|
27Ìâ´ð°¸²»¶Ô. ÎÒµ±Ê±Ñ¡µÄC.3 y* z7 o5 O( \8 P! G( U
https://www.cisco.com/c/en/us/td ... 50xcg/swmacsec.html2 S$ n/ `3 X. m9 p' d4 Z
Understanding Media Access Control Security and MACsec Key Agreement* R+ D( U/ L; V4 ?) p* j: w
MACsec, defined in 802.1AE, provides MAC-layer encryption over wired networks by using out-of-band methods for encryption keying. The MACsec Key Agreement (MKA) Protocol provides the required session keys and manages the required encryption keys. MKA and MACsec are implemented after successful authentication using the 802.1x Extensible Authentication Protocol (EAP) framework. Only host facing links (links between network access devices and endpoint devices such as a PC or IP phone) can be secured using MACsec.
$ M' V2 z' O& t
3 J9 q' J+ @ k i( w% rÓÐÐÄ˼µÄ¿ÉÒԲο¼ÏÂÃæµÄÄÚÈÝ×Ô¼º·ÖÎöÏÂ:/ t4 w7 `+ L. n. ]1 J: g. S
When the switch receives frames from the client, it decrypts them and calculates the correct ICV by using session keys provided by MKA.# ]/ @) R5 p" H& @9 \
% j8 t2 F& Y3 g1 [https://www.cisco.com/c/en/us/td ... 50xcg/swmacsec.html: `" A: ]. e5 h% d' Q1 l
, t8 f! f8 I) s) k6 C( v
- r% T4 M7 ~3 m; d5 g y) wMACsec is the IEEE 802.1AE standard for authenticating and encrypting packets between two MACsec-capable devices. The Catalyst 4500 series switch supports 802.1AE encryption with MACsec Key Agreement (MKA) on downlink ports for encryption between the switch and host devices.. f( T. K5 f* v7 h* r9 }
1 ]7 c' |! S* c6 y1 _3 d6 n, {
https://www.cisco.com/c/en/us/td ... onfig/swmacsec.html; N. F# Q' B4 L
|
10#
2019-11-30 20:15:17
»Ø¸´(0)
ÊÕÆð»Ø¸´
|