- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2021 07:30 AM - edited 10-13-2021 07:31 AM
Hi all,
hope to find everyone well in this times
I had a request from a costumer where he said that I need to have all the network links encrypted but I have no clue how to implement this.
Basically the core of the network is comprised by Cisco 9300L in a ring disposition where all the packets are being routed from switch to switch by EIGRP. I know I won't be able to apply encryption in simple L2 managed switches but is it possible to encrypt all the data passing trough to the core of the network?
Also in the opinion of all, what's the best way to encrypt like the costumer requested, all the links of the network?
Thank you for the help
Solved! Go to Solution.
- Labels:
-
Other Network Security Topics
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2021 07:33 AM
On Layer 2 you can do MACSEC on Cat 9300
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2021 07:35 AM
You can implement MACSec on a hop-by-hop basis, between switch from the access layer to distribution to core.
https://community.cisco.com/t5/networking-documents/macsec-history-amp-terminology/ta-p/4436094
If you wish to encrypt from the user's computer to the access layer switch, you'd need AnyConnect.
https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/117277-config-anyconnect-00.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2021 07:33 AM
On Layer 2 you can do MACSEC on Cat 9300
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2021 07:35 AM
You can implement MACSec on a hop-by-hop basis, between switch from the access layer to distribution to core.
https://community.cisco.com/t5/networking-documents/macsec-history-amp-terminology/ta-p/4436094
If you wish to encrypt from the user's computer to the access layer switch, you'd need AnyConnect.
https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/117277-config-anyconnect-00.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2021 10:50 AM
Thank you very much, this is extremely helpful. I will apply this to all of the core switches on a hop by hop basis.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-20-2021 08:25 AM
Hi all,
a doubt arisen from this now, I was trying to understand this better and watching CBT Nuggets as well and found that Keith Barker programmed MACSec using the following command in the interface "CTS Manual" and then applying the PMK.
What is the difference between the "CTS Manual" and the "key chain keychain1 macsec" configuration?
Thank you
