Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

Configure macsec keychain policy using the GUI

Want to summarize with AI?

Log in

Configure MACsec keychain policy through the GUI to define key policies with pre-shared keys for secure fabric interface communication.


Procedure

  1. On the menu bar, click Fabric > Fabric Policies > Policies > MACsec > KeyChains. In the Navigation pane, right click on KeyChains to open Create MACsec Keychain Policy and perform the following actions:

    1. In the Name field, enter a name for the MACsec Fabric Interface policy.
    2. Expand the MACsec Key Policy table to create the Key policy.
  2. In the MACsec Key Policy dialog box perform the following actions:

    1. In the Name field, enter a name for the MACsec Key policy.
    2. In the Key Name field, enter a key name (up to 64 hexadecimal characters).
      Note

      A maximum of 64 keys are supported per keychain.

    3. In the Pre-shared Key field, enter the pre-shared key information.
      Note
      • For 128-bit cipher suites only 32 character PSKs are permitted.

      • For 256-bit cipher suites only 64 Character PSKs are permitted.

    4. In the Start Time field, select a date for the key to become valid.
    5. In the End Time field, select a date for the key to expire. Click Ok and Submit.
      Note

      When defining multiple keys in a keychain, the keys must be defined with overlapping times in order to assure a smooth transition from the old key to the new key. The endTime of the old key should overlap with the startTime of the new key.

    For configuring the Keychain policy through Access Policies, on the menu bar click Fabric > External Access Policies. In the Navigation pane, click on Policies > Interface > MACsec > MACsec KeyChain Policies and right click on to open Create MACsec Keychain Policy and perform the steps above.