Visible to Intel only — GUID: tup1652825309222
Ixiasoft
2.2.1.1. Common Port Mux Interface
2.2.1.2. Common Port Demux Interface
2.2.1.3. Controlled Port Mux Interface
2.2.1.4. Controlled Port Demux Interface
2.2.1.5. Uncontrolled Port RX Interface
2.2.1.6. Uncontrolled Port TX Interface
2.2.1.7. Crypto RX Interface
2.2.1.8. Crypto TX Interface
2.2.1.9. Management Interface
2.2.1.10. Decrypt Port Mux Management Interface
2.2.1.11. Decrypt Port Demux Management Interface
2.2.1.12. Encrypt Port Mux Management Interface
2.2.1.13. Encrypt Port Demux Management Interface
2.2.1.14. Crypto IP Management Bus
2.2.2.1. Common Port Mux Interface Waveform
2.2.2.2. Common Port Demux Interface Waveform
2.2.2.3. Controlled Port Mux Interface Waveform
2.2.2.4. Controlled Port Demux Interface Waveform
2.2.2.5. Uncontrolled Port RX Interface Waveform
2.2.2.6. Uncontrolled Port TX Interface Waveform
2.2.2.7. Crypto RX Waveform
2.2.2.8. Crypto TX Waveform
2.2.2.9. MACsec Management Interface (Read)
2.2.2.10. MACsec Management Interface (Write)
Visible to Intel only — GUID: tup1652825309222
Ixiasoft
4.6. MACsec Software Rekeying
When PN is about to expire, rekeying occurs. An example of a sequence that can happen is shown below.
Transmit SA:
- Set “Enable Transmission enable” to False (the default value is False) for new SA.
- Choose a security association and program the following configuration:
- Set the Key value for the SA.
- Set the next packet number value for the SA.
- Set the confidentiality offset value for the SA.
- Initialize all the stats configuration.
- Ensure no Tx traffic entering the MACsec IP is using the expired SA.
- Set “Enable Transmission enable” to False for expired SA.
- Set “Enable Transmission enable” to True for new SA.
Receive SA:
- Set “Enable Receive enable” to False (the default value is False) for new SA.
- Choose a security association and program the following configuration:
- Set the Key value for the SA belonging to the SC.
- Set the next packet number value for the SA belonging to the SC.
- Set the lowest PN value for the SA belonging to the SC.
- Initialize all the stats configuration.
- Set “Enable Receive enable” to True (the default value is False) for new SA.
- Ensure the Rx traffic entering the MACsec IP is using the new SA.
- Set “Enable Receive enable” to False (the default value is False) for the expired SA.