Overview
Explains how to configure MACsec policy exceptions to permit specific packet types, such as LACP, pause frames, and LLDP, to bypass encryption and be transmitted in clear text for troubleshooting and interoperability.
This chapter explains how to configure MACsec policy exceptions to permit specific packet types—such as LACP, pause frames, and LLDP packets—to bypass MACsec encryption and be transmitted in clear text. It provides step-by-step procedures, example commands, and important security considerations for enabling these exceptions in Cisco environments.
MACsec policy exception
Defines MACsec policy exceptions as a mechanism to bypass encryption for designated packet types, allowing clear-text transmission to support interoperability and specific network topology requirements.
MACsec policy exceptions for LACP packets
Explains the use of MACsec policy exceptions for LACP packets, which allow link aggregation control traffic to be sent in clear text to ensure bundle formation and troubleshooting across intermediate nodes.
MACsec policy exceptions for LLDP packets
Describes how to allow LLDP packets to be transmitted in clear text, facilitating neighbor discovery and troubleshooting on MACsec-enabled ports while maintaining encryption for all other data traffic.