Configuring ANYsec MKA
ANYsec uses MKA to distribute SAKs. MKA is part of the IEEE802.1x standard and is a Layer 2 protocol without an IP header. As an MPLS Layer 2.5 encryption protocol, ANYsec reuses MKA by encapsulating MKA in IP/UDP to distribute the SAK from one PE to another.
The user-configurable UDP port identifies the MKA packets on the router. Use the config>anysec>mka-over-ip>mka-udp-port command to configure the MKA UDP port. Nokia recommends reserving the UDP port for MKA for the entire network and ensuring it is not in use by any other application.
The following figure shows the ANYsec implementation using the MKA UDP port configuration.