transport-security

transport-security
+  macsec
   +  interface name string 
      +  admin-state keyword
      +  exclude-mac destination-mac string 
      +  exclude-protocols protocol keyword 
      +  interface-ref
         +  interface reference
      +  mka
         -  encryption-offset keyword
         +  fallback-key-chain reference
         -  hello-interval number
         +  key-chain reference
         -  key-number number
         -  key-server boolean
         -  key-server-priority number
         -  latest-sak-an number
         -  latest-sak-ki binary
         -  message-count number
         -  mka-participant ca-key-name string 
            -  cak-name string
            -  keychain-key-index number
            -  keychain-name string
            -  latest-sak-lpn number
            -  member-id binary
            -  message-count number
            -  mka-peer member-id binary 
               -  key-server-priority number
               -  lowest-acceptable-pn number
               -  message-number number
               -  mka-peer-mid binary
               -  sci binary
               -  type keyword
            -  previous-sak-lpn number
            -  principal boolean
            -  type keyword
         +  mka-policy reference
         -  oper-cipher keyword
         -  oper-state keyword
         -  outbound-sci binary
         -  previous-sak-an number
         -  previous-sak-ki binary
         -  statistics
            -  cak-info-missing number
            -  ckn-not-found number
            -  in-cak-mkpdu number
            -  in-mkpdu number
            -  in-mkpdu-errors
               -  bad-peer-errors number
               -  icv-verification-errors number
               -  peer-list-errors number
               -  validation-errors number
            -  in-sak-mkpdu number
            -  invalid-ckn-length number
            -  key-number-invalid number
            -  liveness-check-fail number
            -  max-peers-set-zero number
            -  new-live-peer number
            -  out-cak-mkpdu number
            -  out-mkpdu number
            -  out-mkpdu-errors
               -  pdu-invalid-number number
               -  pdu-not-quad-size number
               -  pdu-too-big number
               -  pdu-too-small number
            -  out-sak-mkpdu number
            -  parameter-not-quad-size number
            -  parameter-size-invalid number
            -  peer-same-mi number
            -  peers-removed number
            -  sak-cipher-mismatch-errors number
            -  sak-decryption-errors number
            -  sak-encryption-errors number
            -  sak-generated number
            -  sak-generation-errors number
            -  sak-hash-errors number
            -  sak-install-fail number
            -  sak-no-key-server number
            -  sak-non-live-peer number
            -  unsupported-algorithm-agility number
      -  oper-state keyword
      +  replay-protection
         +  admin-state keyword
         +  window-size number
      +  rx-must-be-encrypted boolean
      -  scsa-rx sci-rx string 
         -  delayed-packets number
         -  late-packets number
         -  not-using-sa-packets number
         -  sc-invalid number
         -  sc-octets-invalid number
         -  sc-octets-valid number
         -  sc-sak-installed-count number
         -  sc-valid number
         -  sci-rx-identifier string
         -  security-association rx-sa-an number 
            -  discarded-active number
            -  discarded-inactive number
            -  sa-invalid number
            -  sa-sak-installed boolean
            -  sa-valid number
         -  unchecked-packets number
      -  scsa-tx sci-tx string 
         -  sc-auth-only number
         -  sc-encrypted number
         -  sc-octets-auth-only number
         -  sc-octets-encrypted number
         -  sc-sak-installed-count number
         -  sci-tx-identifier string
         -  security-association tx-sa-an number 
            -  sa-auth-only number
            -  sa-encrypted number
            -  sa-sak-installed boolean
      -  statistics
         -  rx-badtag-pkts number
         -  rx-nosci-pkts number
         -  rx-overrun-packets number
         -  rx-unknownsci-pkts number
         -  rx-untagged-pkts number
         -  tx-too-long-packets number
         -  tx-untagged-pkts number
   +  mka
      +  policy name string 
         +  admin-state keyword
         +  clear-tag-mode keyword
         +  confidentiality-offset keyword
         +  eapol-destination-address string
         +  encrypt boolean
         +  hello-interval number
         +  key-server-priority number
         +  macsec-cipher-suite keyword
         +  sak-rekey-on-live-peer-loss boolean
      -  statistics
         -  in-mkpdu-errors
            -  bad-peer-errors number
            -  icv-verification-errors number
            -  peer-list-errors number
            -  validation-errors number
         -  out-mkpdu-errors
            -  pdu-invalid-number number
            -  pdu-not-quad-size number
            -  pdu-too-big number
            -  pdu-too-small number
         -  sak-cipher-mismatch-errors number
         -  sak-decryption-errors number
         -  sak-encryption-errors number
         -  sak-generation-errors number
         -  sak-hash-errors number
         -  sak-install-fail number

