Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
This document will contain a number of MACsec specific terms, please see the History & Terminology document I wrote for a detailed understanding. I also encourage you to Click Helpful, if this is helpful or to comment if you have questions or conce...
This is the first in a series of documents I'm writing on MACsec. As the configuration will become increasingly complex, I encourage you to read them in order. I also encourage you to Click Helpful, if this is helpful or to comment if you have ques...
Summary
Here we will go over the configuration needed for MACsec Switch to Switch using a Pre-Shared Key. Topics that will be covered include, command usage, key derivation and key server election. Please see the MACsec History and Terminology for ...
Itay, Glad to hear you got this working with a tweak to the MKA policy.
If show macsec interfafce ten1/1/1 shows MACsec as enabled && AnyConnect shows GCM encryption occurring then traffic -on the wire- is encrypted.
So, why doesn't Wireshark...
A couple of questions...
Please shut \ no shut again, then do show logging | inc X/Y/Z (just use the numerical interface identifier) There should be output from the interface flap and from the MKA negotiation.
From the other thread, I see...
Hello Itay,
On the switch please shut, no shut the port that faces the host.
Then run those same commands above and post the output inline if there is a problem uploading a text file.
also post the output from
show macsec interface gigX/Y/Z
Tha...
Hi ic,
Try removing the ip access-group from the interface and let me know what you see.
Also please do
show interface gigX/Y/Z
show logging | inc gigX/Y/Z
sh mac address-table gigX/Y/Z
Tim
Hi ic,
In a Cisco PoC your account team should be able to engage with TAC and other pre-sales resources to help out.
Alternatively, please create a -new- thread with a sanitized show running-config and indicate the interface you are using for te...