Enabling MACsec in Cisco NDFC Release 12.1.3

Enabling MACsec, Release 12.1.3

New and Changed Information

The following table provides an overview of the significant changes up to this current release. The table does not provide an exhaustive list of all changes or of the new features up to this release.

Release Version Feature Description
NDFC release 12.1.3 Reorganized content Content within this document was originally provided in the Cisco NDFC-Fabric Controller Configuration Guide or the Cisco NDFC-SAN Controller Configuration Guide. Beginning with release 12.1.3, this content is now provided solely in this document and is no longer provided in those documents.

MACsec Support in Data Center VXLAN EVPN and BGP Fabrics

MACsec is supported in the Data Center VXLAN EVPN and BGP fabrics on intra-fabric links. You should enable MACsec on the fabric and on each required intra-fabric link to configure MACsec. Unlike CloudSec, auto-configuration of MACsec is not supported.

MACsec is supported on switches with minimum Cisco NX-OS Releases 7.0(3)I7(8) and 9.3(5).

Guidelines

  • If MACsec cannot be configured on the physical interfaces of the link, an error is displayed when you click Save. MACsec cannot be configured on the device and link due to the following reasons:
    • The minimum NX-OS version is not met.
    • The interface is not MACsec capable.
  • MACsec global parameters in the fabric settings can be changed at any time.
  • MACsec and CloudSec can coexist on a BGW device.
  • MACsec status of a link with MACsec enabled is displayed on the Links window.
  • Brownfield migration of devices with MACsec configured is supported using switch and interface freeform configs.

For more information about MACsec configuration, which includes supported platforms and releases, see the Configuring MACsec chapter in Cisco Nexus 9000 Series NX-OS Security Configuration Guide.

The following sections show how to enable and disable MACsec in Nexus Dashboard Fabric Controller.

Enabling MACsec

  1. Navigate to LAN > Fabrics.
  2. Click Actions > Create to create a new fabric or click Actions > Edit Fabric on an existing Easy or eBGP fabric.
  3. Click the Advanced tab and specify the MACsec details.

Enable MACsec - Select the check box to enable MACsec for the fabric.

MACsec Primary Key String - Specify a Cisco Type 7 encrypted octet string that is used for establishing the primary MACsec session. For AES_256_CMAC, the key string length must be 130 and for AES_128_CMAC, the key string length must be 66. If these values are not specified correctly, an error is displayed when you save the fabric.

? The default key lifetime is infinite.

MACsec Primary Cryptographic Algorithm - Choose the cryptographic algorithm used for the primary key string. It can be AES_128_CMAC or AES_256_CMAC. The default value is AES_128_CMAC.

You can configure a fallback key on the device to initiate a backup session if the primary session fails.

MACsec Fallback Key String - Specify a Cisco Type 7 encrypted octet string that is used for establishing a fallback MACsec session. For AES_256_CMAC, the key string length must be 130 and for AES_128_CMAC, the key string length must be 66. If these values are not specified correctly, an error is displayed when you save the fabric.

MACsec Fallback Cryptographic Algorithm - Choose the cryptographic algorithm used for the fallback key string. It can be AES_128_CMAC or AES_256_CMAC. The default value is AES_128_CMAC.

MACsec Cipher Suite - Choose one of the following MACsec cipher suites for the MACsec policy:

  • GCM-AES-128
  • GCM-AES-256
  • GCM-AES-XPN-128
  • GCM-AES-XPN-256

The default value is GCM-AES-XPN-256.

? The MACsec configuration is not deployed on the switches after the fabric deployment is complete. You need to enable MACsec on intra-fabric links to deploy the MACsec configuration on the switch.

MACsec Status Report Timer - Specifies MACsec operational status periodic report timer in minutes.

