10-27-2021 09:38 AM
Hello,
we've a WS-C3850-24T running software 16.09.06 with ipbasek9 license. When we tried to put the config to the interface we got below,
c3850(config-if)#mka policy mkapolicy1
% GCM-AES-256 is not supported
% Cannot apply MKA Policy "mkapolicy1"...
- Interface is not MACsec capable.
Any ideas why this happened?
Thanks!
Bo
10-27-2021 09:54 AM
- I am not sure it can work with that 'software level' could you have a go with a universak9 image as in :
https://software.cisco.com/download/home/284455433/type/282046477/release/Gibraltar-16.12.5b
M.
10-27-2021 10:41 AM
Thanks for your reply but according to release notes on CCO Macsec MKA was support from 16.9.1
128-bit—(IP Base and IP Services)
256-bit—(IP Services)
Bo
10-27-2021 11:55 PM
- I though that the mka policy command was a global configuration setting not per interface , you may try that.
M.
10-28-2021 03:22 AM
Yes I know, MKA policy is global under interface looks like this,
macsec network-link
mka pre-shared-key key-chain XXX
10-28-2021 08:00 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv18875
Check if the described workaround can be applied to your case too.
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide