Describes MACsec encryption support on the NCS1K14-OXP2-K9 line card and provides concepts, guidelines, configuration tasks, verification tasks, and troubleshooting references for 800G controllers.
MACsec encryption over 800G trunks on OXP2-K9 line card
Describes the Media Access Control Security (MACsec) encryption feature for 800G trunk interfaces on the NCS1K14-OXP2-K9 line card, including release information, protection behavior, and configuration scope.
Configure 800G client services for MACsec
Configures the 800G client service prerequisites for MACsec by verifying the OXP2-K9 hardware, checking FPD status, provisioning the muxponder slice, and applying the supported AppSel configuration.
MACsec EAP-TLS authentication on OXP2-K9 line card
Describes certificate-based MACsec authentication on OXP2-K9 controllers, including certificate authority support, local EAP-TLS authentication, remote EAP-TLS authentication with RADIUS/AAA, and 802.1X controller configuration.
Configure MACsec encryption with a pre-shared keychain on OXP2-K9 line card
Provides the workflow to provision the 800G service, configure keychains and policies, enable MACsec on the controller, optionally add fallback protection, and verify the encrypted session.
MACsec verification commands on OXP2-K9 line card
Lists the show commands that verify MACsec session state, controller programming, fallback status, data-plane counters, and support data on OXP2-K9 800G controllers.
MACsec performance and statistics on OXP2-K9 line card
Describes how to use CLI and SNMP counters to verify MACsec traffic protection on OXP2-K9 800G controllers and to identify packet validation, key, or replay issues.