Lists the switches and line cards that support MACsec and provides configuration guidelines and limitations.
MACsec encryption provides secure communication between network devices. This reference details the supported switches and line cards, along with configuration guidelines and limitations to ensure proper deployment and operation.
Supported switches and line cards
MACsec is supported on the following switches:
-
N9K-C93108TC-FX3P
-
N9K-C93108TC-FX3 (beginning with the 6.0(5) release)
-
N9K-C93108TC-FX
-
N9K-C93180YC-FX3
-
N9K-C93180YC-FX
-
N9K-C93216TC-FX2
-
N9K-C93240YC-FX2
-
N9K-C9332C
-
N9K-C93360YC-FX2
-
N9K-C9336C-FX2
-
N9K-C9348GC-FXP, only with 10G+
-
N9K-C9364C
-
N9K-C9364D-GX2A
-
N9K-C9348D-GX2A
-
N9K-C9332D-GX2B
-
N9K-C9408 (beginning with the 6.0(2) release)
-
N9K-C9364C-H1, ports 49-64 (beginning with the 6.1(3) release)
-
N9K-C9332D-H2R, ports 1-32 (beginning with the 6.1(3) release)
-
N9K-C93400LD-H1, ports 1-54 (beginning with the 6.1(3) release)
-
N9K-C9348GC-FX3 (beginning with the 6.1(5)release)
MACsec is supported on the following line cards:
-
N9K-X9716D-GX
-
N9K-X9736C-FX
Configuration guidelines and limitations
Configure MACsec on switches according to the following guidelines and limitations:
-
MACsec encryption is configured under fabric policies for fabric ports and access policies for access ports and can be applied to physical interfaces, port-channels, or vPCs (virtual port-channels). Interfaces with MACsec enabled can operate as either Layer 2 interfaces (such as EPGs or L3Out SVIs) or Layer 3 interfaces (including L3Out routed interfaces or routed sub-interfaces). Enabling MACsec on an interface enables MACsec encryption on the entire interface and applies to all VLANs or sub-interfaces configured on the interface.
-
MACsec is not supported on 10G QSA modules.
-
MACsec is not supported with 1G/100M speed on a Cisco ACI leaf switch. Beginning with the 6.1(5) release, N9K-C93180YC-FX3 and N9K-C938GC-FX3 support MACsec on 1G/100M as well.
-
MACsec is not supported with 1G speed on a Cisco ACI leaf switch.
-
MACsec between a Cisco ACI leaf switch and a computer host has not been validated by Cisco. Switch-to-switch mode has been validated and is supported.
-
MACsec is supported on breakout ports.
-
MACsec is supported on remote leaf switches.
-
When using copper ports, the copper cables must be connected directly the peer device (standalone N9k) in 10G mode.
-
A 10G copper SFP module on the peer is not supported.
-
FEX ports are not supported for MACsec.
-
The must-secure mode is not supported at the pod level.
-
A MACsec policy with the name "default" is not supported.
-
Auto-key generation is only supported at the pod level for fabric ports.
-
Do not clean reboot a node if the fabric ports of that node is running MACsec in must-secure mode.
-
Adding a new node to a pod or stateless reboot of a node in a pod that is running MACsec, must-secure mode requires changing the mode to should-secure for the node to join the pod.
-
Only initiate an upgrade or downgrade if the fabric links are in the should-secure mode. After the upgrade or downgrade has completed, you can change the mode to must-secure. Upgrading or downgrading in the must-secure mode resultsin traffic disruption.
-
The keychain configuration needs to be consistent across the pod. If the keychain configuration is not consistent, then the fabric ports will not come up.
-
There should be one key in the keychain with an end time of infinite. When a keychain expires, then traffic is blocked on affected interfaces which are configured for must-secure mode. Interfaces configured for should-secure mode transmit unencrypted traffic.
-
There should be overlaps in the end time and start time of keys that are used sequentially to ensure the MACsec session stays up when there is a transition between keys.