Quantcast
Channel: All Ethernet Switching posts
Viewing all articles
Browse latest Browse all 10307

Re: 802.1-AE not working with EX4300

$
0
0

Hi Alexandru

 

2 things I would want you to confirm

 

1) Does Dot1x work fine as standalone >>>> Yes as you have mentioned in the trailing mails.

2) MACSEC works without Dot1x also.


Please use this config for macsec below and check.

 

Switch A

 

root@labtestmacsecurity# ...|display set |match security
set security macsec connectivity-association ca1 security-mode static-cak
set security macsec connectivity-association ca1 replay-protect replay-window-size 5
set security macsec connectivity-association ca1 pre-shared-key ckn 37c9c2c45ddd012aa5bc8ef284aa23ff6729ee2e4acb66e91fe34ba2cd9fe311
set security macsec connectivity-association ca1 pre-shared-key cak "$9$BusRylvWLX-VuOclvMXxHq.PFn/9p0ORn6lKWLVboJGjmf69AuBItpIcylLXHq.f36tuO1Ick.fzn/tpxN-Vwgik.PTzbs"
set security macsec interfaces ge-0/1/0 connectivity-association ca1

 

Switch B

 

{master:0}[edit]
root@switchB# ...security |display set
set security macsec connectivity-association ca1 security-mode static-cak
set security macsec connectivity-association ca1 replay-protect replay-window-size 5
set security macsec connectivity-association ca1 pre-shared-key ckn 37c9c2c45ddd012aa5bc8ef284aa23ff6729ee2e4acb66e91fe34ba2cd9fe311
set security macsec connectivity-association ca1 pre-shared-key cak "$9$BusRylvWLX-VuOclvMXxHq.PFn/9p0ORn6lKWLVboJGjmf69AuBItpIcylLXHq.f36tuO1Ick.fzn/tpxN-Vwgik.PTzbs"
set security macsec interfaces ge-0/0/0 connectivity-association ca1

 

Thanks

Partha 


Viewing all articles
Browse latest Browse all 10307

Trending Articles