Configuring A Preshared Key; Configuring The Mka Key Server Priority; Configuring Macsec Protection Parameters In Interface View - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
2.
Enter interface view.
3.
Enable MACsec desire.

Configuring a preshared key

In device-oriented mode, configure a preshared key as the CAK to be used during MKA negotiation.
To successfully establish an MKA session between two devices, make sure the connected MACsec
ports are configured with the same preshared key.
To configure a preshared key:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure a preshared key.

Configuring the MKA key server priority

Configure an MKA key server priority for key server selection. The lower the priority value, the higher
the priority.
In device-oriented mode, the port that has higher priority becomes the key server. If a port and its
peers have the same priority, MACsec compares the SCI values on the ports. The port with the
lowest SCI value (a combination of MAC address and port ID) becomes the key server.
A port with priority 255 cannot become the key server. For a successful key server selection, make
sure a minimum of one participant's key server priority is not 255.
To configure the MKA key server priority:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure the MKA key
server priority.
Configuring MACsec protection parameters in
interface view
If you configure a parameter in interface view after applying an MKA policy, the configuration in
interface view overwrites the configuration of the parameter in the MKA policy. Your configuration
Command
interface interface-type
interface-number
macsec desire
Command
system-view
interface interface-type
interface-number
mka psk ckn name cak simple
value
Command
system-view
interface interface-type
interface-number
mka priority priority-value
495
Remarks
N/A
By default, the port does not
expect MACsec protection for
outbound frames.
Remarks
N/A
N/A
By default, no MKA preshared key
exists on the port.
Remarks
N/A
N/A
The default setting is 0.

Advertisement

Table of Contents
loading

Table of Contents