Introduces Auto MACsec for wireless APs, detailing peer detection via LLDP, 802.1X authentication, encrypted link establishment, default settings, onboarding processes, compatibility requirements, and instructions for disabling the feature in AP join profiles.
Auto MACsec is a link-security capability that
-
detects a compatible peer through LLDP
-
authenticates the AP through 802.1X using a hardware-backed identity, and
-
establishes hop-by-hop MACsec protection before the AP joins the wireless controller.
Auto MACsec reduces the manual configuration required to protect the wired uplink between a wireless AP and its directly connected access switch. The encrypted link helps protect traffic on the last network hop from interception and man-in-the-middle attacks.
Auto MACsec peer detection functionality is supported on Wi-Fi 7 APs equipped with MACsec-capable physical layer (PHY) interfaces.
Cisco IOS XE 26.2 uses LLDP for Auto MACsec peer detection.
During initial Auto MACsec onboarding, the access point can use its hardware SUDI when no locally significant certificate (LSC) or other port-authentication configuration is available.
This feature supports Day 0 APs and APs that do not have an 802.1X username or MACsec preshared key (PSK) configured.
Auto MACsec is enabled by default. If an AP does not have an 802.1X username or MACsec PSK configuration, it automatically attempts to establish an Auto MACsec connection.
You can disable Auto MACsec in the AP join profile. If the AP currently uses an Auto MACsec connection, disabling the feature immediately interrupts the connection and causes the AP to rejoin. If the AP cannot recover, verify the switch configuration and remove the corresponding Auto MACsec configuration from the switch.
If an AP has an 802.1X username or MACsec PSK configured, it uses that configuration instead of Auto MACsec, even when Auto MACsec is enabled.