nanog mailing list archives

Re: MACsec SFP


From: Tim Durack <tdurack () gmail com>
Date: Wed, 25 Jun 2014 18:10:38 -0400

On Cisco equipment supporting MACsec, EAP and MKA is of course configured
through the normal cli.
On Wednesday, June 25, 2014, Pieter Hulshoff <phulshof () aimvalley nl> wrote:

On 25-06-14 22:45, Christopher Morrow wrote:

today you program the key (on switches that do macsec, not in an SFP
that does it for you, cause those don't exist, yet) in your router
config and as near as I have seen there isn't a key distribution
protocol aside from that which you write/manage yourself and which is
likely using ssh/snmp(ick)/telnet(ick).


I'm not familiar with the MACsec key distribution available in current
routers/switches. Are you saying Cisco doesn't support EAP and/or MKA for
this purpose or just that the command protocol for configuring EAP/MKA is
run via SSH/SNMP/telnet?

Kind regards,

Pieter Hulshoff



-- 
Tim:>


Current thread: