<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MacSec host to host on same switch in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762970#M1097217</link>
    <description>&lt;P&gt;There is no support for Host to Host encryption within the same switch.&amp;nbsp; MACSec is a "per hop" or "on the wire" encryption protocol, meaning you can encrypt traffic on the link (or wire) between the Host and the switch, or on the link between two switches, but traffic that passes across a switch / within a switch is not encrypted.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Quote: "MACsec is the IEEE 802.1AE standard for authenticating and encrypting packets between two MACsec-capable devices. Catalyst switches support 802.1AE encryption with MACsec Key Agreement (MKA) on switch-to-host links for encryption between the switch and host device. The switch also supports MACsec encryption for switch-to-switch (inter-network device) security using both Cisco TrustSec Network Device Admission Control (NDAC), Security Association Protocol (SAP) and MKA-based key exchange protocol."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/sec/b_169_sec_9300_cg/macsec_encryption.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/sec/b_169_sec_9300_cg/macsec_encryption.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2023 09:32:13 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2023-01-26T09:32:13Z</dc:date>
    <item>
      <title>MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762864#M1097210</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Does Macsec support host to host encryption between hosts on the same switch?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 08:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762864#M1097210</guid>
      <dc:creator>ivan.yeung</dc:creator>
      <dc:date>2023-01-26T08:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762869#M1097211</link>
      <description>&lt;P&gt;Yes, MACsec (MAC Security) supports host-to-host encryption between hosts on the same switch. It uses IEEE 802.1AE standard for providing secure communication over a LAN by encrypting data frames at the MAC layer. It can be used for both point-to-point and point-to-multipoint connections, and can be configured on individual switch ports or on a VLAN level.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please rate this and mark as solution/answer, if this resolved your issue&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;All the best,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AK&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 08:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762869#M1097211</guid>
      <dc:creator>khorram1998</dc:creator>
      <dc:date>2023-01-26T08:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762888#M1097212</link>
      <description>&lt;P&gt;Hi Khorram1998&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any ref links?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 08:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762888#M1097212</guid>
      <dc:creator>ivan.yeung</dc:creator>
      <dc:date>2023-01-26T08:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762945#M1097215</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Yes, here are a few references on MacSec host to host encryption on the same switch:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Cisco documentation on Configuring MACsec on Cisco IOS XE Switches: &lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0110.html" target="_new"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0110.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Please note that the Cisco documentation and standard are the most reliable resources to follow.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please rate this and mark as solution/answer, if this resolved your issue&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;All the best,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AK&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 26 Jan 2023 09:04:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762945#M1097215</guid>
      <dc:creator>khorram1998</dc:creator>
      <dc:date>2023-01-26T09:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762970#M1097217</link>
      <description>&lt;P&gt;There is no support for Host to Host encryption within the same switch.&amp;nbsp; MACSec is a "per hop" or "on the wire" encryption protocol, meaning you can encrypt traffic on the link (or wire) between the Host and the switch, or on the link between two switches, but traffic that passes across a switch / within a switch is not encrypted.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Quote: "MACsec is the IEEE 802.1AE standard for authenticating and encrypting packets between two MACsec-capable devices. Catalyst switches support 802.1AE encryption with MACsec Key Agreement (MKA) on switch-to-host links for encryption between the switch and host device. The switch also supports MACsec encryption for switch-to-switch (inter-network device) security using both Cisco TrustSec Network Device Admission Control (NDAC), Security Association Protocol (SAP) and MKA-based key exchange protocol."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/sec/b_169_sec_9300_cg/macsec_encryption.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/sec/b_169_sec_9300_cg/macsec_encryption.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 09:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762970#M1097217</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-26T09:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762986#M1097220</link>
      <description>&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;consider below:&lt;/P&gt;&lt;P&gt;host A to switchA is encrypted by macsec and host B to switchB is encrypted by macsec also, so host A and host B is encrypted by macsec? am i correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 09:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762986#M1097220</guid>
      <dc:creator>ivan.yeung</dc:creator>
      <dc:date>2023-01-26T09:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762993#M1097222</link>
      <description>&lt;P&gt;That depends on what you are defining as encrypted.&amp;nbsp; Traffic from Host A to Switch A is encrypted,&amp;nbsp; Traffic from Host B to Switch B is encrypted, but that is where the encryption stops.&amp;nbsp; Traffic from Host A to Host B (i.e. end to end) i NOT encrypted.&lt;/P&gt;
&lt;P&gt;you could configure MACSec on the inter-switch link but you still do not have true Host to Host encryption.&amp;nbsp; Let us say that Host A is connected to port Eth1/1 and the uplink port between Switch A and Switch B is Eth1/48 respectively, and finally Host B is connected to Eth1/1 on Switch B.&amp;nbsp; then the following would be true&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Host A to Switch A Eth1/1 IS encrypted&lt;/LI&gt;
&lt;LI&gt;Switch A Eth1/1 to Switch A Eth1/48 IS NOT encrypted&lt;/LI&gt;
&lt;LI&gt;Switch A Eth1/48 to Switch B Eth1/48 IS encrypted&lt;/LI&gt;
&lt;LI&gt;Switch B Eth1/48 to Switch B Eth1/1 IS NOT encrypted&lt;/LI&gt;
&lt;LI&gt;Switch B Eth1/1 to Host B IS encrypted&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 26 Jan 2023 10:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4762993#M1097222</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-26T10:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: MacSec host to host on same switch</title>
      <link>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4766706#M1097372</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1127365"&gt;@ivan.yeung&lt;/a&gt;&amp;nbsp; , Marius is correct.&amp;nbsp; Here is a Configuration Guide for MACsec Switch to Host. &lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/networking-knowledge-base/configuring-macsec-switch-to-host-with-cat9k-amp-ise/ta-p/4436087" target="_blank"&gt;https://community.cisco.com/t5/networking-knowledge-base/configuring-macsec-switch-to-host-with-cat9k-amp-ise/ta-p/4436087&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 12:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/macsec-host-to-host-on-same-switch/m-p/4766706#M1097372</guid>
      <dc:creator>Tim Glen</dc:creator>
      <dc:date>2023-02-01T12:47:50Z</dc:date>
    </item>
  </channel>
</rss>

