Configuration Guide for Cisco NCS 1014, IOS XR Releases 26.x.x

PDF

Configuration Guide for Cisco NCS 1014, IOS XR Releases 26.x.x

MACsec verification commands on OXP2-K9 line card

Want to summarize with AI?

Log in

Lists the show commands that verify MACsec session state, controller programming, fallback status, data-plane counters, and support data on OXP2-K9 800G controllers.


Use these commands to verify MACsec configuration and collect data for troubleshooting.

Table 1. MACsec verification commands

Command

Use

Successful indication

show macsec mka summary

Shows a high-level view of MACsec sessions.

The primary session shows Secured. If fallback is configured, the fallback session shows Active.

show macsec mka session

Shows peer count, session status, key server state, PSK type, and CKN.

The session shows one peer and Secured status after both endpoints are configured.

show macsec mka session controller controller-type port detail

Shows detailed MKA status, cipher suites, SAK status, peer lists, and policy values.

The output shows Secured status, Rx and Tx SAK status, MACsec desired, and one live peer.

show macsec mka controller controller-name detail

Shows controller programming details for Rx and Tx secure channels.

The output shows protected traffic, attach success, provisioned secure channel state, and provisioned SAK state.

show macsec secy stats controller controller-type port sc

Shows SecY interface and secure-channel statistics.

Expected packet counters increment for encrypted traffic. Drop counters remain stable in a healthy session.

show macsec mka statistics controller controller-type port

Shows MKA control-plane statistics.

The counters confirm MKA packet exchange with the peer.

show tech-support ncs10xx detail

Collects detailed support data for root-cause analysis.

Use this command when show command outputs do not identify the failure cause.