cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Join Customer Connection to register!
484
Views
0
Helpful
4
Replies
carl_townshend
Frequent Contributor

MAC Sec - who uses it etc

Hi All

Can anyone tell me if they use Macsec and why?

We have some ethernet circuits to remote sites and we need to look at encryption.

Is it easy to do switch to switch encryption, much config involved?

does this bring the throughput down on the switch or is it done in asics?

cheers

4 REPLIES 4
mwood000111
Beginner

We attempted to use it in our VPLS mesh setup but was not successful.  Only could be really used for point to point.  We stood up two sites but once we added the third leg, that broke it down.  Cisco stated they couldnt support this design.  This was after a few months of troubleshooting, code upgrades to address this issue (using a C9300 and moving to 16.9.1).  Config was pretty basic.  Cant say if the throughput was impacted or not as we were not able to fully implement.  Useful link below for the C9300 platform.  HTH.

 

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/configuration_guide/sec/b_166_sec_9300_cg/macsec_encryption.html#task_CCBD6C0C4B07493BB5531708AE622C61

mlund
Rising star

Hi

I have done it, reason is gouvernment regulations.

And it's done in hardware so no impact on throughput. example config

interface x/y/z

cts manual
 no propagate sgt
 sap pmk 0000000000000000000000000000000000000000000000000000001234ABCDEF mode-list gcm-encrypt

the same in both switches.

/Mikael

carl_townshend
Frequent Contributor

Hi there

can you tell me what each command does?

is there a key you put in which has to match each end?

 

Hi,

Here is the complete guide for the same:

https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/command_sum.html#79442

 

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!