Hi Katerina, Did you ever resolve this problem ? I have the same question (using C93240YC-FX2 ) - I think this can be done, but I'm wondering if it can be done without both links going down at the same time. In contrary to IOS, NX-OS requires macsec to be configured on the portchannel instead of the underlying ethernet interface. This might trigger a VPC inconsistency. For example, starting with DC1 secondary, the portchannel between DC1 secondary and DC2 secondary might go down because: - Macsec is not yet configured on DC2 secondary - DC1 secondary is inconsistent with DC1 primary (VPC inconsistency) Now when fixing DC2 secondary, at least MacSec between DC1 secondary and DC2 secondary is consistent. But the link might still stay down because: - DC1 secondary is inconsistent with DC1 primary (VPC inconsistency) - DC2 secondary is inconsistent with DC2 primary (VPC inconsistency) If we then start with the portchannel between DC1 primary and DC2 primary, it will initially go down also because MacSec is not configured on both sides at the same time. This would bring the whole VPC down. Anyone has experience with this, can it be done without downtime ? Will Macsec actually trigger a VPC inconsistency ? Thanks.
... View more