Loading...
Loading...
Receiving the error when trying to configure MACSEC on 10G ports via QSA adapter on NCS-55A1-36H-S chassis: And MACSEC is not working on the interface: NODE: node0_0_CPU0 Interface-Name Status Cipher-Suite KeyChain PSK/EAP CKN Hu0/0/0/0 Init NONE KEY-CHAIN-MACSEC PRIMARY 01 Hu0/0/0/9 Init NONE KEY-CHAIN-MACSEC PRIMARY 01 Hu0/0/0/18 Secured GCM-AES-XPN-256 KEY-CHAIN-MACSEC PRIMARY 01 Total MACSec Sessions : 3 Secured Sessions : 1 Pending Sessions : 2 interface TenGigE0/0/0/27 description tordc02-sob-p-01:Te0/0/0/18, WAN (Prov: Zayo, CID: OGYX/297302//ZYO) bundle id 207 mode active carrier-delay up 300000 down 0 macsec psk-keychain KEY-CHAIN-MACSEC policy MACSEC-POLICY ! Interface Name : TenGigE0/0/0/27 Interface Namestring : TenGigE0/0/0/27 Interface short name : Te0/0/0/27 Interface handle : 0x288 Interface number : 0x288 MacSecControlledIfh : 0x2d0 MacSecUnControlledIfh : 0x2d8 Interface MAC : 94ae.f0b7.f86c Ethertype : 888E EAPoL Destination Addr : 0180.c200.0003 MACsec Shutdown : FALSE Config Received : TRUE IM notify Complete : TRUE Interface CAPS Add : FALSE RxSA CAPS Add : TRUE TxSA CAPS Add : TRUE MKA PSK Info Key Chain Name : KEY-CHAIN-MACSEC MKA Cipher Suite : AES-256-CMAC CKN : 01 MKA fallback_PSK Info fallback keychain Name : - NA - Policy : MACSEC-POLICY But on breakout 10G ports everything is ok.
MACSEC is configured on 10G (non-breakout) port on NCS-55A1-36H-S chassis
Use breakout cable for 10G ports
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.