Configure MACsec encryption with EAP-TLS by establishing RADIUS authentication, managing digital certificates via a trustpoint, and defining the necessary EAP and 802.1X profiles. Once these components are configured, apply the profiles to your physical interfaces to enable secure, certificate-based mutual authentication and automated key management.
This task enables the router to authenticate 802.1X clients with EAP-TLS, providing mutual authentication and generating a Master Session Key (MSK) for secure communication.
Before you begin
-
Ensure a Certificate Authority (CA) server is configured for the network.
-
Verify the configured CA certificate is valid.
-
Confirm that Cisco Identity Services Engine (ISE) Release 2.2 or later, or Cisco Secure Access Control Server Release 5.6 or later, is configured as the external AAA server.
-
Ensure the remote AAA server is configured with the EAP-TLS method.
-
Synchronize the routers, CA server, and external AAA server using Network Time Protocol (NTP) to ensure certificate validation.
Follow these steps to configure MACsec encryption using EAP-TLS authentication:
Procedure
MACsec encryption is successfully configured on the router using EAP-TLS authentication, enabling secure communication and mutual authentication for 802.1X clients.