show security macsec connections
Syntax
show security macsec connections <interface interface-name>
Description
Display the status of the active MACsec connections on the switch.
This command does not display output when MACsec is enabled using static secure association key (SAK) security mode.
Options
none | Display MACsec connection information for all interfaces on the switch. |
interface interface-name | (Optional) Display MACsec connection information for the specified interface only. |
Required Privilege Level
view
Output Fields
Table 1 lists the
output fields for the show security macsec connections
command.
Output fields are listed in the approximate order in which they appear.
Field Name |
Field Description |
---|---|
Fields for Interface | |
|
Name of the interface. |
|
Name of the connectivity association. A connectivity association is named using the |
|
Name of the cipher suite used for encryption. |
|
Encyption setting. Encryption is enabled
when this output is The encryption setting is set using the |
|
Offset setting. The offset is set using the |
|
SCI tagging. The SCI tag is included on
packets in a secure channel when this output is You can enable SCI tagging using the Note:
SCI tags are automatically appended to packets leaving
a MACsec-enabled interface on an EX4300 switch. The |
|
Replay protection setting. Replay protection
is enabled when this output is You can enable replay protection using the |
|
Replay protection window setting. This output
is set to The size of the replay window is configured using the |
Sample Output
show security macsec connections
user@host> show security macsec connections Interface name: xe-0/1/0 CA name: CA1 Cipher suite: GCM-AES-128 Encryption: on Key server offset: 0 Include SCI: no Replay protect: off Replay window: 0
Release Information
Command introduced in Junos OS Release 13.2X50-D15.