Junos MACsec on EX and QFX: Configuration Guide - 夜莺博客

Junos MACsec on EX and QFX: Configuration Guide

MACsec (IEEE 802.1AE) encrypts and authenticates every frame on a point-to-point Ethernet link, which makes it the natural way to protect an unlit or shared-facility link between two switches. Juniper EX and QFX devices implement MACsec through connectivity associations: one CA per secured link, with the MKA protocol negotiating session keys between the two directly connected devices. This guide walks through the configuration model, the static CAK mode that Juniper recommends for switch-to-switch links, and the verification commands that show whether the secure channel is actually passing traffic rather than silently dropping it.

MACsec concepts you need before configuring

A connectivity association (CA) is a set of MACsec attributes (key, cipher suite, replay window, SCI handling) that two interfaces use to build one inbound and one outbound secure channel. The CA must exist on both ends of the point-to-point link with matching parameters. Two security modes exist:

  • Static CAK – a connectivity association key is configured on both devices, and the MKA key server periodically generates a random secure association key (SAK) that is shared only across that link. Replay protection, SCI tagging and protocol exclusion are only available in this mode.
  • Dynamic CAK – the CAK is derived/negotiated rather than pre-shared; simpler in some deployments but with a smaller feature set.

For links between switches, Juniper's documented best practice is static CAK: the SAK rotates frequently, and only the two endpoints ever see it.

License and platform prerequisites

MACsec on EX and QFX requires a feature license, with the exception of the QFX10000-6C-DWDM and QFX10000-30C-M line cards. Only MACsec-capable ports or MICs can carry a CA, and the port must be a point-to-point link – MACsec is not designed for shared segments or links with an intermediate switch. Note also that when MACsec is enabled on a logical interface, 802.1Q VLAN tags are sent in clear text; only the payload is protected.

Configuring a connectivity association

The CA is defined under the security macsec hierarchy and then applied to the physical interface:

set security macsec connectivity-association CA1 security-mode static-cak
set security macsec connectivity-association CA1 mka key-server-priority 1
set security macsec connectivity-association CA1 mka transmit-interval 2000
set security macsec connectivity-association CA1 mka key-server-priority 1
set security macsec connectivity-association CA1 replay-protect replay-window-size 64
set security macsec connectivity-association CA1 include-sci
set security macsec connectivity-association CA1 exclude-protocol lldp
set security macsec connectivity-association CA1 pre-shared-key ckn cak

set security macsec interfaces xe-0/0/0 connectivity-association CA1

Both peers must share the same CKN/CAK pair and the same cipher suite. Only one device should win the key-server election; use key-server-priority (lower value wins) to make the choice deterministic instead of leaving it to the MKA election. The exclude-protocol statement is useful for control protocols such as LLDP that neighbouring devices need to read in clear text.

Replay protection and SCI tagging

The replay window defines how many out-of-order frames are tolerated before a frame is discarded. On WAN or multi-hop-tunnel links a window that is too small causes drops that look like random loss, while SCI tagging embeds the secure channel identifier in each frame – useful for troubleshooting with a capture tool, at the cost of a few extra bytes per frame.

Verifying the secured link

show security macsec connections
show security macsec statistics interface xe-0/0/0
show security macsec interfaces xe-0/0/0 detail
monitor traffic interface xe-0/0/0 no-resolve

Look for an established MKA session, an active SAK, and incrementing ok counters with zero unchecked or late frames. A CA that is up but shows incoming frames failing authentication almost always means the CKN/CAK pair does not match on both ends.

Troubleshooting checklist

  • No MKA session – verify the interface is MACsec-capable, licensed, and that both ends use the same CA name, cipher suite and pre-shared key.
  • Session flaps – the transmit interval and key-server priority must be sane on both ends; two devices both insisting on being key server produces repeated elections.
  • Traffic drops after enabling – check for an MTU issue (the MACsec header and ICV add overhead), and remember that VLAN tags remain visible while payloads are encrypted.
  • Control protocol breakage – exclude LLDP, LACP or other link-local protocols if a peer or a passive tap must read them.

MACsec is the right control on links that leave your physical control. If you are troubleshooting the LAG that carries the protected link, see Junos Aggregated Ethernet and LACP configuration, and for the MAC-limit side of access security see Junos port security and MAC limits.

原文链接:https://juniper.net/documentation/en_US/junos/topics/task/configuration/macsec.html