without the required license, the interface is forced to a link-down state."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/15.0_1_se/configuration/guide/swmacsec.html#wp1334072"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/15.0_1_se/configuration/guide/swmacsec.html#wp1334072&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 15:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962458#M7485</guid>
      <dc:creator>andrew-lang</dc:creator>
      <dc:date>2012-07-02T15:24:58Z</dc:date>
    </item>
    <item>
      <title>how configure Encryption with MACsec switch to switch without AC</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962459#M7486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have confirmed a working configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch# configure terminal&lt;/P&gt;&lt;P&gt;Switch(config)# interface gi1/2&lt;/P&gt;&lt;P&gt;Switch(config-if)# cts manual &lt;/P&gt;&lt;P&gt;Switch(config-if-cts-manual)# sap pmk &lt;HEXKEY&gt; mode-list gcm-encrypt&lt;/HEXKEY&gt;&lt;/P&gt;&lt;P&gt;Switch(config-if-cts-manual)# no propagate sgt&lt;/P&gt;&lt;P&gt;Switch(config-if-cts-manual)# exit &lt;/P&gt;&lt;P&gt;Switch(config-if)# shut&lt;/P&gt;&lt;P&gt;Switch(config-if)# no shut&lt;/P&gt;&lt;P&gt;Switch(config-if)# end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will work on both service module interface or regular switch interface and I am using 3560-X.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p.s. the issue I had was actually with an incorrect lab setup by spanning the traffic. Span decrypts traffic before sending it to the destination port. A re-test via a physical tap verified it was working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Cheers!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 08:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962459#M7486</guid>
      <dc:creator>andrew-lang</dc:creator>
      <dc:date>2012-07-11T08:59:08Z</dc:date>
    </item>
    <item>
      <title>how configure Encryption with MACsec switch to switch without AC</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962460#M7487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;Great response! I was curious if I still needed the Service Module for switch-to-switch encryption? The data sheet made it sound like switch-to-switch encryption would not work without the Service Module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 23:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962460#M7487</guid>
      <dc:creator>michael.lorincz</dc:creator>
      <dc:date>2012-07-17T23:16:14Z</dc:date>
    </item>
    <item>
      <title>how configure Encryption with MACsec switch to switch without AC</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962461#M7488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, if using Manual Mode, would I still need to setup trustsec credentials on the switch or is that something only used with 802.1x authentication? Sorry, I'm new to this! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 23:23:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962461#M7488</guid>
      <dc:creator>michael.lorincz</dc:creator>
      <dc:date>2012-07-17T23:23:18Z</dc:date>
    </item>
    <item>
      <title>how configure Encryption with MACsec switch to switch without AC</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962462#M7489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't need the credentials in manual mode, these are used to get the PAC from ACS 5.x or ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 09:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962462#M7489</guid>
      <dc:creator>jon.humphries</dc:creator>
      <dc:date>2012-09-17T09:32:32Z</dc:date>
    </item>
    <item>
      <title>Hi Jon - Coming in late on</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962463#M7490</link>
      <description>&lt;P&gt;Hi Jon -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Coming in late on this post - must I get a MACsec module to perform encryption between switches or is this only if I would need to perform encryption in hardware?&lt;/P&gt;&lt;P&gt;Thank you, Pat&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2015 18:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962463#M7490</guid>
      <dc:creator>Patrick McHenry</dc:creator>
      <dc:date>2015-01-21T18:30:06Z</dc:date>
    </item>
    <item>
      <title>Hi Pat,for my understanding</title>
      <link>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962464#M7491</link>
      <description>&lt;P&gt;Hi Pat,&lt;/P&gt;&lt;P&gt;for my understanding the MACSEC (service) module have to be used for links using the SFP+ ports in the module itself (eg fiber). Encryption is always done in hardware. MACSEC cannot be used&amp;nbsp;on C3KX-NM-10G or C3KX-NM-1G. modules.&amp;nbsp;MACSEC encryption is supported in hardware on "downlink" ports (copper ports).&lt;/P&gt;&lt;P&gt;Can somebody agree/disagree with this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br Fritz&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2015 08:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-configure-encryption-with-macsec-switch-to-switch-without/m-p/1962464#M7491</guid>
      <dc:creator>kerstin-534</dc:creator>
      <dc:date>2015-06-22T08:49:05Z</dc:date>
    </item>
  </channel>
</rss>

