Configures MAC Security (MACsec) replay-protect window size for port(s).
|replay-protect||Configures dropping out-of-order packets received on a port.|
|window_size_in_packets||Sets replay-protect window size value. Out-of-order packets up to selected value are accepted. Range is 0–4,294,967,295. Default is 0 (out-of-order packets are dropped).|
|disable||Disables replay protection. Out-of-order packets are allowed.|
|ports||Specifies configuring ports.|
|port_list||Lists which ports to configure the replay-protect window on.|
Default value for replay-protect window is 0 packets, which drops all out-of-order packets.
The replay protection feature provides for the dropping of out-of-order packets received on a port. The window size is set to 0 by default, meaning any packet received out-of-order is dropped. Setting the window size to non-zero sets the range of sequence numbers that are tolerated, to allow receipt of packets that have been misordered by the network. If replay protection is disabled, packet sequence numbers are not checked and out-of-order packets are not dropped.
ImportantAfter enabling MACsec, if you change the replay protect window size, you must run the configure macsec initialize ports port_list command afterward. Otherwise, the change is not applied.
# configure macsec replay-protect disable port 13 # configure macsec intialize port 13
# configure macsec replay-protect 50 port 14 # configure macsec intialize port 14
This command was first available in ExtremeXOS 30.1.
This command is available on the following platforms.
NoteThe MACsec feature requires the installation of the MAC Security feature pack license.
|Platform||Ports||LRM/MACsec Adapter Required?|
|ExtremeSwitching X460-G2-24p-24hp, X460-G2-24t-24ht switches||Half-duplex, 1G ports (25–48)||No|
|All other SFP/SFP+ ports *||Yes|
|ExtremeSwitching X450-G2, X460-G2, X440-G2, X590, X620, and X695 series switches||SFP/SFP+ ports *||Yes|
X465-24W, X465-24XE: ports 1–24
X465-48T, X465-48P, X465-48W, X465i-48W: ports 1–48
X465-24MU-24W: ports 25–48
VIM5-4XE: all 4 ports
VIM5-4YE in X465-24MU, X465-24MU-24W switches: all 4 ports
VIM5-4YE in X465-24W, X465-48T, X465-48P, X465-48W, X464.24S, X465-24S, X465i-48W: first 2 ports only
Note: * For ExtremeSwitching X460-G2 series switches, the VIM-2X option does not support the LRM/MACsec Adapter.