cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
124
Views
1
Helpful
3
Replies

MacSec on 8300 TX Interface

DaveBeattie
Level 1
Level 1

I am looking to run "switch-to-switch" MacSec on a 8300-2N2S-4T2X. The hand off is 1GE-TX. I realise that the onboard TX interfaces do not support MacSec, but could I use a TX SPF (GLC-TE or SFP-10G-T-X) in one of the onboard 10G interfaces to make this work? The opposite end of the link will be an identical 8300-2N2S-4T2X router.

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

MKA is supported on switch-to-host facing links. Host-facing links typically use flexible authentication ordering for handling heterogeneous devices with or without IEEE 802.1x, and can optionally use MKA-based MACsec encryption.

check the limitation here :

https://www.cisco.com/c/en/us/td/docs/routers/ir8340/software/configuration/b_ir8340_cg_17-8/m-macsec-encryption.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi BB

Thanks for the response, but I am using a 8300-2N2S-4T2X router not a 8340 and I am looking to do switch-to-switch MacSec, not switch-to-host.

 

This video demonstrates the MACsec capabilities on Catalyst 8300 and 8200 series edge platforms, supported interfaces and modules with a live demo that explains successful MACsec peering using C-NIM-2T module on these platforms .
Review Cisco Networking for a $25 gift card