transport-security Descriptions

transport-security

Description Enclosing container for transport security
Contexttransport-security
Treetransport-security
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4

macsec

Description Enter the macsec context
Context transport-security macsec
Treemacsec
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4

interface name string

Description List of interfaces on which MACsec is enabled / available When interface is configured the entire interface is protected via macsec.
Contexttransport-security macsec interface name string
Treeinterface
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
name string
Description Name of the interface being created for the MACSec
Contexttransport-security macsec interface name string
String Length1 to 255
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
admin-state keyword
Description Enable MACsec on an interface
Context transport-security macsec interface name string admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
exclude-mac destination-mac string
Description list of destination macs to be excluded from the macsec encryption
Contexttransport-security macsec interface name string exclude-mac destination-mac string
Treeexclude-mac
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
destination-mac string
Description exclude this destination mac from encryption
Contexttransport-security macsec interface name string exclude-mac destination-mac string
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
exclude-protocols protocol keyword
Description protocols to be excluded from macsec
Context transport-security macsec interface name string exclude-protocols protocol keyword
Treeexclude-protocols
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
protocol keyword
Description exclude this protocol
Context transport-security macsec interface name string exclude-protocols protocol keyword
Options
  • lacp

    LACP protocol

  • lldp

    LLDP protocol

  • cdp

    Cisco discovery protocol

  • eapol-start

    EAP over LAN start packets

  • efm-oam

    Ethernet in first mile protocol

  • eth-cfm

    Connectivity fault management protocol

  • ptp

    Precision Time Protocol

  • ubfd

    Micro BFD protocol

ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
interface-ref
Description Enter the interface-ref context
Context transport-security macsec interface name string interface-ref
Treeinterface-ref
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
interface reference
Description Reference to a base interface, for example a port or LAG
Contexttransport-security macsec interface name string interface-ref interface reference
Treeinterface
Referenceinterface name string
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
mka
Description Enclosing container for the MKA interface
Contexttransport-security macsec interface name string mka
Treemka
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
encryption-offset keyword
Description Indicates the operational encryption offset used for the datapath PDUs when all parties in the CA have the SAK. This value is specified by the key server
Contexttransport-security macsec interface name string mka encryption-offset keyword
Treeencryption-offset
Options
  • 0-bytes

    No octets are sent unencrypted

  • 30-bytes

    30 octects are sent unencrypted

  • 50-bytes

    50 octects are sent unencrypted

ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
hello-interval number
Description MKA hello interval, the intervals are 1000 ms up to 6000 ms
Contexttransport-security macsec interface name string mka hello-interval number
Treehello-interval
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
key-number number
Description

Indicates the number of the currently assigned CAK

When a new CAK is generated, this number is incremented.

Contexttransport-security macsec interface name string mka key-number number
Treekey-number
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
key-server boolean
Description Indicates whether this server is the highest priority server in the peer group
Contexttransport-security macsec interface name string mka key-server boolean
Treekey-server
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
key-server-priority number
Description Indicates the priority of local server
Contexttransport-security macsec interface name string mka key-server-priority number
Treekey-server-priority
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
latest-sak-an number
Description

Indicates the Association Number (AN) of the latest Secure Association Key (SAK)

This number is concatenated with an SCI to identify a Secure Association (SA).

