cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1879
Views
0
Helpful
1
Replies

MACsec switch-to-switch capture traffic

Moti A
Level 1
Level 1

Hi,

I am trying to capture encrypted traffic between two MACsec enabled switches (manual mode), I put the secured interfaces as a source but I can see clear test capture even though I can see that the links are secured.

I am using 6504 switches with WS-X6908-10G line cards and using monitor capture feature - when I am exporting the captured buffer to Wireshark I can see all payload content.
my thought is that the capture point is before the encryption and decryption take place since those are PHY to PHY based.

 

Am I right?

1 Accepted Solution

Accepted Solutions

Hi,
The traffic will be encrypted on egress from the switch, so if you are taking a packet capture from the switch itself, the traffic would not have been encrypted yet. You'd have to capture the traffic in between the switches.

HTH

View solution in original post

1 Reply 1

Hi,
The traffic will be encrypted on egress from the switch, so if you are taking a packet capture from the switch itself, the traffic would not have been encrypted yet. You'd have to capture the traffic in between the switches.

HTH
Review Cisco Networking for a $25 gift card