Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

Configure macsec using the NX-OS style CLI

Want to summarize with AI?

Log in

Configure MACsec security policies and key chains for both access and fabric interfaces using the NX-OS style CLI interface.


Procedure

  1. Configure MACsec Security Policy for access interfaces

    Example:

    apic1# configure
    apic1(config)#   template macsec access security-policy accmacsecpol1 
    apic1(config-macsec-param)#     cipher-suite gcm-aes-128
    apic1(config-macsec-param)#     conf-offset offset-30
    apic1(config-macsec-param)#     description 'description for mac sec parameters'
    apic1(config-macsec-param)#     key-server-priority 1
    apic1(config-macsec-param)#     sak-expiry-time 110
    apic1(config-macsec-param)#     security-mode must-secure
    aapic1(config-macsec-param)#     window-size 1
    apic1(config-macsec-param)#     exit
    apic1(config)# 
  2. Configure MACsec key chain for access interface

    PSK can be configured in 2 ways:

    Note
    • Inline with the psk-string command as illustrated in key 12ab below. The PSK is not secure because it is logged and exposed.

    • Entered separately in a new command Enter PSK string after the psk-string command as illustrated in key ab12. The PSK is secured because it is only echoed locally and is not logged.

    Example:

    apic1# configure
    apic1(config)#   template macsec access keychain acckeychainpol1
    apic1(config-macsec-keychain)#     description 'macsec key chain kc1'
    apic1(config-macsec-keychain)#     key 12ab
    apic1(config-macsec-keychain-key)#       life-time start 2017-09-19T12:03:15 end 2017-12-19T12:03:15
    apic1(config-macsec-keychain-key)#       psk-string 123456789a223456789a323456789abc
    apic1(config-macsec-keychain-key)#       exit
    apic1(config-macsec-keychain)#     key ab12
    apic1(config-macsec-keychain-key)#       life-time start now end infinite
    apic1(config-macsec-keychain-key)#       life-time start now end infinite
    apic1(config-macsec-keychain-key)# psk-string
    Enter PSK string: 123456789a223456789a323456789abc
    apic1(config-macsec-keychain-key)# exit
    apic1(config-macsec-keychain)# exit
    apic1(config)#
  3. Configure MACsec interface policy for access interface

    Example:

    apic1# configure
    apic1(config)#   template macsec access interface-policy accmacsecifpol1
    apic1(config-macsec-if-policy)#     inherit macsec security-policy accmacsecpol1 keychain acckeychainpol1
    apic1(config-macsec-if-policy)#     exit
    apic1(config)#
  4. Associate MACsec interface policy to access interfaces on leaf or spine

    Example:

    apic1# configure
    apic1(config)#   template macsec access interface-policy accmacsecifpol1
    apic1(config-macsec-if-policy)#     inherit macsec security-policy accmacsecpol1 keychain acckeychainpol1
    apic1(config-macsec-if-policy)#     exit
    apic1(config)
  5. Configure MACsec Security Policy for fabric interfaces

    Example:

    apic1# configure
    apic1(config)#   template macsec fabric security-policy fabmacsecpol1
    apic1(config-macsec-param)#     cipher-suite gcm-aes-xpn-128
    apic1(config-macsec-param)#     description 'description for mac sec parameters'
    apic1(config-macsec-param)#     window-size 1
    apic1(config-macsec-param)#     sak-expiry-time 100
    apic1(config-macsec-param)#     security-mode must-secure
    apic1(config-macsec-param)#     exit
    apic1(config)#
  6. Configure MACsec key chain for fabric interface

    PSK can be configured in 2 ways:

    Note
    • Inline with the psk-string command as illustrated in key 12ab below. The PSK is not secure because it is logged and exposed.

    • Entered separately in a new command Enter PSK string after the psk-string command as illustrated in key ab12. The PSK is secured because it is only echoed locally and is not logged.

    Example:

    apic1# configure
    apic1(config)#   template macsec fabric security-policy fabmacsecpol1
    apic1(config-macsec-param)#     cipher-suite gcm-aes-xpn-128
    apic1(config-macsec-param)#     description 'description for mac sec parameters'
    apic1(config-macsec-param)#     window-size 1
    apic1(config-macsec-param)#     sak-expiry-time 100
    apic1(config-macsec-param)#     security-mode must-secure
    apic1(config-macsec-param)#     exit
    apic1(config)#   template macsec fabric keychain fabkeychainpol1
    apic1(config-macsec-keychain)#     description 'macsec key chain kc1'
    apic1(config-macsec-keychain)#     key 12ab
    apic1(config-macsec-keychain-key)#       psk-string 123456789a223456789a323456789abc
    apic1(config-macsec-keychain-key)#life-time start 2016-09-19T12:03:15 end 2017-09-19T12:03:15
    apic1(config-macsec-keychain-key)#       exit
    apic1(config-macsec-keychain)#     key cd78
    apic1(config-macsec-keychain-key)# psk-string
    Enter PSK string: 123456789a223456789a323456789abc
    apic1(config-macsec-keychain-key)# life-time start now end infinite
    apic1(config-macsec-keychain-key)# exit
    apic1(config-macsec-keychain)# exit
    apic1(config)#
  7. Associate MACsec interface policy to fabric interfaces on leaf (or spine):

    Example:

    apic1# configure
    apic1(config)#   leaf 101
    apic1(config-leaf)#     fabric-interface ethernet 1/52-53
    apic1(config-leaf-if)#       inherit macsec interface-policy fabmacsecifpol2
    apic1(config-leaf-if)#       exit
    apic1(config-leaf)#