Contexttransport-security macsec interface name string mka latest-sak-an number
Treelatest-sak-an
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
latest-sak-ki binary
Description

Indicates the Key Identifier (KI) of the latest SAK

This number is derived from the MI of the key server and the key number.

Contexttransport-security macsec interface name string mka latest-sak-ki binary
Treelatest-sak-ki
String Length16
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
message-count number
Description Indicates the current count of MKA messages that is attached to MKA PDUs
Contexttransport-security macsec interface name string mka message-count number
Treemessage-count
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
mka-participant ca-key-name string
Description List of MKA participants.
Context transport-security macsec interface name string mka mka-participant ca-key-name string
Treemka-participant
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
ca-key-name string
Description MACsec CKN, a hexadecimal name is only valid
Contexttransport-security macsec interface name string mka mka-participant ca-key-name string
String Length2 to 64
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
cak-name string
Description MACsec CKN, a hexadecimal name is only valid
Contexttransport-security macsec interface name string mka mka-participant ca-key-name string cak-name string
Treecak-name
String Length2 to 64
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
mka-peer member-id binary
Description List of MKA peers.
Context transport-security macsec interface name string mka mka-participant ca-key-name string mka-peer member-id binary
Treemka-peer
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
type keyword
Description Indicates the type of the peer entry
Context transport-security macsec interface name string mka mka-participant ca-key-name string mka-peer member-id binary type keyword
Treetype
Options
  • live-peer-list

    These peer entry is in the Live Peer List

  • potential-peer-list

    These peer entry is in the Potential Peer List

ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
type keyword
Description Indicates the type of the MKA participant based on keychain it is using
Contexttransport-security macsec interface name string mka mka-participant ca-key-name string type keyword
Treetype
Options
  • primary

    This MKA participant is using primary keychain

  • fallback

    This MKA participant is using fallback keychain

ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
oper-cipher keyword
Description Indicates the operational encryption algorithm used for datapath PDUs when all parties in the CA have the SAK. This value is specified by the key server
Contexttransport-security macsec interface name string mka oper-cipher keyword
Treeoper-cipher
Options
  • gcm-aes-128

    gcm-aes-128 Cipher Suite

  • gcm-aes-256

    gcm-aes-256 Cipher Suite

  • gcm-aes-xpn-128

    gcm-aes-xpn-128 Cipher Suite

  • gcm-aes-xpn-256

    gcm-aes-xpn-256 Cipher Suite

ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
oper-state keyword
Description The operational state of the mka instance
Contexttransport-security macsec interface name string mka oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
outbound-sci binary
Description Indicates the Secure Channel Identifier (SCI) information for transmitting MACsec frames
Contexttransport-security macsec interface name string mka outbound-sci binary
Treeoutbound-sci
String Length8
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
previous-sak-an number
Description

Indicates the Association Number (AN) of the previous Security Association key (SAK)

This number is concatenated with an SCI to identify an Secure Association SA.

Contexttransport-security macsec interface name string mka previous-sak-an number
Treeprevious-sak-an
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
previous-sak-ki binary
Description

Indicates the Key Identifier (KI) of the previous SAK

This number is derived from the Member Identifier (MI) of the key server and the key number.

