Macsec between OS6860 and OS6560
Posted: 01 Jun 2022 23:56
We are trying to configure macsec between a 6860 and 6560 but the operation is still down. Below is the configuration on both switches:
! Security:
security key 1 algorithm aes-cmac-128 encrypt-key 7a67552a3599018672f22d3d3db929d8 keyed-name 0x0000000000000000000000000000000038782f413f4428472b4b625065536856
security key-chain 1 name "MACsec1"
security key-chain 1 key 1
! Zero Configuration:
! MAC Security:
interfaces port 1/1/27 macsec mode dynamic key-chain 1 server-priority 20 encryption
interfaces port 1/1/27 macsec admin-state enable
Below is the status:
TLTB_CORE-> show interfaces macsec dynamic
Server Transmit Key Operation
Chas/Slot/Port Admin-State Mode Keychain Encryption Priority Interval(Sec) Server Status
----------------+-------------+----------+----------+------------+----------+---------------+--------+--------------
1/1/27 Enabled keychain 1 Enabled 20 2 YES DOWN
TLTB_CORE-> show interfaces macsec dynamic
Server Transmit Key Operation
Chas/Slot/Port Admin-State Mode Keychain Encryption Priority Interval(Sec) Server Status
----------------+-------------+----------+----------+------------+----------+---------------+--------+--------------
1/1/27 Enabled keychain 1 Enabled 20 2 YES DOWN
The following are the logs:
2022 Jun 2 15:41:53.102 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state INIT - gport=26
2022 Jun 2 15:41:53.124 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state CHANGE - gport=26
2022 Jun 2 15:41:53.161 TLTB_CORE swlogd intfNi Drv INFO: niEsmCreateMkaInstance:780 : Created MKA - gport=26
2022 Jun 2 15:41:54.350 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state SECURED - gport=26
2022 Jun 2 15:41:56.065 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state RECEIVE - gport=26
2022 Jun 2 15:41:56.126 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state RECEIVING - gport=26
2022 Jun 2 15:41:56.138 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state TRANSMIT - gport=26
2022 Jun 2 15:41:56.336 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state TRANSMITTING - gport=26
2022 Jun 2 15:41:56.357 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state RETIRE - gport=26
2022 Jun 2 15:42:04.163 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state CHANGE - gport=26
Grateful for any assistance.
! Security:
security key 1 algorithm aes-cmac-128 encrypt-key 7a67552a3599018672f22d3d3db929d8 keyed-name 0x0000000000000000000000000000000038782f413f4428472b4b625065536856
security key-chain 1 name "MACsec1"
security key-chain 1 key 1
! Zero Configuration:
! MAC Security:
interfaces port 1/1/27 macsec mode dynamic key-chain 1 server-priority 20 encryption
interfaces port 1/1/27 macsec admin-state enable
Below is the status:
TLTB_CORE-> show interfaces macsec dynamic
Server Transmit Key Operation
Chas/Slot/Port Admin-State Mode Keychain Encryption Priority Interval(Sec) Server Status
----------------+-------------+----------+----------+------------+----------+---------------+--------+--------------
1/1/27 Enabled keychain 1 Enabled 20 2 YES DOWN
TLTB_CORE-> show interfaces macsec dynamic
Server Transmit Key Operation
Chas/Slot/Port Admin-State Mode Keychain Encryption Priority Interval(Sec) Server Status
----------------+-------------+----------+----------+------------+----------+---------------+--------+--------------
1/1/27 Enabled keychain 1 Enabled 20 2 YES DOWN
The following are the logs:
2022 Jun 2 15:41:53.102 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state INIT - gport=26
2022 Jun 2 15:41:53.124 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state CHANGE - gport=26
2022 Jun 2 15:41:53.161 TLTB_CORE swlogd intfNi Drv INFO: niEsmCreateMkaInstance:780 : Created MKA - gport=26
2022 Jun 2 15:41:54.350 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state SECURED - gport=26
2022 Jun 2 15:41:56.065 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state RECEIVE - gport=26
2022 Jun 2 15:41:56.126 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state RECEIVING - gport=26
2022 Jun 2 15:41:56.138 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state TRANSMIT - gport=26
2022 Jun 2 15:41:56.336 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state TRANSMITTING - gport=26
2022 Jun 2 15:41:56.357 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state RETIRE - gport=26
2022 Jun 2 15:42:04.163 TLTB_CORE swlogd intfNi Mka INFO: CP: CP entering state CHANGE - gport=26
Grateful for any assistance.