cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
778
Views
0
Helpful
1
Replies

MACSEC Verification(manul mode)

Eugen Bitca
Level 1
Level 1

Hello,

I have macsec (manual mode) between 4500-x and Cat6500 Sup2.

How can I verifiy if MACSEC do realy encrypt traffic, SPAN session shows traffic unencrypted.

 

Configuration on both sides:

interface GigabitEthernet1/1
 switchport mode trunk
 switchport nonegotiate
 mtu 9198
 cts manual
  no propagate sgt
  sap pmk 0000000000000000000000000000000000000000000000000000000000ABC123 mode-list gcm-encrypt   
 storm-control broadcast level 2.00

 

Thank you

1 Reply 1

Eugen Bitca
Level 1
Level 1

MacSec EtherType 0x88e5 is transmitted over EoMPLS network.

So, between 2 MacSec Ports I configured a small test EoMPLS network, and inside MPLS, SPAN sessions shows encrypted traffic.

Review Cisco Networking for a $25 gift card