Contexttransport-security macsec interface name string mka previous-sak-ki binary
Treeprevious-sak-ki
String Length16
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
statistics
Description MKA interface counters
Context transport-security macsec interface name string mka statistics
Treestatistics
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
cak-info-missing number
Description Indicates the number of times internal CAK data is not available for the generation of the SAK.
Contexttransport-security macsec interface name string mka statistics cak-info-missing number
Treecak-info-missing
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
ckn-not-found number
Description Indicates the number of MKPDUs received with a CKN that does not match the CA configured for the port.
Contexttransport-security macsec interface name string mka statistics ckn-not-found number
Treeckn-not-found
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
in-cak-mkpdu number
Description Validated MKPDU received CAK count
Context transport-security macsec interface name string mka statistics in-cak-mkpdu number
Treein-cak-mkpdu
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
in-mkpdu number
Description Validated MKPDU received count
Context transport-security macsec interface name string mka statistics in-mkpdu number
Treein-mkpdu
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
in-mkpdu-errors
Description Enter the in-mkpdu-errors context
Context transport-security macsec interface name string mka statistics in-mkpdu-errors
Treein-mkpdu-errors
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
in-sak-mkpdu number
Description Validated and installed MKPDU received SAK count
Contexttransport-security macsec interface name string mka statistics in-sak-mkpdu number
Treein-sak-mkpdu
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
invalid-ckn-length number
Description Indicates the number of MKPDUs received which contain a CAK name that exceeds the maximum CAK name length.
Contexttransport-security macsec interface name string mka statistics invalid-ckn-length number
Treeinvalid-ckn-length
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
key-number-invalid number
Description Indicates the number of SAKs received with an invalid Key Number
Contexttransport-security macsec interface name string mka statistics key-number-invalid number
Treekey-number-invalid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
liveness-check-fail number
Description Indicates the number of MKPDUs received which contain an MN that is not acceptably recent.
Contexttransport-security macsec interface name string mka statistics liveness-check-fail number
Treeliveness-check-fail
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
max-peers-set-zero number
Description

Indicates the number of SecY SAK installations that have failed

Failed due to the max peer entry being set to 0.

Contexttransport-security macsec interface name string mka statistics max-peers-set-zero number
Treemax-peers-set-zero
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
new-live-peer number
Description Indicates the number of validated peers that have been added to the live peer list.
Contexttransport-security macsec interface name string mka statistics new-live-peer number
Treenew-live-peer
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
out-cak-mkpdu number
Description MKPDU CAK sent count
Context transport-security macsec interface name string mka statistics out-cak-mkpdu number
Treeout-cak-mkpdu
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
out-mkpdu number
Description MKPDU sent count
Context transport-security macsec interface name string mka statistics out-mkpdu number
Treeout-mkpdu
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
out-mkpdu-errors
Description Enter the out-mkpdu-errors context
Context transport-security macsec interface name string mka statistics out-mkpdu-errors
Treeout-mkpdu-errors
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
out-sak-mkpdu number
Description Validated and installed MKPDU transmit SAK count
Contexttransport-security macsec interface name string mka statistics out-sak-mkpdu number
Treeout-sak-mkpdu
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
parameter-not-quad-size number
Description Indicates the number of MKPDUs received which contain a parameter set that is not a multiple of 4 octets.
Contexttransport-security macsec interface name string mka statistics parameter-not-quad-size number
Treeparameter-not-quad-size
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
parameter-size-invalid number
Description Indicates the number of MKPDUs received which contain a parameter set body length that exceeds the remaining length of the MKPDU.
Contexttransport-security macsec interface name string mka statistics parameter-size-invalid number
Treeparameter-size-invalid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
peer-same-mi number
Description Indicates the number of MKPDUs received which contain a peerlist with an MI entry which conflicts with the local MI.
Contexttransport-security macsec interface name string mka statistics peer-same-mi number
Treepeer-same-mi
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
peers-removed number
Description

Indicates the number of peers removed from the live/potential peer

Peer removed due to not receiving an MKPDU within the MKA Live Time (6.0 sec).

Contexttransport-security macsec interface name string mka statistics peers-removed number
Treepeers-removed
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-generated number
Description Indicates the number of SAKs generated by this MKA instance
Contexttransport-security macsec interface name string mka statistics sak-generated number
Treesak-generated
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-hash-errors number
Description MKA error Hash Key generation count
Context transport-security macsec interface name string mka statistics sak-hash-errors number
Treesak-hash-errors
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-no-key-server number
Description Indicates the number of SAKs received from a none key server MKA participant
Contexttransport-security macsec interface name string mka statistics sak-no-key-server number
Treesak-no-key-server
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-non-live-peer number
Description Indicates the number of SAKs received from a peer that is not a member of the Live Peers List.
Contexttransport-security macsec interface name string mka statistics sak-non-live-peer number
Treesak-non-live-peer
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
unsupported-algorithm-agility number
Description Indicates the number of MKPDUs received which contain an unsupported Algorithm Agility value.
Contexttransport-security macsec interface name string mka statistics unsupported-algorithm-agility number
Treeunsupported-algorithm-agility
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
oper-state keyword
Description Indicates the operational state of macsec on this subinterface
Contexttransport-security macsec interface name string oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
replay-protection
Description Enter the replay-protection context
Context transport-security macsec interface name string replay-protection
Treereplay-protection
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
admin-state keyword
Description Enable MACsec on an interface
Context transport-security macsec interface name string replay-protection admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
window-size number
Description

