Enabling MACsec Replay Protection

The replay protection feature provides for the dropping of out‐of‐order packets received on a port. If replay protection is enabled, the MIB object secyRxSCStatsDelayPkts is incremented and the packet is dropped. If replay protection is disabled, the MIB object secyRxSCStatsDelayPkts is incremented and the packet is forwarded. A window is configurable for the number of allowed out-of-order packets before packets are dropped. This window defaults to 0 (all out-of-order packets are dropped).

Replay protect and the associated window feature are detailed in IEEE 802.1X‐2010.

Use the set macsec secy command in any command mode to enable MACsec replay protection and the number of allowed out-of-order packets on a port.