
OPERATIONAL DEFECT DATABASE
...

...
On N9K-C9332C & N9K-C9364C - 100G macsec links stop forwarding traffic after some time (depending on the traffic rate), if no sak-expiry-time is configured. This will result in connectivity loss and LACP suspension
Macsec enabled on 100G interfaces without sak-expiry-time
Workaround 1) Configure XPN Cipher-suite instead of non-xpn Workaound 2) Configure "sak-rekey-time 300" under macsec security policy
Cisco Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.