01-06-2024 03:27 AM
Hi,
I seek advice regarding MACSEC Cisco 9K cipher recommendation to be used?
Thanks,
Sam
Solved! Go to Solution.
01-06-2024 03:36 AM
from cisco doc.
The default MACsec cipher suite in the MKA policy will always be "GCM-AES-128". If the device supports both "GCM-AES-128" and "GCM-AES-256" ciphers, it is highly recommended to define and use a user defined MKA policy to include both 128 and 256 bits ciphers or only 256 bits cipher, as may be required.
MHM
01-06-2024 04:25 AM
Hello @sammanai
The default MACsec cipher suite "GCM-AES-128" is a strong choice, you have the option to define a user-defined MKA policy.
If your device supports both "GCM-AES-128" and "GCM-AES-256," and based on Cisco recommendation, you may consider defining a user-defined MKA policy that includes both 128-bit and 256-bit ciphers. This allows you to have flexibility in selecting the appropriate level of encryption based on your specific security requirements.
01-06-2024 03:36 AM
from cisco doc.
The default MACsec cipher suite in the MKA policy will always be "GCM-AES-128". If the device supports both "GCM-AES-128" and "GCM-AES-256" ciphers, it is highly recommended to define and use a user defined MKA policy to include both 128 and 256 bits ciphers or only 256 bits cipher, as may be required.
MHM
01-06-2024 04:25 AM
Hello @sammanai
The default MACsec cipher suite "GCM-AES-128" is a strong choice, you have the option to define a user-defined MKA policy.
If your device supports both "GCM-AES-128" and "GCM-AES-256," and based on Cisco recommendation, you may consider defining a user-defined MKA policy that includes both 128-bit and 256-bit ciphers. This allows you to have flexibility in selecting the appropriate level of encryption based on your specific security requirements.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide