Describes certificate-based MACsec authentication on OXP2-K9 controllers, including certificate authority support, local EAP-TLS authentication, remote EAP-TLS authentication with RADIUS/AAA, and 802.1X controller configuration.
Use EAP-TLS authentication when MACsec peers must use certificates and 802.1X instead of pre-shared keychains to derive the keys used by MKA.
|
Method |
Authentication point |
Key source |
Use |
|---|---|---|---|
|
Certificate authority (CA) trust |
The router authenticates the CA and enrolls a device certificate through a configured trustpoint. |
The trustpoint supplies the certificate material used by EAP-TLS. |
Use CA trust before configuring either local or remote EAP-TLS authentication. |
|
Local EAP-TLS authentication |
The router acts as both authenticator and authentication server. |
The router verifies the peer certificate against its local SCEP trustpoint and generates the Master Session Key (MSK). |
Use local EAP-TLS when the MACsec session must come up without external AAA server authentication. |
|
Remote EAP-TLS authentication with RADIUS/AAA |
The router acts as a pass-through authenticator and sends EAP messages to a remote RADIUS server. |
The RADIUS server verifies the peer certificate and returns the MSK in the Access-Accept response. |
Use remote EAP-TLS when certificate validation and policy decisions are centralized through Authentication, Authorization, and Accounting (AAA). |
802.1X controller role
The dot1x profile configures the OXP2-K9 controller to use Port Access Entity (PAE) role both . The controller can act as the authenticator when it challenges the peer and as the supplicant when the peer challenges it. This mutual role is required for router-to-router MACsec authentication.