01-31-2011 03:04 AM - edited 03-04-2019 11:15 AM
01-31-2011 04:37 AM
Can you rephrase that and maybe attach a digram ?
01-31-2011 02:45 PM
I have update, thanks for any help you can provide.
01-31-2011 03:31 PM
Hi
I do not think that you can do that with an etherchannel.
shure you can do load balancing and so on but i do not think the etherchannel will like an encryption engine in one link of the the etherchannel and one in another.
To be honest this looks like recipe for disaster.
If i were you and I needed an encrypted link I would look into 802.1ae and the new breed of switches that is coming up.
good luck
02-01-2011 05:20 AM
MACSec is not end to end encryption, and that is what the customer requires. This is an Ethernet encryptor that leaves the MAC header clear and encrypts layer 3 and above. They are only using EtherChannel to allow quick recovery of a failed condition, not for the added bandwidth. We may have to redesign to allow this network to function.
02-01-2011 07:27 AM
Ok fair enough.
You are absolutely right it is not end to end encryption.
Can you paste the make and model of your encryption devices ?
it might make things easier to find information on how they handle things.
Good luck
HTH
02-01-2011 07:37 AM
removed
02-01-2011 01:45 PM
Hi
You say that you want to use it for "failover purposes"
Maybe you can use link state tracking ?
I can not find how they are working or how they are configured and you mentioned that you needed a link for some information like key exchange and stuff.
If nothing else I am shure you will be able to do some things with TCL to make it work.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide