cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
884
Views
0
Helpful
5
Replies

C3850 MacSec issue

booleung
Level 1
Level 1

Hello,

we've a WS-C3850-24T running software 16.09.06 with ipbasek9 license. When we tried to put the config to the interface we got below,

c3850(config-if)#mka policy mkapolicy1

% GCM-AES-256 is not supported

% Cannot apply MKA Policy "mkapolicy1"...
- Interface is not MACsec capable.

Any ideas why this happened?

Thanks!

Bo

 

 

5 Replies 5

marce1000
VIP
VIP

 

 - I am not sure it can work with that 'software level' could you have a go with a universak9 image as in : 

          https://software.cisco.com/download/home/284455433/type/282046477/release/Gibraltar-16.12.5b

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Thanks for your reply but according to release notes on CCO Macsec MKA was support from 16.9.1

128-bit—(IP Base and IP Services)

256-bit—(IP Services)

Bo

 

 - I though that the mka policy command was a global configuration setting not per interface , you may try that.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Yes I know, MKA policy is global under interface looks like this,

macsec network-link
mka pre-shared-key key-chain XXX

 

 - FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv18875

       Check if  the described workaround can be applied to your case too.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card