MACsec window size, as defined by the number of out-of-order frames that are accepted.

A value of 0 means that frames are accepted only in the correct order.

Contexttransport-security macsec interface name string replay-protection window-size number
Treewindow-size
Default0
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
rx-must-be-encrypted boolean
Description

when true; only accept encrypted packets,

If false accept a mix of encrypted and clear text packets

Contexttransport-security macsec interface name string rx-must-be-encrypted boolean
Treerx-must-be-encrypted
Defaulttrue
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
scsa-rx sci-rx string
Description RX Secure Channel and Secure Association Statistics
Contexttransport-security macsec interface name string scsa-rx sci-rx string
Treescsa-rx
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sci-rx string
Description RX Secure Channel and Secure Association Statistics
Contexttransport-security macsec interface name string scsa-rx sci-rx string
String Length16
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
delayed-packets number
Description Indicates the number of received packets with the condition that the PN of the packets is lower than the lower bound of the replay protection PN
Contexttransport-security macsec interface name string scsa-rx sci-rx string delayed-packets number
Treedelayed-packets
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
late-packets number
Description Indicates the number of received packets that have been discarded due to replay window protection on this SC
Contexttransport-security macsec interface name string scsa-rx sci-rx string late-packets number
Treelate-packets
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
not-using-sa-packets number
Description

Indicates the summation of counter /macsec/rx-sa/not-using-sa-packets

Information for all the SAs which belong to this SC.

Contexttransport-security macsec interface name string scsa-rx sci-rx string not-using-sa-packets number
Treenot-using-sa-packets
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-invalid number
Description

Invalid Secure Channel RX Packets counter

This counter reflects the number of invalid received packets in a secure channel. Indicates the summation of counter /macsec/rx-sa/not-valid-packets information for all the SAs which belong to this SC.

Contexttransport-security macsec interface name string scsa-rx sci-rx string sc-invalid number
Treesc-invalid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-octets-invalid number
Description

Invalid Secure Channel RX Packets counter

This counter reflects the number of invalid received packets in a secure channel.

Contexttransport-security macsec interface name string scsa-rx sci-rx string sc-octets-invalid number
Treesc-octets-invalid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-octets-valid number
Description

Valid Secure Channel RX Packets counter

This counter reflects the number of valid received packets in a secure channel. Indicates the number of octets of plain text recovered from received packets that were integrity protected and encrypted.

Contexttransport-security macsec interface name string scsa-rx sci-rx string sc-octets-valid number
Treesc-octets-valid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-sak-installed-count number
Description

Secure Channel installed RX SAKs count

This counter reflects the number of SAKs that are installed in RX security channel.

Contexttransport-security macsec interface name string scsa-rx sci-rx string sc-sak-installed-count number
Treesc-sak-installed-count
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-valid number
Description

Valid Secure Channel RX Packets counter

This counter reflects the number of valid received packets in a secure channel. Indicates the summation of counter /macsec/rx-sa/ok-packets information for all the SAs which belong to this SC.

Contexttransport-security macsec interface name string scsa-rx sci-rx string sc-valid number
Treesc-valid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sci-rx-identifier string
Description

Secure Channel Identifier

Every Receive Channel is uniquely identified using this field.

