SA exhaustion behavior

Security zones 1 through 4 each have 16 Rx-SAs and 16 Tx-SAs and security zone 5 has 64 Rx-SAs and 64 Tx-SAs; see SA limits and network design for information. Two Rx-SAs are used for each Rx-SC for rollover purposes, and two Tx-SAs are used for each Tx-SC for rollover purposes. Security zones 1 through 4 are each allowed a maximum of 8 peers. A maximum of 32 peers is allowed in security zone 5.

Under each port, it is possible to assign the number of peers allowed on that port using the config>port>ethernet>dot1x>macsec>sub-port>max-peer command.

CAUTION: Nokia strongly recommends ensuring that the maximum peer value configured with the max-peer command does not exceed the maximum number of peers allowed per security zone or per port. Peers join the CA randomly on a first-come, first-served basis. If the maximum number of peers is exceeded, the peer connectivity may be random in the event of a node failure or packet loss.