SV-283916r1203997_rule
V-283916
SRG-NET-000205-RTR-000013
NOKI-RT-001080
CAT II
10
Configure the connection association using the example below:
- configure macsec connectivity-association "FJM-MACsec1"
- config>macsec>connectivity-association# clear-tag-mode single-tag
- config>macsec>connectivity-association# replay-window-size 2
- config>macsec>connectivity-association# replay-protection
- config>macsec>connectivity-association# cipher-suite gcm-aes-256
- config>macsec>connectivity-association# static-cak
- config>macsec>conn-assoc>static-cak# pre-shared-key 1 encryption-type aes-256-cmac create
- config>macsec>conn-assoc>static-cak>pre-shared-key# cak wrlzKvncyuYlYKdRwW3SEUPnGZ6y4qPMTlmCZ0QvnOIx66eDgHY57Q27QnvLiy/x hash2
- config>macsec>conn-assoc>static-cak>pre-shared-key# ckn dead123456789012345678901234567890123456789012345678901234567890
- config>macsec>conn-assoc>static-cak>pre-shared-key# exit
- config>macsec>conn-assoc>static-cak# pre-shared-key 2 encryption-type aes-256-cmac create
- config>macsec>conn-assoc>static-cak>pre-shared-key# cak 6aF8QgBi/cWEa9SiYTxte38+RqnQLgeMQemd0PjWb61P2kPOg5Pc9clNySHiwfmA hash2
- config>macsec>conn-assoc>static-cak>pre-shared-key# ckn beef123456789012345678901234567890123456789012345678901234567890
- config>macsec>conn-assoc>static-cak>pre-shared-key# exit
- config>macsec>conn-assoc>static-cak# active-psk 2
- config>macsec>conn-assoc>static-cak# mka-key-server-priority 1
- config>macsec>conn-assoc>static-cak# exit
- config>macsec>connectivity-association# no shutdown
- config>macsec>connectivity-association# exit all
Configure the port using the example below:
- configure port 1/1/c15/1
- config>port# ethernet dot1x
- config>port>ethernet>dot1x# macsec
- config>port>ethernet>dot1x>macsec# sub-port 1 create
- config>port>ethernet>dot1x>macsec>sub-port# ca-name FJM-MACsec1
- config>port>ethernet>dot1x>macsec>sub-port# encap-match single-tag 10
- config>port>ethernet>dot1x>macsec>sub-port# max-peer 1
- config>port>ethernet>dot1x>macsec>sub-port# no shutdown
- config>port>ethernet>dot1x>macsec>sub-port# exit
- config>port>ethernet>dot1x>macsec# exit
- config>port>ethernet>dot1x# no shutdown
- config>port>ethernet>dot1x# exit
- config>port# no shutdown
- config>port# exit all
Verify the connection association using the command below:
- show macsec connectivity-association "FJM-MACsec1" detail
Connectivity Association "FJM-MACsec1"
Admin State : Up
Description : FJM-MACsec1
Delay Protection : Disabled
Replay Protection : Enabled
Replay Window Size : 2
Macsec Encrypt : Enabled
Clear Tag Mode : single-tag
Cipher Suite : gcm-aes-256
Encryption Offset : 0
Assigned ports : 1/1/c15/1:1
-------------------------------------------------------------------------------
Static Cak
-------------------------------------------------------------------------------
MKA Key Server Priority : 1
Active Pre-Shared-Key Index : 2
Hello Interval : 2
Active Pre-Shared-Key CKN : beef12345678901234567890123456789012345678901234
5678901234567890
Encryption Type : aes-256-cmac
Verify macsec mks-session using the command below:
- show macsec mka-session port 1/1/c15/1 detail
MKA Session for port 1/1/c15/1: sub-port 1 encap :10
Security Zone : 14
CA Name : FJM-MACsec1
MKA Oper State : in-service
Oper Cipher Suite : gcm-aes-256
Oper Encrypt Offset: 0
CAK Name : beef123456789012345678901234567890123456789012345678901234
567890
MKA Member ID : 8ec720196e42d3ab16921210
Transmit Interval : 2000
Outbound SCI : 0031263b8cc40001
MKA Encapsulation : :10
Message Number : 501
Key Number : 3
Key Server : no
Key Server Priority: 1
Latest SAK AN : 2
Latest SAK KI : dcf5a9fd6e055c47744f276c00000003
Latest SAK LPN : 1
Previous SAK AN : 0
Previous SAK KI : 00000000000000000000000000000000
Previous SAK LPN : 0
If the management traffic is not secured via MACsec tunnel, this is a finding.
V-283916
False
NOKI-RT-001080
Verify the connection association using the command below:
- show macsec connectivity-association "FJM-MACsec1" detail
Connectivity Association "FJM-MACsec1"
Admin State : Up
Description : FJM-MACsec1
Delay Protection : Disabled
Replay Protection : Enabled
Replay Window Size : 2
Macsec Encrypt : Enabled
Clear Tag Mode : single-tag
Cipher Suite : gcm-aes-256
Encryption Offset : 0
Assigned ports : 1/1/c15/1:1
-------------------------------------------------------------------------------
Static Cak
-------------------------------------------------------------------------------
MKA Key Server Priority : 1
Active Pre-Shared-Key Index : 2
Hello Interval : 2
Active Pre-Shared-Key CKN : beef12345678901234567890123456789012345678901234
5678901234567890
Encryption Type : aes-256-cmac
Verify macsec mks-session using the command below:
- show macsec mka-session port 1/1/c15/1 detail
MKA Session for port 1/1/c15/1: sub-port 1 encap :10
Security Zone : 14
CA Name : FJM-MACsec1
MKA Oper State : in-service
Oper Cipher Suite : gcm-aes-256
Oper Encrypt Offset: 0
CAK Name : beef123456789012345678901234567890123456789012345678901234
567890
MKA Member ID : 8ec720196e42d3ab16921210
Transmit Interval : 2000
Outbound SCI : 0031263b8cc40001
MKA Encapsulation : :10
Message Number : 501
Key Number : 3
Key Server : no
Key Server Priority: 1
Latest SAK AN : 2
Latest SAK KI : dcf5a9fd6e055c47744f276c00000003
Latest SAK LPN : 1
Previous SAK AN : 0
Previous SAK KI : 00000000000000000000000000000000
Previous SAK LPN : 0
If the management traffic is not secured via MACsec tunnel, this is a finding.
M
5746