Contexttransport-security macsec interface name string scsa-rx sci-rx string sci-rx-identifier string
Treesci-rx-identifier
String Length16
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
security-association rx-sa-an number
Description Enter the receiving-sa list instance
Context transport-security macsec interface name string scsa-rx sci-rx string security-association rx-sa-an number
Treesecurity-association
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
rx-sa-an number
Description Indicates the AN for identifying the receiving SA
Contexttransport-security macsec interface name string scsa-rx sci-rx string security-association rx-sa-an number
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
discarded-active number
Description Indicates the number of not valid packets that have been discarded on this active SA.
Contexttransport-security macsec interface name string scsa-rx sci-rx string security-association rx-sa-an number discarded-active number
Treediscarded-active
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
discarded-inactive number
Description Indicates the number of received packets that have been discarded on this SA which is not currently in use.
Contexttransport-security macsec interface name string scsa-rx sci-rx string security-association rx-sa-an number discarded-inactive number
Treediscarded-inactive
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sa-invalid number
Description

Invalid Secure Association RX Packets counter

This counter reflects the number of integrity check fails for received packets in a secure association.

Contexttransport-security macsec interface name string scsa-rx sci-rx string security-association rx-sa-an number sa-invalid number
Treesa-invalid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sa-sak-installed boolean
Description

Secure Association (SA) RX sak installed

This counter reflects if the RX SAK is installed for this SA.

Contexttransport-security macsec interface name string scsa-rx sci-rx string security-association rx-sa-an number sa-sak-installed boolean
Treesa-sak-installed
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sa-valid number
Description

Secure Association Valid RX Packets counter

This counter reflects the number of packets in a secure association that passed integrity check.

Contexttransport-security macsec interface name string scsa-rx sci-rx string security-association rx-sa-an number sa-valid number
Treesa-valid
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
unchecked-packets number
Description Indicates the number of packets that have failed the integrity check on this SC
Contexttransport-security macsec interface name string scsa-rx sci-rx string unchecked-packets number
Treeunchecked-packets
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
scsa-tx sci-tx string
Description TX Secure Channel and Secure Association Statistics
Contexttransport-security macsec interface name string scsa-tx sci-tx string
Treescsa-tx
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sci-tx string
Description TX Secure Channel and Secure Association Statistics
Contexttransport-security macsec interface name string scsa-tx sci-tx string
String Length16
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-auth-only number
Description

Secure Channel Authenticated only TX Packets counter

This counter reflects the number of authenticated only transmitted packets in a secure channel.

Contexttransport-security macsec interface name string scsa-tx sci-tx string sc-auth-only number
Treesc-auth-only
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-encrypted number
Description

Secure Channel Encrypted TX Packets counter

This counter reflects the number of encrypted and authenticated transmitted packets in a secure channel.

Contexttransport-security macsec interface name string scsa-tx sci-tx string sc-encrypted number
Treesc-encrypted
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-octets-auth-only number
Description

Secure Channel Authenticated only TX octets counter

This counter reflects the number of authenticated only transmitted octets in a secure channel.

Contexttransport-security macsec interface name string scsa-tx sci-tx string sc-octets-auth-only number
Treesc-octets-auth-only
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-octets-encrypted number
Description

Secure Channel Encrypted TX octets counter

This counter reflects the number of encrypted and authenticated transmitted octets in a secure channel.

Contexttransport-security macsec interface name string scsa-tx sci-tx string sc-octets-encrypted number
Treesc-octets-encrypted
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sc-sak-installed-count number
Description

Secure Channel installed TX SAKs count

This counter reflects the number of SAKs that are installed in TX security channel.

Contexttransport-security macsec interface name string scsa-tx sci-tx string sc-sak-installed-count number
Treesc-sak-installed-count
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sci-tx-identifier string
Description

Secure Channel Identifier

Every Transmit Channel is uniquely identified using this field.

Contexttransport-security macsec interface name string scsa-tx sci-tx string sci-tx-identifier string
Treesci-tx-identifier
String Length16
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
security-association tx-sa-an number
Description Enter the transmitting-sa list instance
Contexttransport-security macsec interface name string scsa-tx sci-tx string security-association tx-sa-an number
Treesecurity-association
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
tx-sa-an number
Description Indicates the AN for identifying the transmitting SA
Contexttransport-security macsec interface name string scsa-tx sci-tx string security-association tx-sa-an number
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sa-auth-only number
Description

Secure Association Authenticated only TX Packets counter

This counter reflects the number of authenticated only, transmitted packets in a secure association.

