cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1562
Views
0
Helpful
5
Replies

C3850 MacSec issue

booleung
Level 1
Level 1

Hello,

we've a WS-C3850-24T running software 16.09.06 with ipbasek9 license. When we tried to put the config to the interface we got below,

c3850(config-if)#mka policy mkapolicy1

% GCM-AES-256 is not supported

% Cannot apply MKA Policy "mkapolicy1"...
- Interface is not MACsec capable.

Any ideas why this happened?

Thanks!

Bo

 

 

5 Replies 5

marce1000
Hall of Fame
Hall of Fame

 

 - I am not sure it can work with that 'software level' could you have a go with a universak9 image as in : 

          https://software.cisco.com/download/home/284455433/type/282046477/release/Gibraltar-16.12.5b

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Thanks for your reply but according to release notes on CCO Macsec MKA was support from 16.9.1

128-bit—(IP Base and IP Services)

256-bit—(IP Services)

Bo

 

 - I though that the mka policy command was a global configuration setting not per interface , you may try that.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Yes I know, MKA policy is global under interface looks like this,

macsec network-link
mka pre-shared-key key-chain XXX

 

 - FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv18875

       Check if  the described workaround can be applied to your case too.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '