Introduces MACsec encryption technology and guides through configuration procedures for securing both fabric and access links using graphical and command-line interfaces.
This chapter contains the following sections:
Macsec
Describes an IEEE 802.1AE standards-based Layer 2 hop-by-hop encryption protocol that provides data confidentiality and integrity for media access independent protocols.
Guidelines and limitations for macsec on switches
Lists the switches and line cards that support MACsec and provides configuration guidelines and limitations.
Configure macsec for fabric links using the GUI
Configure MACsec fabric interface policies and apply them to leaf, spine, or pod policy groups to secure fabric links.
Configure macsec for access links using the GUI
Configure MACsec for access links by creating a MACsec Fabric Interface Policy and applying it to a Fabric Leaf or Spine Port Policy Group using the GUI.
Configure macsec parameters using the APIC GUI
Configure MACsec access parameters policy and apply it to interface policy groups to secure traffic on fabric interfaces.
Configure macsec keychain policy using the GUI
Configure MACsec keychain policy through the GUI to define key policies with pre-shared keys for secure fabric interface communication.
Configure macsec using the NX-OS style CLI
Configure MACsec security policies and key chains for both access and fabric interfaces using the NX-OS style CLI interface.