Contexttransport-security macsec interface name string scsa-tx sci-tx string security-association tx-sa-an number sa-auth-only number
Treesa-auth-only
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sa-encrypted number
Description

Secure Association (SA) encrypted Packets counter

This counter reflects the number of encrypted and authenticated transmitted packets in a secure association.

Contexttransport-security macsec interface name string scsa-tx sci-tx string security-association tx-sa-an number sa-encrypted number
Treesa-encrypted
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sa-sak-installed boolean
Description

Secure Association (SA) TX sak installed

This counter reflects if the TX SAK is installed for this SA.

Contexttransport-security macsec interface name string scsa-tx sci-tx string security-association tx-sa-an number sa-sak-installed boolean
Treesa-sak-installed
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
statistics
Description MACsec interface counters
Context transport-security macsec interface name string statistics
Treestatistics
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
rx-badtag-pkts number
Description

MACsec interface level Receive Bad Tag Packets counter

This counter will increment if MACsec is enabled on interface and incoming packet has incorrect MACsec tag.

Contexttransport-security macsec interface name string statistics rx-badtag-pkts number
Treerx-badtag-pkts
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
rx-nosci-pkts number
Description

MACsec interface level Receive No SCI Packets counter

This counter will increment if MACsec is enabled on interface and incoming packet does not have SCI field in MACsec tag.

Contexttransport-security macsec interface name string statistics rx-nosci-pkts number
Treerx-nosci-pkts
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
rx-overrun-packets number
Description Indicates the number of packets discarded because the number of received packets exceeded the cryptographic performance capabilities
Contexttransport-security macsec interface name string statistics rx-overrun-packets number
Treerx-overrun-packets
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
rx-unknownsci-pkts number
Description

MACsec interface level Receive Unknown SCI Packets counter

This counter will increment if MACsec is enabled on the interface and SCI present in the MACsec tag of the incoming packet does not match any SCI present in ingress SCI table.

Contexttransport-security macsec interface name string statistics rx-unknownsci-pkts number
Treerx-unknownsci-pkts
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
rx-untagged-pkts number
Description

MACsec interface level Receive untagged Packets counter

This counter will increment if MACsec is enabled on interface and the incoming packet does not have MACsec tag.

Contexttransport-security macsec interface name string statistics rx-untagged-pkts number
Treerx-untagged-pkts
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
tx-too-long-packets number
Description

Indicates the number of transmitted packets discarded because of long lenght

The packet length is greater than the Maximum Transmission Unit (MTU) of the Ethernet physical interface.

Contexttransport-security macsec interface name string statistics tx-too-long-packets number
Treetx-too-long-packets
Default0
Unitspackets
Configurable False
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
tx-untagged-pkts number
Description

MACsec interface level Transmit untagged Packets counter

This counter will increment if MACsec is enabled on interface and the outgoing packet is not tagged with MACsec header.

Contexttransport-security macsec interface name string statistics tx-untagged-pkts number
Treetx-untagged-pkts
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4

mka

Description The MKA
Contexttransport-security macsec mka
Treemka
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
policy name string
Description List of MKA policies
Context transport-security macsec mka policy name string
Treepolicy
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
name string
Description Name of the MKA policy
Context transport-security macsec mka policy name string
String Length1 to 255
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
admin-state keyword
Description

Enable mka policy

While MKA policy is enabled no policy parameters can be configured or modified.

