Configure MACsec security policies and key chains for both access and fabric interfaces using the NX-OS style CLI interface.
Procedure
-
Configure MACsec Security Policy for access interfaces
Example:
apic1# configure apic1(config)# template macsec access security-policy accmacsecpol1 apic1(config-macsec-param)# cipher-suite gcm-aes-128 apic1(config-macsec-param)# conf-offset offset-30 apic1(config-macsec-param)# description 'description for mac sec parameters' apic1(config-macsec-param)# key-server-priority 1 apic1(config-macsec-param)# sak-expiry-time 110 apic1(config-macsec-param)# security-mode must-secure aapic1(config-macsec-param)# window-size 1 apic1(config-macsec-param)# exit apic1(config)# -
Configure MACsec key chain for access interface
PSK can be configured in 2 ways:
Note
-
Inline with the psk-string command as illustrated in key 12ab below. The PSK is not secure because it is logged and exposed.
-
Entered separately in a new command Enter PSK string after the psk-string command as illustrated in key ab12. The PSK is secured because it is only echoed locally and is not logged.
Example:
apic1# configure apic1(config)# template macsec access keychain acckeychainpol1 apic1(config-macsec-keychain)# description 'macsec key chain kc1' apic1(config-macsec-keychain)# key 12ab apic1(config-macsec-keychain-key)# life-time start 2017-09-19T12:03:15 end 2017-12-19T12:03:15 apic1(config-macsec-keychain-key)# psk-string 123456789a223456789a323456789abc apic1(config-macsec-keychain-key)# exit apic1(config-macsec-keychain)# key ab12 apic1(config-macsec-keychain-key)# life-time start now end infinite apic1(config-macsec-keychain-key)# life-time start now end infinite apic1(config-macsec-keychain-key)# psk-string Enter PSK string: 123456789a223456789a323456789abc apic1(config-macsec-keychain-key)# exit apic1(config-macsec-keychain)# exit apic1(config)# -
-
Configure MACsec interface policy for access interface
Example:
apic1# configure apic1(config)# template macsec access interface-policy accmacsecifpol1 apic1(config-macsec-if-policy)# inherit macsec security-policy accmacsecpol1 keychain acckeychainpol1 apic1(config-macsec-if-policy)# exit apic1(config)# -
Associate MACsec interface policy to access interfaces on leaf or spine
Example:
apic1# configure apic1(config)# template macsec access interface-policy accmacsecifpol1 apic1(config-macsec-if-policy)# inherit macsec security-policy accmacsecpol1 keychain acckeychainpol1 apic1(config-macsec-if-policy)# exit apic1(config) -
Configure MACsec Security Policy for fabric interfaces
Example:
apic1# configure apic1(config)# template macsec fabric security-policy fabmacsecpol1 apic1(config-macsec-param)# cipher-suite gcm-aes-xpn-128 apic1(config-macsec-param)# description 'description for mac sec parameters' apic1(config-macsec-param)# window-size 1 apic1(config-macsec-param)# sak-expiry-time 100 apic1(config-macsec-param)# security-mode must-secure apic1(config-macsec-param)# exit apic1(config)# -
Configure MACsec key chain for fabric interface
PSK can be configured in 2 ways:
Note
-
Inline with the psk-string command as illustrated in key 12ab below. The PSK is not secure because it is logged and exposed.
-
Entered separately in a new command Enter PSK string after the psk-string command as illustrated in key ab12. The PSK is secured because it is only echoed locally and is not logged.
Example:
apic1# configure apic1(config)# template macsec fabric security-policy fabmacsecpol1 apic1(config-macsec-param)# cipher-suite gcm-aes-xpn-128 apic1(config-macsec-param)# description 'description for mac sec parameters' apic1(config-macsec-param)# window-size 1 apic1(config-macsec-param)# sak-expiry-time 100 apic1(config-macsec-param)# security-mode must-secure apic1(config-macsec-param)# exit apic1(config)# template macsec fabric keychain fabkeychainpol1 apic1(config-macsec-keychain)# description 'macsec key chain kc1' apic1(config-macsec-keychain)# key 12ab apic1(config-macsec-keychain-key)# psk-string 123456789a223456789a323456789abc apic1(config-macsec-keychain-key)#life-time start 2016-09-19T12:03:15 end 2017-09-19T12:03:15 apic1(config-macsec-keychain-key)# exit apic1(config-macsec-keychain)# key cd78 apic1(config-macsec-keychain-key)# psk-string Enter PSK string: 123456789a223456789a323456789abc apic1(config-macsec-keychain-key)# life-time start now end infinite apic1(config-macsec-keychain-key)# exit apic1(config-macsec-keychain)# exit apic1(config)# -
-
Associate MACsec interface policy to fabric interfaces on leaf (or spine):
Example:
apic1# configure apic1(config)# leaf 101 apic1(config-leaf)# fabric-interface ethernet 1/52-53 apic1(config-leaf-if)# inherit macsec interface-policy fabmacsecifpol2 apic1(config-leaf-if)# exit apic1(config-leaf)#