  1. Click a fabric to view the Summary in the side kick. Click the side kick to expand. Click Links tab.
  2. Choose an intra-fabric link on which you want to enable MACsec and click Actions > Edit.
  3. In the Link Management - Edit Link window, click Advanced in the Link Profile section, and select the Enable MACsec check box. If MACsec is enabled on the intra fabric link but not in the fabric settings, an error is displayed when you click Save.
  4. When MACsec is configured on the link, the following configurations are generated:
    • Create MACsec global policies if this is the first link that enables MACsec.
    • Create MACsec interface policies for the link.
  5. From the Fabric Actions drop-down list, select Deploy Config to deploy the MACsec configuration.

Disabling MACsec

To disable MACsec on an intra-fabric link, navigate to the Link Management - Edit Link window, unselect the Enable MACsec check box, click Save. From the Fabric Actions drop-down list, select Deploy Config to disable MACsec configuration. This action performs the following:

  • Deletes MACsec interface policies from the link.
  • If this is the last link where MACsec is enabled, MACsec global policies are also deleted from the device.

Only after disabling MACsec on links, navigate to the Fabric Settings and unselect the Enable MACsec check box under the Advanced tab to disable MACsec on the fabric. If there's an intra-fabric link in the fabric with MACsec enabled, an error is displayed when you click Actions > Recalculate Config from the Fabric Actions drop-down list.


File Info : application/pdf, 8 Pages, 118.54KB

enabling-macsec

References

Asciidoctor PDF 2.3.7, based on Prawn 2.4.0 Asciidoctor PDF 2.3.7, based on Prawn 2.4.0; modified using iText 2.1.7 by 1T3XT

Related Documents

Preview Cisco NDFC-Fabric Controller Configuration Guide, Release 12.1.1e
This guide provides comprehensive instructions for configuring the Cisco NDFC-Fabric Controller, Release 12.1.1e. It covers various aspects of fabric management, including provisioning, configuration, monitoring, and troubleshooting.
Preview Cisco Nexus Dashboard Fabric Controller (NDFC) Deployment Guide
This guide provides comprehensive instructions for deploying the Cisco Nexus Dashboard Fabric Controller (NDFC), detailing its architecture, networking requirements, and deployment options for various environments.
Preview Cisco vPC Fabric Peering Configuration Guide - Release 12.1.3
Learn how to configure vPC Fabric Peering on Cisco Nexus switches using Cisco NDFC. This guide covers virtual peer link creation, conversion, QoS settings, and limitations for Release 12.1.3.
Preview Cisco Nexus 9000 Series NX-OS Release Notes, Release 10.2(2)F
This document details the features, issues, and exceptions of Cisco NX-OS Release 10.2(2)F software for Cisco Nexus 9000 Series switches, including new and enhanced software features, unsupported features, and resolved and open issues.
Preview Cisco Nexus Dashboard Fabric Controller Installation and Upgrade Guide, Release 12.1.2e
This guide provides comprehensive instructions for installing and upgrading the Cisco Nexus Dashboard Fabric Controller (NDFC) Release 12.1.2e. It covers system requirements, deployment options, prerequisites, and detailed upgrade paths for managing Cisco data center network infrastructure.
Preview Verified Scalability Guide for Cisco Nexus Dashboard Fabric Controller, Release 12.2.2
This guide provides verified scalability values for various deployment types for Cisco Nexus Dashboard Fabric Controller, Release 12.2.2. It details system resource requirements and scale limits for different fabric configurations.
Preview Cisco NDFC-Fabric Controller Configuration Guide, Release 12.1.1e
This guide provides comprehensive instructions for configuring the Cisco NDFC-Fabric Controller, Release 12.1.1e. It covers various aspects of fabric management, including provisioning, configuration, monitoring, and troubleshooting for different network environments like VXLAN EVPN, IPFM, and more. Learn about managing switches, interfaces, policies, and virtual infrastructure to optimize your network operations.
Preview Verified Scalability Guide for Cisco Nexus Dashboard Fabric Controller, Release 12.0.2f
Detailed scalability limits and server resource requirements for Cisco Nexus Dashboard Fabric Controller (NDFC) Release 12.0.2f, covering various deployment types for fabric controller, discovery, VXLAN EVPN, and SAN controller.