Contexttransport-security macsec mka policy name string admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
clear-tag-mode keyword
Description Specifies the number of tags that will be in clear infront of the sectag
Contexttransport-security macsec mka policy name string clear-tag-mode keyword
Treeclear-tag-mode
Defaultno-tag
Options
  • no-tag

    Do not put any tags into clear

  • single-tag

    Put 4 bytes after the MAC header into clear

  • double-tag

    Put 8 bytes after the MAC header into clear

ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
confidentiality-offset keyword
Description The confidentiality offset specifies a number of octets in an Ethernet frame that are sent in unencrypted and in plain-text
Contexttransport-security macsec mka policy name string confidentiality-offset keyword
Treeconfidentiality-offset
Default0-bytes
Options
  • 0-bytes

    No octets are sent unencrypted

  • 30-bytes

    30 octects are sent unencrypted

  • 50-bytes

    50 octects are sent unencrypted

ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
eapol-destination-address string
Description This command can be used to set eap over lan destination mac to a unicast mac for L2 multiple hop networks
Contexttransport-security macsec mka policy name string eapol-destination-address string
Treeeapol-destination-address
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
encrypt boolean
Description Enable or disable PDU encryption, if enabled the PDUs are encrypted and authenticated if disabled the PDU is only authenticated and not encrypted
Contexttransport-security macsec mka policy name string encrypt boolean
Treeencrypt
Defaulttrue
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
hello-interval number
Description MKA hello interval, the intervals are 1000 ms up to 6000 ms
Contexttransport-security macsec mka policy name string hello-interval number
Treehello-interval
Range1000 | 2000 | 3000 | 4000 | 5000 | 6000
Default2000
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
key-server-priority number
Description

Specifies the key server priority used by the macsec

Macsec Key Agreement (MKA) advertises and selects a key server. The node with the lower priority-number is selected as the key server. If the priority-number is identical on both sides of a point-to-point link, the MKA protocol selects the device with the lower MAC address as the key server

Contexttransport-security macsec mka policy name string key-server-priority number
Treekey-server-priority
Default16
ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
macsec-cipher-suite keyword
Description Set cipher suite(s) for security association key (SAK) derivation
Contexttransport-security macsec mka policy name string macsec-cipher-suite keyword
Treemacsec-cipher-suite
Options
  • gcm-aes-128

    gcm-aes-128 Cipher Suite

  • gcm-aes-256

    gcm-aes-256 Cipher Suite

  • gcm-aes-xpn-128

    gcm-aes-xpn-128 Cipher Suite

  • gcm-aes-xpn-256

    gcm-aes-xpn-256 Cipher Suite

ConfigurableTrue
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
statistics
Description Operational state data for MKA
Context transport-security macsec mka statistics
Treestatistics
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
in-mkpdu-errors
Description Enter the in-mkpdu-errors context
Context transport-security macsec mka statistics in-mkpdu-errors
Treein-mkpdu-errors
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
peer-list-errors number
Description MKPDU RX non-recent peer list Message Number error count
Contexttransport-security macsec mka statistics in-mkpdu-errors peer-list-errors number
Treepeer-list-errors
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
out-mkpdu-errors
Description Enter the out-mkpdu-errors context
Context transport-security macsec mka statistics out-mkpdu-errors
Treeout-mkpdu-errors
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-decryption-errors number
Description MKA error SAK decryption/unwrap count
Contexttransport-security macsec mka statistics sak-decryption-errors number
Treesak-decryption-errors
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-encryption-errors number
Description MKA error SAK encryption/wrap count
Context transport-security macsec mka statistics sak-encryption-errors number
Treesak-encryption-errors
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-hash-errors number
Description MKA error Hash Key generation count
Context transport-security macsec mka statistics sak-hash-errors number
Treesak-hash-errors
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4
sak-install-fail number
Description MKA error SAK cipher mismatch count
Context transport-security macsec mka statistics sak-install-fail number
Treesak-install-fail
Default0
ConfigurableFalse
Platforms7250 IXR-10e-gen2cp, 7250 IXR-10e-gen2cp-3, 7250 IXR-10e-gen3, 7250 IXR-18e-gen3, 7250 IXR-6e-gen2cp, 7250 IXR-6e-gen2cp-3, 7250 IXR-6e-gen3, 7250 IXR-X1b, 7250 IXR-X3b, 7250 IXR-X4