HP FlexNetwork 7500 Series Command Reference Manual page 685

Hide thumbs Also See for FlexNetwork 7500 Series:
Table of Contents
Table 102 Command output
Field
Protect frames
Active MKA policy
Replay protection
Replay window size
Confidentiality offset
Validation mode
Included SCI
SCI conflict
Cipher suite
Transmit secure channel
Receive secure channel
Elapsed time
SCI
Current SA
Previous SA
Description
Status of MACsec desire on the port:
Yes.
No.
If the port does not have an MKA principal actor, this field displays N/A.
MKA policy applied to the port.
This field displays N/A if the port is not enabled with MACsec desire.
This field is not available if the port is enabled with MACsec desire but is not
applied an MKA policy.
Status of replay protection on the port:
Enabled.
Disabled.
If the port is not enabled with MACsec desire, this field displays N/A.
Replay protection window size in number of frames.
This field displays N/A in the following situations:
The port is not enabled with MACsec desire.
The port is not enabled with replay protection.
Confidentiality offset in bytes.
If the port is not enabled with MACsec desire, this field displays N/A.
Validation mode:
Check.
Strict.
If the port is not enabled with MACsec desire, this field displays N/A.
Whether the frame includes SCI tag:
Yes.
No.
If the port is not enabled with MACsec desire, this field displays N/A.
Whether the SCI in the received MKA packets is the same as the local SCI:
Yes—The SCI in the received MKA packets is the same as the local SCI.
No—No MKA packet is received, or the SCI in the received MKA
packets is different from the local SCI.
If the port is not enabled with MACsec desire, this field displays N/A.
Information about the secure channel for outbound traffic.
This field is not available if the port is not enabled with MACsec desire.
Information about the secure channel for inbound traffic.
This field is not available if the port is not enabled with MACsec desire.
Lifetime of the secure channel.
A hexadecimal string that contains the MAC address and port ID.
Current SA used by the secure channel.
If no current SA is available, each of the AN, PN, and LPN fields for the
current SA displays N/A.
Previous SA used by the secure channel.
If no previous SA is available, each of the AN and LPN fields for the previous
SA displays N/A.
670
Table of Contents
loading

Table of Contents