10-13-2021 07:30 AM - edited 10-13-2021 07:31 AM
Hi all,
hope to find everyone well in this times
I had a request from a costumer where he said that I need to have all the network links encrypted but I have no clue how to implement this.
Basically the core of the network is comprised by Cisco 9300L in a ring disposition where all the packets are being routed from switch to switch by EIGRP. I know I won't be able to apply encryption in simple L2 managed switches but is it possible to encrypt all the data passing trough to the core of the network?
Also in the opinion of all, what's the best way to encrypt like the costumer requested, all the links of the network?
Thank you for the help
Solved! Go to Solution.
10-13-2021 07:33 AM
On Layer 2 you can do MACSEC on Cat 9300
10-13-2021 07:35 AM
You can implement MACSec on a hop-by-hop basis, between switch from the access layer to distribution to core.
https://community.cisco.com/t5/networking-documents/macsec-history-amp-terminology/ta-p/4436094
If you wish to encrypt from the user's computer to the access layer switch, you'd need AnyConnect.
https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/117277-config-anyconnect-00.html
10-13-2021 07:33 AM
On Layer 2 you can do MACSEC on Cat 9300
10-13-2021 07:35 AM
You can implement MACSec on a hop-by-hop basis, between switch from the access layer to distribution to core.
https://community.cisco.com/t5/networking-documents/macsec-history-amp-terminology/ta-p/4436094
If you wish to encrypt from the user's computer to the access layer switch, you'd need AnyConnect.
https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/117277-config-anyconnect-00.html
10-13-2021 10:50 AM
Thank you very much, this is extremely helpful. I will apply this to all of the core switches on a hop by hop basis.
10-20-2021 08:25 AM
Hi all,
a doubt arisen from this now, I was trying to understand this better and watching CBT Nuggets as well and found that Keith Barker programmed MACSec using the following command in the interface "CTS Manual" and then applying the PMK.
What is the difference between the "CTS Manual" and the "key chain keychain1 macsec" configuration?
Thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide